Making Of: The Sanitizer API by Frederik Braun | Nullcon Berlin

34:43 · 05 Apr 2022 – 07 Apr 2022 · YouTube

About this talk

This talk addresses Cross-Site Scripting (XSS), a prevalent security vulnerability on the web, and introduces the forthcoming Sanitizer API, a built-in browser feature designed to ensure safe HTML output. The speaker provides essential context regarding XSS, analyzing the shortcomings of previous solutions and examining HTML parsing ambiguities that may lead to additional security risks, such as mXSS. The talk showcases the current prototype of the Sanitizer API, emphasizing its security considerations and encouraging both security researchers and developers to engage with this new technology. Frederik Braun, a Staff Security Engineer at Mozilla Firefox and a contributor to the W3C Web Application Security Working Group, leads this informative session.

From event

Nullcon Berlin 2022

05 Apr 2022 – 07 Apr 2022

All event videos
Back to Watch