Uploaded April 2026 | Updated September 2026, 2 weeks ago
In this episode of Coffee with Developers, Mohamed Shiralizadeh from ING dives deep into one of the most overlooked but critical parts of web development: cookies.
From their origins at Netscape to their role in authentication, Mohamed breaks down how cookies actually work, where they’re stored, and why they can be a major security risk if misconfigured. Through live demos, he shows how attackers can exploit cookies via session hijacking, XSS attacks, and weak encryption—and how developers can defend against them using proper attributes like Secure, HttpOnly, and SameSite.
If you’ve ever clicked “Accept Cookies” without thinking twice, this episode will make you rethink everything.
00:00 – Intro & Guest Introduction
01:40 – What Cookies Are & Why They Matter
04:00 – Cookie Lifecycle Explained
06:00 – Where Cookies Are Stored (Live Demo)
09:50 – Cookie Attributes & Security Basics
20:10 – Advanced Security: Secure, HttpOnly & XSS
-------------
WeAreDevelopers is the global platform for developers and AI professionals to grow, connect, and lead in the age of AI. Millions of professionals use our year-round platform to build skills, explore thousands of hours of expert content, find career opportunities, and engage with a community that shares knowledge at scale. Companies partner with us to reach developers authentically, strengthening their employer brand, engaging top talent, and showcasing their products to a global network. Our flagship events in Europe, North America, and India bring together the world’s leading engineers, tech leaders, and companies. Together, we are driving the innovations that define the next era of technology.
Head to worldcongress.dev to secure 10% with the code "wearedevs_yt"
-------------
In this episode of Coffee with Developers, Mohamed Shiralizadeh from ING dives deep into one of the most overlooked but critical parts of web development: cookies.
From their origins at Netscape to their role in authentication, Mohamed breaks down how cookies actually work, where they’re stored, and why they can be a major security risk if misconfigured. Through live demos, he shows how attackers can exploit cookies via session hijacking, XSS attacks, and weak encryption—and how developers can defend against them using proper attributes like Secure, HttpOnly, and SameSite.
If you’ve ever clicked “Accept Cookies” without thinking twice, this episode will make you rethink everything.
00:00 – Intro & Guest Introduction
01:40 – What Cookies Are & Why They Matter
04:00 – Cookie Lifecycle Explained
06:00 – Where Cookies Are Stored (Live Demo)
09:50 – Cookie Attributes & Security Basics
20:10 – Advanced Security: Secure, HttpOnly & XSS
-------------
WeAreDevelopers is the global platform for developers and AI professionals to grow, connect, and lead in the age of AI. Millions of professionals use our year-round platform to build skills, explore thousands of hours of expert content, find career opportunities, and engage with a community that shares knowledge at scale. Companies partner with us to reach developers authentically, strengthening their employer brand, engaging top talent, and showcasing their products to a global network. Our flagship events in Europe, North America, and India bring together the world’s leading engineers, tech leaders, and companies. Together, we are driving the innovations that define the next era of technology.
Head to worldcongress.dev to secure 10% with the code "wearedevs_yt"
-------------










