How do cookies, localStorage, and sessionStorage differ on size and security?
PICTURE THIS: A SENTENCE BECOMES TOKENS
The model does not read letters like humans. It reads these pieces, then predicts the next one.
Simple meaning
Cookies are small, sent with matching requests, and can be HttpOnly so JS cannot steal them.
WHY — Browser instead of guessing?
Why interviewers care about Browser:
question about Browser.
trade-offs, and what you would actually do on a Frontend project - not buzzwords.
Name the idea, why it exists, then one short example.
End with when you use it and one common pitfall.
STEPS — What happens with tokens?
Before the model can read a sentence, it goes through these steps:
- 1Cookies are small, sent
with matching requests, and can be HttpOnly so JS cannot steal them.
- 2Web storage is larger,
origin-scoped, and fully readable by any script on the page.
- 3XSS makes localStorage tokens
easy to exfiltrate, which is why I prefer HttpOnly cookies for sessions.
- 4Context mix
Attention looks at nearby tokens together.
- 5Next token
The model scores what should come next.
- 6Decode
IDs turn back into readable text.
EXAMPLE — See it in action
Let's see how a real sentence is tokenized (tokens may vary by model):
Note: Actual tokens and IDs depend on the tokenizer (e.g., GPT, Llama, etc.).
Key takeaway
Cookies are small, sent with matching requests, and can be HttpOnly so JS cannot steal them. Web storage is larger, origin-scoped, and fully readable by any script on the page.