Making Of: The Sanitizer API by Frederik Braun | Nullcon Berlin
About this talk
This talk addresses Cross-Site Scripting (XSS), a prevalent security vulnerability on the web, and introduces the forthcoming Sanitizer API, a built-in browser feature designed to ensure safe HTML output. The speaker provides essential context regarding XSS, analyzing the shortcomings of previous solutions and examining HTML parsing ambiguities that may lead to additional security risks, such as mXSS. The talk showcases the current prototype of the Sanitizer API, emphasizing its security considerations and encouraging both security researchers and developers to engage with this new technology. Frederik Braun, a Staff Security Engineer at Mozilla Firefox and a contributor to the W3C Web Application Security Working Group, leads this informative session.
More from this event
See all 19 talks →
Keynote | High-assurance Code Reviews: How Consulting Works When The Risks Are High by Dan Guido
49:15
Night Track | GNU Anastasis: Privacy-Preserving Key Backup And Recovery by Christian Grothoff
28:47
Fuzzware: Automating & Scaling Fuzzing For Firmware by Tobias Scharnowski & Marius Muench | Nullcon
39:10
CXO Panel | Digital Identity In The Age Of Fintech | Nullcon Berlin 2022
56:07