Sign in

Mike West

@mikewe.st
716 followers 59 following 16 posts

web browser stuff: security, privacy, safety, etc.

PostsRepliesMedia
Reposted by Mike West
Ricky Mondello @rmondello.com · 08/09/2026
New post on my blog about switching password managers in 2026! It covers: - why your iPhone or iPad, and not your Mac, might be the place to start your switch - the recent controversy in password management and some thoughts on values - and more! rmondello.com/2026/09/07/s...
rmondello.com
Switching Password Managers in 2026
Important Note: Although I work at Apple in the password management and app/website authentication spaces, in this post I am speaking only for myself, personally. There is no “news” in this post or any kind of “inside scoop”. Please do share this post, but if I see “Apple’s Ricky Mondello” anywhere, I’ll be sad. My [...]
513248
Reposted by Mike West
Scott Helme @scotthelme.bsky.social · 08/07/2026
This looks like it could be really promising! Connection Allowlist: a network firewall, built into the browser scotthelme.co.uk/connection-a...
scotthelme.co.uk
Connection Allowlist: a network firewall, built into the browser
Connection Allowlist is a new browser security mechanism that lets a document declare, up front, the exact set of destinations it's permitted to open network connections to. Anything not on the list…
092
Mike West @mikewe.st · 07/05/2026
I think your `challenge` has a different threat model, and it might well make sense to use some of the same techniques to consume the value in a way that doesn't make it available to CSS or script. I'd be happy to chat with you about the threat model, which isn't really clear to me at the moment.
110
Mike West @mikewe.st · 07/05/2026
CSP's use of `nonce` has a different threat model. We basically assume that if you can execute script, then you can read nonces and execute more script. We want to ensure, however, that scriptless attacks (e.g. using CSS attribute selectors) can't leak secrets that could be used to execute script.
110
Mike West @mikewe.st · 07/05/2026
I meant all the stuff in html.spec.whatwg.org/multipage/ur... about hiding the value of the content attribute to protect against some esoteric attacks that probably don't apply here.
html.spec.whatwg.org
HTML Standard
110
Mike West @mikewe.st · 07/05/2026
CSP uses nonces to identify specific script, style, and link tags that have been allowlisted by the page’s policy. The usage here is different, and I could imagine that a different name could be helpful (`challenge`?). I’m also not sure you need the same value-hiding behavior?
100
Mike West @mikewe.st · 25/01/2026
FWIW, CSP is the best thing you can use today, but it's not really built for exfiltration mitigation. We're working on github.com/wicg/connect... with that specific threat model in mind.
github.com
GitHub - WICG/connection-allowlists
Contribute to WICG/connection-allowlists development by creating an account on GitHub.
152
Mike West @mikewe.st · 09/12/2025
No spoilers!
120
Mike West @mikewe.st · 08/08/2025
I think @arw.me has an electric coffee mug (Ember?) keeping his beverage at a reasonable temperature for some extended period. Perhaps he could pass on a recommendation?
100
Mike West @mikewe.st · 15/12/2024
Have you considered writing more about potatoes?
020
Mike West @mikewe.st · 10/12/2024
On the other hand, knocking down fences is fun, while understanding why fences are there is usually not fun. :(
130
Reposted by Mike West
Freddy @freddyb.bsky.social · 27/11/2024
Modern solutions against cross-site attacks (frederikbraun.de/modern-solut...): An article about cross-site leak attacks and browser-based defenses. You will also learn why web security best practices is always opt-in and finally how YOU can get increased security controls.
frederikbraun.de
Modern solutions against cross-site attacks
Modern solutions against cross-site attacks
03419
Mike West @mikewe.st · 20/11/2024
Do you, like me, periodically need to produce a base64-encoded SHA-2 hash of some text? Have you found existing online generator tools to be slightly annoying in some minor way that doesn't precisely fit your workflow? Well, here's another that will annoy you in _different_ ways: sha2.it
sha2.it
SHA2 digest generator
030
Mike West @mikewe.st · 19/11/2024
You're entirely right. The promises signatures can make are different in kind, but hopefully no less useful. wicg.github.io/signature-ba... and wicg.github.io/signature-ba... get at the distinctions to some extent, and I'd welcome additions to those descriptions.
wicg.github.io
Signature-based Integrity
010
Mike West @mikewe.st · 19/11/2024
It's unfortunate that this is _also_ the way to discover whether food is untasty.
000
Reposted by Mike West
Michele Spagnuolo @miki.it · 17/11/2024
Happy to publish the effort of my last five years: Security Signals. research.google/pubs/securit...
research.google
Security Signals: Making Web Security Posture Measurable At Scale
0277
Mike West @mikewe.st · 17/11/2024
wicg.github.io/signature-ba... seems likely to depend on this mechanism; it's going to be necessary to spell out unambiguous approaches to those decision points that make it clear how to generate and validate signatures in a consistent way on both the server and the client.
wicg.github.io
Signature-based Integrity
000
Mike West @mikewe.st · 17/11/2024
I'm skimming RFC9421's signing and validation algorithms for reasons, and it seems like the spec provides way more room for confusion about what's being signed than I'd prefer, with guidance like "Determine an order for any signature parameters...". How? 🤷 www.rfc-editor.org/rfc/rfc9421....
rfc-editor.org
RFC 9421: HTTP Message Signatures
This document describes a mechanism for creating, encoding, and verifying digital signatures or message authentication codes over components of an HTTP message. This mechanism supports use cases where...
100
Mike West @mikewe.st · 15/11/2024
Daniel Stenberg's notes from this week's HTTP Workshop are a nice way of catching up on smart folks' thoughts about the present and future of your favorite transport protocol: Day 1: daniel.haxx.se/blog/2024/11... Day 2: daniel.haxx.se/blog/2024/11... Day 3: daniel.haxx.se/blog/2024/11...
daniel.haxx.se
The 2024 HTTP Workshop
Day one. For the sixth time, this informal group of HTTP implementers and related "interested parties" unite in a room over a couple of days doing a HTTP Workshop. Nine years since that first event in...
121
Mike West @mikewe.st · 15/11/2024
I set up this account, then nerdsniped myself right past the process of crafting a witty and enticing "Hello, world!" post to instead spend a few minutes trying to figure out whether Bluesky supported security keys rather than email for 2FA. It apparently doesn't. 🤷
010