we1x Profile Banner
Lukas Weichselbaum Profile
Lukas Weichselbaum

@we1x

Followers
2K
Following
3K
Media
99
Statuses
1K

Leading @Google's web security team. Opinions are my own. Bluesky: @webappsec.dev

Joined January 2011
Don't wanna be here? Send us removal request.
@we1x
Lukas Weichselbaum
1 year
My @LocoMocoSec keynote slides on "Google's Recipe for Scaling (Web) Security" are online now:
Tweet media one
3
13
40
@we1x
Lukas Weichselbaum
2 months
RT @SecurityMB: Google CTF is on! Here's a challenge that I created: . Good luck πŸ˜€.
0
27
0
@we1x
Lukas Weichselbaum
3 months
RT @SecurityMB: Here's my blog post about escaping `<>` in attributes and why it makes mXSS harder to exploit!.
0
19
0
@we1x
Lukas Weichselbaum
3 months
RT @GoogleVRP: 🚨 Heads up for web devs! 🚨 . The HTML spec just got an important update to protect against mutation XSS (mXSS). Find out ho….
Tweet card summary image
bughunters.google.com
The HTML specification has been updated to escape '<' and '>' in attributes to prevent mutation XSS (mXSS) vulnerabilities. This post details the reasoning behind this change and explains why this...
0
58
0
@we1x
Lukas Weichselbaum
5 months
One of my teams at Google, π—”π—œ π—”π—΄π—²π—»π˜ π—¦π—²π—°π˜‚π—Ώπ—Άπ˜π˜†, is expanding in π—­π˜‚π—Ώπ—Άπ—°π—΅ πŸ‡¨πŸ‡­and π—‘π—²π˜„ 𝗬𝗼𝗿𝗸 πŸ‡ΊπŸ‡Έ. We're looking for π—¦π—²π—°π˜‚π—Ώπ—Άπ˜π˜† π—˜π—»π—΄π—Άπ—»π—²π—²π—Ώπ˜€ with experience in attacking and securing AI/ML systems. DMs open.
0
0
5
@we1x
Lukas Weichselbaum
6 months
Safari Tech Preview 215: Added support for Trusted Types πŸŽ‰.
Tweet card summary image
webkit.org
Safari Technology Preview Release 215 is now available for download for macOS Sequoia and macOS Sonoma.
0
2
17
@we1x
Lukas Weichselbaum
6 months
RT @0xAsm0d3us: @ryancbarnett @akamai_research This reminds me of this cool paper from Google I read years back. The best possible resource….
0
3
0
@we1x
Lukas Weichselbaum
6 months
RT @GoogleVRP: Developers, tired of DOM XSS in your web applications? 😩 We were too. See how we refactored our code to solve Trusted Types….
Tweet card summary image
bughunters.google.com
Join us as we take a closer look at the technical details of how we identified the root causes for TT violations in two flagship rollouts: Gmail and AppSheet.
0
24
0
@we1x
Lukas Weichselbaum
7 months
RT @dinodaizovi: This is a great example of secure by design through a framework-centric approach to security. The key idea is to build hig….
0
2
0
@we1x
Lukas Weichselbaum
7 months
RT @we1x: Building secure web apps shouldn't be a burden. We've built a high-assurance web framework at Google that makes security easy for….
0
14
0
@we1x
Lukas Weichselbaum
7 months
RT @royalhansen: "This blog post aims to provide a detailed blueprint for how Google has created and deployed a high-assurance web framewor….
Tweet card summary image
bughunters.google.com
Learn more about how Google has created and deployed a high-assurance web framework that almost completely eliminates exploitable web vulnerabilities.
0
16
0
@we1x
Lukas Weichselbaum
7 months
Building secure web apps shouldn't be a burden. We've built a high-assurance web framework at Google that makes security easy for developers. Learn about our "Secure by Design" approach and how it works in our new blog post: . cc: @ddworken
Tweet media one
0
14
53
@we1x
Lukas Weichselbaum
9 months
RT @ddworken: This is one of my favorite things about Google's security team, getting to work on security exercises like this is unimaginab….
0
1
0
@we1x
Lukas Weichselbaum
10 months
RT @yu5k3: Another great #infosec starter pack on #bluesky! Thanks, @we1x πŸ™Œ.
0
1
0
@we1x
Lukas Weichselbaum
10 months
Web security starter pack is in good shape now and includes many amazing folks passionate about web security like @terjanq or @shehackspurple:. Please share and recommend folks passionate about web security so we can get this community started there πŸ™‚
Tweet media one
2
1
6
@we1x
Lukas Weichselbaum
10 months
More than 200 new followers overnight on bluesky πŸš€.
@we1x
Lukas Weichselbaum
10 months
B l u e s k y is πŸ”₯ got 80 followers overnight! So many infosec folks over there.
0
0
2
@we1x
Lukas Weichselbaum
10 months
I put together a list of folks passionate about web security and related topics I follow on bluesky to stay on top of cool web bugs, web platform security features and fixes Please share, join us there or comment if know someone who should be on that list.
0
4
19
@we1x
Lukas Weichselbaum
10 months
Hey @clintgibler we're missing you and your awesome newsletter on bluesky!.I put together a starter pack for web security to make bootstrapping easier:
0
0
2
@we1x
Lukas Weichselbaum
10 months
B l u e s k y is πŸ”₯ got 80 followers overnight! So many infosec folks over there.
@we1x
Lukas Weichselbaum
10 months
Bootstrap your #infosec network on bluesky with @j_opdenakker's starter pack: Please comment below if you can recommend other starter packs for infosec or other topics πŸ™.
0
0
4
@we1x
Lukas Weichselbaum
10 months
RT @ayper: Excited to share our latest post on memory safety! We're tackling spatial safety in our massive C++ codebase by hardening libc+….
Tweet card summary image
security.googleblog.com
Posted by Alex Rebert and Max Shavrick, Security Foundations, and Kinuko Yasuda, Core Developer Attackers regularly exploit spatial mem...
0
51
0
@we1x
Lukas Weichselbaum
10 months
Bootstrap your #infosec network on bluesky with @j_opdenakker's starter pack: Please comment below if you can recommend other starter packs for infosec or other topics πŸ™.
0
5
8