Sign in

Lukas Weichselbaum

@webappsec.dev
2.4K followers 673 following 55 posts

Leading Google's web security team. Passionate about web security and making secure-by-default web development the norm. Contributed to web platfom security features like CSP, Fetch Metadata, COOP and Trusted Types.

PostsRepliesMedia
Lukas Weichselbaum @webappsec.dev · 09/04/2025
One of my teams at Google, 𝗔𝗜 𝗔𝗴𝗲𝗻𝘁 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆, is expanding in 𝗭𝘂𝗿𝗶𝗰𝗵 🇨🇭and 𝗡𝗲𝘄 𝗬𝗼𝗿𝗸 🇺🇸. We're looking for 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗘𝗻𝗴𝗶𝗻𝗲𝗲𝗿𝘀 with experience in attacking and securing AI/ML systems. DMs open.
143
Lukas Weichselbaum @webappsec.dev · 18/03/2025
Safari Tech Preview 215: Added support for Trusted Types 🎉 webkit.org/blog/16523/r...
webkit.org
Release Notes for Safari Technology Preview 215
Safari Technology Preview Release 215 is now available for download for macOS Sequoia and macOS Sonoma.
081
Reposted by Lukas Weichselbaum
Michele Spagnuolo @miki.it · 01/03/2025
Excited to present Security Signals with @ddworken.bsky.social and @webappsec.dev, my primary project at Google for the past five years. Thanks, @madwebwork.bsky.social! Paper: research.google/pubs/securit... Slides: speakerdeck.com/mikispag/sec...
research.google
Security Signals: Making Web Security Posture Measurable At Scale
0124
Reposted by Lukas Weichselbaum
Lukas Weichselbaum @webappsec.dev · 04/02/2025
Building secure web apps shouldn't be a burden. We've built a high-assurance web framework at Google that makes security easy for developers. Learn about our "Secure by Design" approach and how it works in our new blog post: bughunters.google.com/blog/6644316... cc: @ddworken.bsky.social
bughunters.google.com
Blog: Secure by Design: Google's Blueprint for a High-Assurance Web Framework
Learn more about how Google has created and deployed a high-assurance web framework that almost completely eliminates exploitable web vulnerabilities.
0185
Lukas Weichselbaum @webappsec.dev · 04/02/2025
Thank you!
010
Lukas Weichselbaum @webappsec.dev · 04/02/2025
great list! if you steel have free slots, I'd be grateful to be added as well. I post/blog mostly about web security. Latest: bughunters.google.com/blog/6644316...
bughunters.google.com
Blog: Secure by Design: Google's Blueprint for a High-Assurance Web Framework
Learn more about how Google has created and deployed a high-assurance web framework that almost completely eliminates exploitable web vulnerabilities.
110
Lukas Weichselbaum @webappsec.dev · 04/02/2025
Building secure web apps shouldn't be a burden. We've built a high-assurance web framework at Google that makes security easy for developers. Learn about our "Secure by Design" approach and how it works in our new blog post: bughunters.google.com/blog/6644316... cc: @ddworken.bsky.social
bughunters.google.com
Blog: Secure by Design: Google's Blueprint for a High-Assurance Web Framework
Learn more about how Google has created and deployed a high-assurance web framework that almost completely eliminates exploitable web vulnerabilities.
0185
Lukas Weichselbaum @webappsec.dev · 26/01/2025
Deserved!
030
Lukas Weichselbaum @webappsec.dev · 04/12/2024
Added! 🚀
000
Lukas Weichselbaum @webappsec.dev · 04/12/2024
The Great Google Password Heist: 15 years of hacking passwords to test our security (and build team culture!) bughunters.google.com/blog/6355265...
bughunters.google.com
Blog: The Great Google Password Heist: 15 years of hacking passwords to test our security (and build team culture!)
The Leaving Tradition in Google's security team, which could be described as a type of small-scale offensive security exercise, is a great (and fun) example of team culture. Curious? See this blog pos...
062
Lukas Weichselbaum @webappsec.dev · 02/12/2024
I haven't looked into MITRE's methodology, but at Google we're using "domain tiers": bughunters.google.com/blog/4562175... On TIER0 domains a critical vulnerability (e.g. XSS or authorization bypass) could lead to a full compromise of a user's account or execution of code on their or a cloud system.
bughunters.google.com
Blog: Externalizing the Google Domain Tiers Concept
Do you want to know more about the concept of domain tiers, understand how they are applied at Google, and view a list of Google's highest sensitivity domains? Take a look at this blog post to find ou...
110
Reposted by Lukas Weichselbaum
Freddy @freddyb.bsky.social · 27/11/2024
Modern solutions against cross-site attacks (frederikbraun.de/modern-solut...): An article about cross-site leak attacks and browser-based defenses. You will also learn why web security best practices is always opt-in and finally how YOU can get increased security controls.
frederikbraun.de
Modern solutions against cross-site attacks
Modern solutions against cross-site attacks
03419
Lukas Weichselbaum @webappsec.dev · 26/11/2024
Welcome @shhnjk.bsky.social 🎉
010
Lukas Weichselbaum @webappsec.dev · 26/11/2024
Thank you 🙏
000
Reposted by Lukas Weichselbaum
ChiefGyk3D @chiefgyk3d.com · 26/11/2024
This is my #IT, #Infosec, and #Cybersecurity starter pack. There’s plenty of room if some people want to be added too. But here are some feeds and people I recommend following go.bsky.app/QYMa3yN
4184
Lukas Weichselbaum @webappsec.dev · 26/11/2024
If you still have a spot, I'd love to get added. I write about web security, web platform security features and safe by design principles
100
Lukas Weichselbaum @webappsec.dev · 26/11/2024
These are all good points. One way to get good visibility into XSS issues on sensitive services is via bug bounty programs. At least this worked very well for us. Also CSP was a part of our approach of mitigating XSS at scale. See page 7: static.googleusercontent.com/media/public...
static.googleusercontent.com
100
Lukas Weichselbaum @webappsec.dev · 26/11/2024
Yes, this works (and imho the only approach that works at scale). See page 7 of Google's secure by design whitepaper: static.googleusercontent.com/media/public...
static.googleusercontent.com
010
Lukas Weichselbaum @webappsec.dev · 26/11/2024
MITRE: Cross-Site Scripting Is 2024's Most Dangerous Software Weakness www.darkreading.com/application-...
darkreading.com
Cross-Site Scripting: 2024's Most Dangerous Software
In addition to XSS, MITRE and CISA's 2024 list of the 25 most dangerous security vulnerability types (CWEs) also flagged out-of-bounds write, SQL injection, CSRF, and path traversal.
560
Lukas Weichselbaum @webappsec.dev · 26/11/2024
Unfortunately, the only way to make this work right now is by adding 'strict-dynamic' to your CSP. This an issue that comes up frequently, but we haven't so far been able to come up with an elegant way to this address this in the web platform. cc: @mikewe.st @arturjanc.bsky.social
020
Lukas Weichselbaum @webappsec.dev · 25/11/2024
Sure, added! Please add me to your Swiss Cyber Security package as well, I've been in CH since more than 10 years now =) bsky.app/starter-pack...
100
Lukas Weichselbaum @webappsec.dev · 24/11/2024
Must have been quite a journey! Congrats!
010
Lukas Weichselbaum @webappsec.dev · 24/11/2024
Of course! Added! So great that you're here too
110
Lukas Weichselbaum @webappsec.dev · 23/11/2024
Mamma mia!
030
Reposted by Lukas Weichselbaum
April King @april.social · 21/11/2024
Handling Cookies is a Minefield: Inconsistencies in the HTTP cookie specification and its implementations have caused a situation where countless websites (including Facebook, Netflix, Okta, WhatsApp, Apple, etc.) are one small mistake away from locking their users out. grayduck.mn/2024/11/21/h...
facebook errornetflix errorokta errorwhatsapp error
1216853
Lukas Weichselbaum @webappsec.dev · 22/11/2024
Congratulations, this is amazing! Since you asked, our Google CSP/Reporting API collector currently processes ~3.5B reports per day. That's for CSP, COOP, Trusted Types, and custom reporting. It has enabled us to truly scale up deployment of web platform security features across Google in a safe way
020
Lukas Weichselbaum @webappsec.dev · 21/11/2024
✋ web security & web platform security features nerd and in a hate/love relationship with CSP (it's complicated)
010
Lukas Weichselbaum @webappsec.dev · 21/11/2024
Check out @j-opdenakker.bsky.social starter pack too: go.bsky.app/HDnVb6K
110
Lukas Weichselbaum @webappsec.dev · 21/11/2024
absolutely! Added =)
000
Lukas Weichselbaum @webappsec.dev · 21/11/2024
Welcome Eduardo 🥳 Added you to the starter pack
110
Reposted by Lukas Weichselbaum
Koto @kkotowicz.bsky.social · 21/11/2024
@webappsec.dev has go.bsky.app/Uf8dZhz, it's a good one.
131
Reposted by Lukas Weichselbaum
AntSwig @antswig.bsky.social · 18/11/2024
What do you call a padlock for spiders? Web security! ... I'll see myself out...
042
Lukas Weichselbaum @webappsec.dev · 20/11/2024
That's great news, really love the high quality the content! The last two are already in the starter pack 👍
010
Reposted by Lukas Weichselbaum
Brian Tyler Cohen @briantylercohen.bsky.social · 19/11/2024
It took me twelve years (!) to build up my audience on Twitter. It took 5 days to surpass the 50% point of my Twitter following on Bluesky. I’m hopeful that the overall growth on this site will negate the need to go on Twitter altogether. Sad to see what it devolved into, but thrilled to see it die.
1996680434740
Reposted by Lukas Weichselbaum
Jay 🦋 @jay.bsky.team · 19/11/2024
Bluesky now has over 20M people!! 🎉 We've been adding over a million users per day for the last few days. To celebrate, here are 20 fun facts about Bluesky:
307013027816061
Lukas Weichselbaum @webappsec.dev · 19/11/2024
Thank you! It's really great to see the community grow here!
010
Reposted by Lukas Weichselbaum
terjanq @terjanq.me · 19/11/2024
Great article about multipart parsing. Reminds me about the bypasses I found in modsec parser medium.com/@terjanq/waf...
medium.com
WAF bypasses via 0days
based on findings from a live hacking event
1237
Lukas Weichselbaum @webappsec.dev · 18/11/2024
Also Signatures allows for nice advanced code provenance use cases like removing the CDN form the TCB by signing an OSS build in a github workflow and have the CDN pass on the pubkey.
000
Lukas Weichselbaum @webappsec.dev · 18/11/2024
Indeed signatures have different security properties, but since trusting a signature is an opt-in feature, I'm not worried about this.
100
Lukas Weichselbaum @webappsec.dev · 18/11/2024
added, thank you!
010
Lukas Weichselbaum @webappsec.dev · 18/11/2024
also please join me in thanking @mikewe.st, @ddworken.bsky.social and @yoav.ws for pushing this forward!
010
Lukas Weichselbaum @webappsec.dev · 18/11/2024
yeah, although the risk is that there'll be funky vendor solutions until there's browser support for proper solutions (like we proxy all scripts through our service or do some funky scanning to check if any of your scripts have changed)
100
Lukas Weichselbaum @webappsec.dev · 18/11/2024
@skypacks.bsky.social FYI =)
010
Lukas Weichselbaum @webappsec.dev · 18/11/2024
cc: @scotthelme.bsky.social reporting is being worked on as well
000
Lukas Weichselbaum @webappsec.dev · 18/11/2024
Signature-based SRI is being spec'd right now: wicg.github.io/signature-ba... This will be useful for many use case and become relevant for PCIv4 compliance which requires assuring the integrity of sourced scripts (6.4.3). Please chime in and share your use cases: github.com/WICG/signatu...
4143
Lukas Weichselbaum @webappsec.dev · 18/11/2024
Web security starter pack is in good shape now and includes many amazing folks passionate about web security like @terjanq.bsky.social and @shehackspurple.bsky.social: go.bsky.app/Uf8dZhz Please share and recommend folks passionate about web security so we can get this community started here 🙂
5198
Lukas Weichselbaum @webappsec.dev · 18/11/2024
this should qualify to being added to a starter pack for web security =D go.bsky.app/Uf8dZhz
120
Lukas Weichselbaum @webappsec.dev · 17/11/2024
Really love the energy here! Here's a starter pack for web security: go.bsky.app/Uf8dZhz
01211
Lukas Weichselbaum @webappsec.dev · 17/11/2024
Read all about how we made web security measurable at Google! Security signals have allowed us to massively scale our web security program and enabled us to deploy security features like CSP or Trusted Types at scale!
0113
Lukas Weichselbaum @webappsec.dev · 17/11/2024
I'm using burp for like 15 years now, but @agarri.fr's training was absolutely mind blowing and really super charged my burp skills!
011