Moderate Browser Question 88 of 229

How do cookies, localStorage, and sessionStorage differ on size and security?

Frontend Master · Speak this in 60–90 seconds · Faridabad & Delhi NCR

PICTURE THIS: A SENTENCE BECOMES TOKENS

The model does not read letters like humans. It reads these pieces, then predicts the next one.

Simple meaning

Cookies are small, sent with matching requests, and can be HttpOnly so JS cannot steal them.

1

WHY — Browser instead of guessing?

Why interviewers care about Browser:

This is a process

question about Browser.

Panels listen for order,

trade-offs, and what you would actually do on a Frontend project - not buzzwords.

Stay structured

Name the idea, why it exists, then one short example.

Close cleanly

End with when you use it and one common pitfall.

2

STEPS — What happens with tokens?

Before the model can read a sentence, it goes through these steps:

  1. 1
    Cookies are small, sent

    with matching requests, and can be HttpOnly so JS cannot steal them.

  2. 2
    Web storage is larger,

    origin-scoped, and fully readable by any script on the page.

  3. 3
    XSS makes localStorage tokens

    easy to exfiltrate, which is why I prefer HttpOnly cookies for sessions.

  4. 4
    Context mix

    Attention looks at nearby tokens together.

  5. 5
    Next token

    The model scores what should come next.

  6. 6
    Decode

    IDs turn back into readable text.

3

EXAMPLE — See it in action

Let's see how a real sentence is tokenized (tokens may vary by model):

Input text
“Web storage is larger, origin-scoped, and fully readable by any script on the pa”
Tokenized output
Webstorageislargeroriginscoped
Token IDs (example)
2987408337471632900

Note: Actual tokens and IDs depend on the tokenizer (e.g., GPT, Llama, etc.).

Key takeaway

Cookies are small, sent with matching requests, and can be HttpOnly so JS cannot steal them. Web storage is larger, origin-scoped, and fully readable by any script on the page.

Chat with us