Guides ยท Technology

Browser Security Basics

Lock down the browser

Securing web apps in browsers means enforcing HTTPS, setting HSTS, using secure/HttpOnly/SameSite cookies, Content Security Policy, and sandboxing risky iframes to limit XSS and injection impact.

Transport

Use HTTPS everywhere with HSTS and correct TLS.

Cookies

Set Secure, HttpOnly, SameSite; avoid storing secrets in JS.

Content Controls

Apply CSP, sandbox iframes, and escape user input.

Keep Exploring

Related Terms

One useful idea at a time

Get new explainers in your inbox

Occasional clear explanations. No daily noise.