Clarifications and errata from the course with timestamps.
Cross-site request forgery takes advantage of the trust that a web application, but in the video is misstated "trust user has in a website".
You will also see this sometimes stated as "trust a website has for your browser", but "trust a website has in a user" is how that should be stated, not the other way around.
The Shared Responsibility diagram IS CORRECT.
Color-coding in the legend below the "Shared Responsbility Model" is reversed.
In the video:
Correction:
There is a small typo in the slide. DNSSEC shows port 55, but should be port 53.