Lukas Weichselbaum (@we1x) 's Twitter Profile
Lukas Weichselbaum

@we1x

Leading @Google's web security team. Opinions are my own.
Bluesky: @webappsec.dev

ID: 239904210

linkhttp://webappsec.dev calendar_today18-01-2011 18:10:04

1,1K Tweet

2,2K Takipรงi

504 Takip Edilen

Lukas Weichselbaum (@we1x) 's Twitter Profile Photo

Hey Clint Gibler we're missing you and your awesome newsletter on bluesky! I put together a starter pack for web security to make bootstrapping easier: bsky.app/starter-pack-sโ€ฆ

Lukas Weichselbaum (@we1x) 's Twitter Profile Photo

I put together a list of folks passionate about web security and related topics I follow on bluesky to stay on top of cool web bugs, web platform security features and fixes go.bsky.app/Uf8dZhz Please share, join us there or comment if know someone who should be on that list

Lukas Weichselbaum (@we1x) 's Twitter Profile Photo

Web security starter pack is in good shape now and includes many amazing folks passionate about web security like terjanq or Tanya Janca | Shehackspurple: go.bsky.app/Uf8dZhz Please share and recommend folks passionate about web security so we can get this community started there ๐Ÿ™‚

Web security starter pack is in good shape now and includes many amazing folks passionate about web security like <a href="/terjanq/">terjanq</a> or <a href="/shehackspurple/">Tanya Janca | Shehackspurple</a>:

go.bsky.app/Uf8dZhz

Please share and recommend folks passionate about web security so we can get this community started there ๐Ÿ™‚
David Dworken (@ddworken) 's Twitter Profile Photo

This is one of my favorite things about Google's security team, getting to work on security exercises like this is unimaginably exciting

Lukas Weichselbaum (@we1x) 's Twitter Profile Photo

Building secure web apps shouldn't be a burden. We've built a high-assurance web framework at Google that makes security easy for developers. Learn about our "Secure by Design" approach and how it works in our new blog post: bughunters.google.com/blog/664431627โ€ฆ cc: David Dworken

Building secure web apps shouldn't be a burden. We've built a high-assurance web framework at Google that makes security easy for developers. Learn about our "Secure by Design" approach and how it works in our new blog post: 
bughunters.google.com/blog/664431627โ€ฆ

cc: <a href="/ddworken/">David Dworken</a>
Royal Hansen (@royalhansen) 's Twitter Profile Photo

"This blog post aims to provide a detailed blueprint for how Google has created and deployed a high-assurance web framework that almost completely eliminates exploitable web vulnerabilities." bughunters.google.com/blog/664431627โ€ฆ

Dino A. Dai Zovi (@dinodaizovi) 's Twitter Profile Photo

This is a great example of secure by design through a framework-centric approach to security. The key idea is to build high-level frameworks that abstract away and address as many security risks as possible to make security better by default and as easy as possible for apps.

Google VRP (Google Bug Hunters) (@googlevrp) 's Twitter Profile Photo

Developers, tired of DOM XSS in your web applications? ๐Ÿ˜ฉ We were too. See how we refactored our code to solve Trusted Types violations in Gmail & AppSheet. Your guide to a safer web is here! bughunters.google.com/blog/585078655โ€ฆ

Lukas Weichselbaum (@we1x) 's Twitter Profile Photo

One of my teams at Google, ๐—”๐—œ ๐—”๐—ด๐—ฒ๐—ป๐˜ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜†, is expanding in ๐—ญ๐˜‚๐—ฟ๐—ถ๐—ฐ๐—ต ๐Ÿ‡จ๐Ÿ‡ญand ๐—ก๐—ฒ๐˜„ ๐—ฌ๐—ผ๐—ฟ๐—ธ ๐Ÿ‡บ๐Ÿ‡ธ. We're looking for ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—˜๐—ป๐—ด๐—ถ๐—ป๐—ฒ๐—ฒ๐—ฟ๐˜€ with experience in attacking and securing AI/ML systems. DMs open.

Google VRP (Google Bug Hunters) (@googlevrp) 's Twitter Profile Photo

๐Ÿšจ Heads up for web devs! ๐Ÿšจ The HTML spec just got an important update to protect against mutation XSS (mXSS). Find out how escaping < and > in attributes is making the web a safer place. bughunters.google.com/blog/503874286โ€ฆ

terjanq (@terjanq) 's Twitter Profile Photo

We published a blogpost about SafeContentFrame - a library for rendering untrusted content inside an iframe. The library is a big party of what I've been up to in the few last years! Check out the blog and take a slice of my birthday cake ๐ŸŽ‚! bughunters.google.com/blog/671552987โ€ฆ

We published a blogpost about SafeContentFrame - a library for rendering untrusted content inside an iframe. The library is a big party of what I've been up to in the few last years! Check out the blog and take a slice of my birthday cake ๐ŸŽ‚!

bughunters.google.com/blog/671552987โ€ฆ
Google VRP (Google Bug Hunters) (@googlevrp) 's Twitter Profile Photo

ยกHola from init.g(mexico) we are LIVE! Crazy excited to meet all the incredible students who joined init.g(mexico) today! Very much looking forward to seeing how these bright minds can shape the security industry of tomorrow! Let the learning and hacking begin! init.g() { return

ยกHola from init.g(mexico) we are LIVE! 
Crazy excited to meet all the incredible students who joined init.g(mexico) today! Very much looking forward to seeing how these bright minds can shape the security industry of tomorrow!
Let the learning and hacking begin! init.g() { return