Blog - Security
The W3C blog is for in-depth Web standards topics and educational materials. More information in About W3C Blog.
Browse categories
Browse archives
Threat modeling age-based content restrictions: what we learned at EIC 2026
At the European Identity and Cloud Conference (EIC 2026) in Berlin, we explored how Threat Modeling with LEGO® SERIOUS PLAY® can help uncover security, privacy, and human-rights threats in age-based content restriction systems. Starting from an Issuer-Holder-Verifier model, participants built harms such as exclusion, surveillance, profiling, and correlation, then mapped them back to flows, actors, and assumptions. The exercise showed how compliance choices can become Web architecture.
Human rights and ICT standardization: What is W3C doing about this?
At the Brussels seminar on Human Rights and ICT Standardization, W3C contributed to the discussion on how human-rights principles can enter technical work while design choices are still open. The post connects Ethical Web Principles, accessibility, horizontal review, threat and harm modeling, and the practical cost of participation: making assumptions, impacts, and responsibilities visible before they become infrastructure.
- human rights
Threat Modeling with LEGO SERIOUS PLAY: Building your Digital Identity threat
Published:
By: Simone Onofri, W3C Security Lead and Giovanni Corti, Threat Modeling Community Group participant
W3C explored how Threat Modeling with LEGO SERIOUS PLAY can help uncover security, privacy, and human-rights threats in digital identity systems. Participants built threats from real-world harms, mapped them into shared landscapes, and discovered they are connected.
How to protect your Web applications from XSS
The W3C SWAG (Security Web Application Guidelines) Community Group, launched in June 2024, aims to simplify security features in web app development. SWAG's mission is to enhance web app security by creating best practices for developers and fostering collaboration. A key output includes videos on configuring CSP and Trusted Types, which mitigate XSS. Based on Google’s adoption experience, these resources offer tools to help developers securely configure these protections with minimal effort.