Michał Bentkowski (@SecurityMB) 🦻

Michał Bentkowski (@SecurityMB) 🦻's avatar
Michał Bentkowski (@SecurityMB) 🦻
npub1j2l6...tszt
Information security engineer at Google. Opinions are mine. Personal website: https://bentkowski.info Twitter: https://twitter.com/SecurityMB
Today we published two blog posts about an HTML specification change that makes mutation XSS harder to exploit! Long story short: `<` and `>` are now escaped in attributes. * Blog post about security rationale behind this change: * Blog post about how it affects web developers: