This is page 1, displaying results 1-5

W3C, threat modeling, and the CRA: a report from GDC 2026

Published:

By: Giovanni Corti, from W3C Member Fondazione Bruno Kessler, participant of the W3C Security Interest Group (SING)

At GDC 2026, W3C Security Interest Group member Giovanni Corti shared how threat modeling was integrated into the revision of ETSI EN 304 617, the draft harmonized standard for browser cybersecurity under the EU Cyber Resilience Act, referencing the W3C Threat Modeling Guide and the Threat Model for the Web.

  • gdc

Threat modeling age-based content restrictions: what we learned at EIC 2026

Published:

By: Simone Onofri, W3C Security Lead, Zahra Ebadi Ansaroudi and Amir Sharif

At the European Identity and Cloud Conference (EIC 2026) in Berlin, we explored how Threat Modeling with LEGO® SERIOUS PLAY® can help uncover security, privacy, and human-rights threats in age-based content restriction systems. Starting from an Issuer-Holder-Verifier model, participants built harms such as exclusion, surveillance, profiling, and correlation, then mapped them back to flows, actors, and assumptions. The exercise showed how compliance choices can become Web architecture.

Human rights and ICT standardization: What is W3C doing about this?

Published:

By: Simone Onofri, W3C Security Lead

At the Brussels seminar on Human Rights and ICT Standardization, W3C contributed to the discussion on how human-rights principles can enter technical work while design choices are still open. The post connects Ethical Web Principles, accessibility, horizontal review, threat and harm modeling, and the practical cost of participation: making assumptions, impacts, and responsibilities visible before they become infrastructure.

  • human rights

Threat Modeling with LEGO SERIOUS PLAY: Building your Digital Identity threat

Published:

By: Simone Onofri, W3C Security Lead and Giovanni Corti, Threat Modeling Community Group participant

W3C explored how Threat Modeling with LEGO SERIOUS PLAY can help uncover security, privacy, and human-rights threats in digital identity systems. Participants built threats from real-world harms, mapped them into shared landscapes, and discovered they are connected.

How to protect your Web applications from XSS

Published:

By: Simone Onofri, W3C Security Lead and Daniel Appelquist, W3C SWAG CG Chair

The W3C SWAG (Security Web Application Guidelines) Community Group, launched in June 2024, aims to simplify security features in web app development. SWAG's mission is to enhance web app security by creating best practices for developers and fostering collaboration. A key output includes videos on configuring CSP and Trusted Types, which mitigate XSS. Based on Google’s adoption experience, these resources offer tools to help developers securely configure these protections with minimal effort.