which browser security features do you find the hardest to use correctly?

very interested in "other" responses too, I could only include 4 options in the poll

CORS
51.6%
Cookie security settings (HttpOnly etc)
5.3%
Content-Security-Policy
41%
Other
2.2%
Poll ended at .
@b0rk Last time I did webdev seriously, it was cross-domain cookie security for SSO use cases. It was in flux and the specs kept changing. Probably it's better and stable now.