Blog - Security
The W3C blog is for in-depth Web standards topics and educational materials. More information in About W3C Blog.
Browse categories
Browse archives
W3C, threat modeling, and the CRA: a report from GDC 2026
Published:
By: Giovanni Corti, from W3C Member Fondazione Bruno Kessler, participant of the W3C Security Interest Group (SING)
At GDC 2026, W3C Security Interest Group member Giovanni Corti shared how threat modeling was integrated into the revision of ETSI EN 304 617, the draft harmonized standard for browser cybersecurity under the EU Cyber Resilience Act, referencing the W3C Threat Modeling Guide and the Threat Model for the Web.
- gdc
Threat modeling age-based content restrictions: what we learned at EIC 2026
At the European Identity and Cloud Conference (EIC 2026) in Berlin, we explored how Threat Modeling with LEGO® SERIOUS PLAY® can help uncover security, privacy, and human-rights threats in age-based content restriction systems. Starting from an Issuer-Holder-Verifier model, participants built harms such as exclusion, surveillance, profiling, and correlation, then mapped them back to flows, actors, and assumptions. The exercise showed how compliance choices can become Web architecture.
Human rights and ICT standardization: What is W3C doing about this?
At the Brussels seminar on Human Rights and ICT Standardization, W3C contributed to the discussion on how human-rights principles can enter technical work while design choices are still open. The post connects Ethical Web Principles, accessibility, horizontal review, threat and harm modeling, and the practical cost of participation: making assumptions, impacts, and responsibilities visible before they become infrastructure.
- human rights
Threat Modeling with LEGO SERIOUS PLAY: Building your Digital Identity threat
Published:
By: Simone Onofri, W3C Security Lead and Giovanni Corti, Threat Modeling Community Group participant
W3C explored how Threat Modeling with LEGO SERIOUS PLAY can help uncover security, privacy, and human-rights threats in digital identity systems. Participants built threats from real-world harms, mapped them into shared landscapes, and discovered they are connected.
How to protect your Web applications from XSS
The W3C SWAG (Security Web Application Guidelines) Community Group, launched in June 2024, aims to simplify security features in web app development. SWAG's mission is to enhance web app security by creating best practices for developers and fostering collaboration. A key output includes videos on configuring CSP and Trusted Types, which mitigate XSS. Based on Google’s adoption experience, these resources offer tools to help developers securely configure these protections with minimal effort.