Simone Onofri

W3C Security Lead

I am Simone Onofri. I work with standards groups on security review and threat modeling for the Web, particularly in digital identity, credentials, authentication, and browser-mediated systems. My work turns security, privacy, interoperability, and human-impact questions into artifacts that groups can review: threat models, specification issues, Security and Privacy Considerations, and practical guidance.

At W3C, I am Team Contact for the Security Interest Group and the Web Application Security, Web Authentication, and Federated Identity Working Groups. I also co-chair the Threat Modeling Community Group. These groups and their editors retain ownership of their documents and decisions.

Selected work

Research and background

In parallel with my W3C role, I am a doctoral researcher in the joint Executive Doctorate in Commercial Diplomacy at the University for Peace (UPEACE) and GIOYA HEI. My research examines how potential social impacts can be made reviewable in technical standardization. This academic work is distinct from W3C positions and Working Group decisions.

Earlier offensive and defensive Web-security work, including the book Attacking and Exploiting Modern Web Applications, provides the technical background for my current standards work.