This blog has moved! Please update your
bookmarks to http://www.blog.modsecurity.org.

« PHP chapter from Apache Security available for download | Main | Improvements to the Servlet specification »

Web Security Improvement Ideas

I have been keeping a list of web security improvement ideas for some time now. It's a list that does not contain only my ideas but thoughts I picked up from others over the years. I have been showing the list to others lately, so I thought it would be a good idea to post it online too. I am posting it here straight from my notebook (you can probably tell from the lack of structure).

With some more work the proposed changes could help us with XSS, session hijacking, CSRF, and phishing. I think the improvements are entirely feasible, although realising them is no small task. The real question in my mind, though, is whether these improvements are sufficient to "solve" the problem of web security in its entirety. (Or at least be future-proof, i.e. compatible with future improvements that may be required.)

Posted by ivanr at July 11, 2005 01:53 PM