Lukas Weichselbaum

@we1x

Security Researcher Opinions are my own.

Регистриран през януари 2011 г.

Потребителят @we1x е блокиран

Наистина ли искаш да видиш тези туитове? Това няма да разблокира @we1x.

  1. Закачен туит
    26.09.2016 г.

    CSP-Evaluator () got released today! Find out if your is among the 95% that can be trivially bypassed!

  2. 19.01

    Wrote up a summary of some of the content security policy related work we have been up to on

  3. 11.01

    Edge now fully supports version 2 (incl. nonces). is on their radar.

  4. 28.11.2016 г.

    Glad to present at in Zürich "Breaking Bad Content Security Policies" with tomorrow, at 9:15, CAB G 61 –

  5. 25.11.2016 г.

    Goodbye ! GAE Scaffold now supports Closure Templates (strict autoescape!) with auto-noncing and nonce-based with .

  6. 11.11.2016 г.

    Thx everyone for joining my talk at You can read up everything about strict csp here:

  7. 10.11.2016 г.

    strict-dynamic support for landed in Firefox (nightly now, stable in FF52)! Kudos to the FF team

  8. 7.11.2016 г.
  9. 4.11.2016 г.

    Join my + 's tutorial on Adopting Strict Content Security Policy for XSS Protection

  10. 27.10.2016 г.

    Great work on CSP. Evaluation and defense proposal. by

  11. 25.10.2016 г.

    picked a particular nice place for dinner this year!

  12. 19.10.2016 г.
  13. 18.10.2016 г.

    I just pushed our open source version of CSP-Evaluator to github. Feel free to reuse checks & whitelist bypass list!

  14. 26.09.2016 г.

    We just released a blog post, docs and a couple of tools (Evaluator, Mitigator) to help adopting a secure

  15. 2.09.2016 г.

    This is one of the most important web sec papers in recent history: (section 3.4 is where the juicy bits are)

  16. 2.09.2016 г.

    Most offer no XSS protection and are based on whitelists(median 12) helps

  17. 1.09.2016 г.

    Our ( ) paper is out. 95% bypassable, whitelisting is doomed, helps.

  18. 1.09.2016 г.

    Our ( ) research paper (ACM CSS) is public now. It's time to drop whitelists!

  19. 4.08.2016 г.

    Want to learn how to adopt strict ? Drop by our ( ) tutorial for in Boston organized by !

  20. Lukas Weichselbaum последва , , and 70 others
    • @thegrugq

      Security Researcher :: Cultural Attaché :: PGP :: Не верь, не бойся, не проси

    • @mathias

      Web standards fanatic. JavaScript, HTML, CSS, HTTP, performance, security, Bash, Unicode, macOS.

Изглежда зареждането отнема известно време.

Twitter може да е претоварен или да изпитва моментно затруднение. Опитай отново или виж Twitter Status за повече информация.

    Може също да харесаш

    ·