ls -lt ~/posts
Longer than a slide, shorter than a paper.
Keynotes written out in full, with the numbers and the material a 45-minute slot cannot hold. The guides and blog posts I wrote elsewhere are listed underneath.
total 1 · no trackers, no third parties, strict CSP
-
Sep 2026 · keynote, written out · OWASP AppSec Days Portugal, Porto · ~35 min
It's never been easier to write (in)secure software
Turning AI, the fastest coder, into the safest
Why AI made insecure code cheap, why the same shift makes secure code cheaper still, and the benchmark that shows the environment, not the model, sets the floor.
written elsewhere
- 2024Secure by Design: Google's Blueprint for a High-Assurance Web FrameworkGoogle Bug Hunters Blog
- 2024An Overview of Google's Commitment to Secure by Designcontributor: wrote the web security section
- 2021Mitigate XSS with a strict Content Security Policyweb.dev
- 2020Protect your resources from web attacks with Fetch Metadataweb.dev
- 2020Towards native security defenses for the web ecosystemGoogle Security Blog
- 2016Reshaping web defenses with strict Content Security PolicyGoogle Security Blog
- 2016Scalable vendor security reviewsGoogle Security Blog
Papers are at ~/pubs, decks at ~/slides. Want the talk rather than the essay? Invite me.