Lukas Weichselbaum

@webappsec.dev

Leading Google's web security team. Passionate about web security and making secure-by-default web development the norm. Contributed to web platfom security features like CSP, Fetch Metadata, COOP and Trusted Types.

One of my teams at Google, 𝗔𝗜 𝗔𝗴𝗲𝗻𝘁 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆, is expanding in 𝗭𝘂𝗿𝗶𝗰𝗵 🇨🇭and 𝗡𝗲𝘄 𝗬𝗼𝗿𝗸 🇺🇸. We're looking for 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗘𝗻𝗴𝗶𝗻𝗲𝗲𝗿𝘀 with experience in attacking and securing AI/ML systems. DMs open.

Building secure web apps shouldn't be a burden. We've built a high-assurance web framework at Google that makes security easy for developers. Learn about our "Secure by Design" approach and how it works in our new blog post: bughunters.google.com/blog/6644316... cc: @ddworken.bsky.social

Blog: Secure by Design: Google's Blueprint for a High-Assurance Web Framework

Learn more about how Google has created and deployed a high-assurance web framework that almost completely eliminates exploitable web vulnerabilities.

bughunters.google.com

Building secure web apps shouldn't be a burden. We've built a high-assurance web framework at Google that makes security easy for developers. Learn about our "Secure by Design" approach and how it works in our new blog post: bughunters.google.com/blog/6644316... cc: @ddworken.bsky.social

Blog: Secure by Design: Google's Blueprint for a High-Assurance Web Framework

Learn more about how Google has created and deployed a high-assurance web framework that almost completely eliminates exploitable web vulnerabilities.

bughunters.google.com

Handling Cookies is a Minefield: Inconsistencies in the HTTP cookie specification and its implementations have caused a situation where countless websites (including Facebook, Netflix, Okta, WhatsApp, Apple, etc.) are one small mistake away from locking their users out. grayduck.mn/2024/11/21/h...

facebook errornetflix errorokta errorwhatsapp error

Congratulations, this is amazing! Since you asked, our Google CSP/Reporting API collector currently processes ~3.5B reports per day. That's for CSP, COOP, Trusted Types, and custom reporting. It has enabled us to truly scale up deployment of web platform security features across Google in a safe way

Scott Helme@scotthelme.bsky.social · 2y ago

Over the last 24 hours, report-uri.com has processed more than 1,000,000,000 pieces of telemetry! This gives us a unique view of JavaScript behaviour across the Web, as observed by over 15,000,000 unique browsers around the World. Talk about Threat Intelligence capabilities!

It took me twelve years (!) to build up my audience on Twitter. It took 5 days to surpass the 50% point of my Twitter following on Bluesky. I’m hopeful that the overall growth on this site will negate the need to go on Twitter altogether. Sad to see what it devolved into, but thrilled to see it die.

Bluesky now has over 20M people!! 🎉 We've been adding over a million users per day for the last few days. To celebrate, here are 20 fun facts about Bluesky:

I'm in the process of creating a *web security* starter pack and need your help finding more webbies here. Please share and recommend folks passionate about web security in comments below so we can get this community started here 🙂 go.bsky.app/Uf8dZhz

Post nicht verfügbar.

Excited to share our latest blog post on memory safety! We’re tackling spatial safety in our massing C++ codebase by hardening live++ by default. It adds bounds checks to things like std::vector, preventing a fair bit of out-of-bounds vulnerabilities: security.googleblog.com/2024/11/retr...

Retrofitting Spatial Safety to hundreds of millions of lines of C++

Posted by Alex Rebert and Max Shavrick, Security Foundations, and Kinuko Yasada, Core Developer Attackers regularly exploit spatial mem...

security.googleblog.com