Security
14 terms in this category.
Content Security Policy
A header that limits which scripts, styles and other resources a page is allowed to load.
Cross-Site Request Forgery
Tricking a logged-in user's browser into sending an unwanted authenticated request to another site.
Cross-Site Scripting
A vulnerability that lets an attacker run JavaScript in another user's browser session on a trusted site.
End-to-End Encryption
Encryption where only the sender and recipient can read the message — not the service provider in the middle.
HSTS
A header that tells browsers to only ever load a site over HTTPS, even if the user types http://.
HTTPS
The encrypted version of HTTP, the protocol your browser uses to talk to websites.
Malvertising
The use of legitimate online advertising networks to deliver malicious code or scams to users.
Man-in-the-Middle Attack
An attacker positioned between you and the site you're talking to, reading or altering traffic.
Passkey
A phishing-resistant replacement for passwords built on public-key cryptography.
Password Manager
An app that generates, stores and autofills unique strong passwords for every site.
Phishing
An attempt to trick users into handing over credentials or money by impersonating a trusted entity.
Safe Browsing
A browser service that warns before you visit a known phishing or malware site.
TLS
The cryptographic protocol that secures HTTPS and most modern network traffic.
Two-Factor Authentication
Requiring a second credential — a code, a hardware key, a passkey — in addition to a password.

Add to Chrome