常時SSLでもCookieの改ざんはできるワケ

As previously explained in the blog post below, cookies can still be tampered with even when using Always-On SSL. While browsers have since made improvements, cookie manipulation is still not fully preventable. An experiment demonstrated that cookie manipulation cannot be prevented even when using HTTPS. https://blog.tokumaru.org/2013/09/coo... In the second half of this video, I'll explain in detail, with demos, the differences in behavior between Safari and Google Chrome (and Firefox). What I want to share today: The Secure attribute on cookies is important for preventing cookie eavesdropping (discussion from the previous video). I'll explain that even if you add the Secure attribute to cookies, it can prevent tampering, but not eavesdropping. I'll also discuss the compatibility status of recent browsers. PS: In the video, I explain that "preventing cookie manipulation itself is difficult," but modern browsers can prevent it by using cookie prefixes. For more information, please refer to the MDH explanation. https://developer.mozilla.org/ja/docs... ------------ ■EG Secure Solutions, Inc.  https://www.eg-secure.co.jp/ ■For business inquiries, please click here  https://www.eg-secure.co.jp/contact/ ------------

TCP/IPを理解している人ほど間違いやすい 常時SSLでもCookieのSecure属性が必要な理由
▶︎

TCP/IPを理解している人ほど間違いやすい 常時SSLでもCookieのSecure属性が必要な理由

【理解してる?】クッキー(Cookie)への同意って何?【情報を守れ!】
▶︎

【理解してる?】クッキー(Cookie)への同意って何?【情報を守れ!】

[Attention Business Owners!] Essential Security Basics for Non-Engineers / Security Risks of Vibe...
▶︎

[Attention Business Owners!] Essential Security Basics for Non-Engineers / Security Risks of Vibe...

Is the UK worse off because of Brexit? | BBC News
▶︎

Is the UK worse off because of Brexit? | BBC News

Passkeys Explained: Are They Actually Better Than Passwords?
▶︎

Passkeys Explained: Are They Actually Better Than Passwords?

【CORS入門】もうCORSエラーに苦しむことはありません。Webエンジニア必見です。
▶︎

【CORS入門】もうCORSエラーに苦しむことはありません。Webエンジニア必見です。

Linux Full Course for Beginners | Learn Linux System Administration
▶︎

Linux Full Course for Beginners | Learn Linux System Administration

【パスキー後編】難しいパスキー認証たった10分でわかる!コレ考えた人天才。わかりやすく解説。        #中小企業セキュリティ #情報処理安全確保支援士
▶︎

【パスキー後編】難しいパスキー認証たった10分でわかる!コレ考えた人天才。わかりやすく解説。        #中小企業セキュリティ #情報処理安全確保支援士

What's happening on the completely anonymous "dark web"? #160
▶︎

What's happening on the completely anonymous "dark web"? #160

System Design Explained: APIs, Databases, Caching, CDNs, Load Balancing & Production Infra
▶︎

System Design Explained: APIs, Databases, Caching, CDNs, Load Balancing & Production Infra

We tested whether a fake Wi-Fi access point could actually steal passwords
▶︎

We tested whether a fake Wi-Fi access point could actually steal passwords

World's Deadliest Computer Virus: WannaCry
▶︎

World's Deadliest Computer Virus: WannaCry

PHP Conference Japan 2021: SPAセキュリティ入門 / 徳丸 浩
▶︎

PHP Conference Japan 2021: SPAセキュリティ入門 / 徳丸 浩

Cookieとセッションってなに?ゼロからわかりやすく解説
▶︎

Cookieとセッションってなに?ゼロからわかりやすく解説

How to Build & Sell AI Agents: Ultimate Beginner’s Guide
▶︎

How to Build & Sell AI Agents: Ultimate Beginner’s Guide

AI Agents Full Course 2026: Master Agentic AI (2 Hours)
▶︎

AI Agents Full Course 2026: Master Agentic AI (2 Hours)

Firewall Fundamentals Explained | Network Security for Beginners
▶︎

Firewall Fundamentals Explained | Network Security for Beginners

Attacking AI - Jason Haddix - NDC Security 2026
▶︎

Attacking AI - Jason Haddix - NDC Security 2026

Let’s Handle 1 Million Requests per Second, It’s Scarier Than You Think!
▶︎

Let’s Handle 1 Million Requests per Second, It’s Scarier Than You Think!

How The FBI Finds Your REAL IP Address
▶︎

How The FBI Finds Your REAL IP Address