While updating my Twitter bio to point here (hi!), I came across @cure53's keynote from Nullcon a few months ago: https://youtu.be/IEv2t_mABXM.
It massively overstates my role in rolling out `SameSite` cookies by default, but a core message resonates with me: we should aim to change the web's default behavior when possible, because opt-in mitigations are difficult to scale.
These are, unfortunately, also the hardest changes to ship precisely because they have sweeping effects across the ecosystem.
