webappsec.dev

$ls -lt ~/slides

Talks, slide by slide.

Every deck I can share, readable right here, with its PDF beside it. Arrow keys or swipe; every slide has its own link.

total 6 · 386 slides · no trackers, no third parties, strict CSP

  1. LocoMocoSec · Kaua'i · 2024 · 78 slides keynote

    A Recipe for Scaling (Web) Security

    Lessons from Google's Frontlines

    How Google cut XSS across hundreds of apps: fix root causes in the browser, ship frameworks that are safe by default, and patch legacy code with data and tooling.

  2. SIGS — Security Interest Group Switzerland · Zürich · 2026 · 76 slides

    From Prompt Injections to Rogue Actions

    Securing AI Agents in Practice

    How prompt injection makes an agent leak data or go rogue, and how Google layers defenses: a policy engine, hardened models, and sanitized output.

  3. NDSS MADWeb · San Diego · 2025 · 41 slides

    Security Signals

    Making Web Security Posture Measurable At Scale

    How Google measures the security posture of 8,000+ web services from sampled HTTP traffic, then uses it to drive and track rollouts.

  4. SecAppDev · Leuven · 2023 · 75 slides

    Modern Security Features

    for web applications

    Four browser features that stop XSS and cross-site leaks: nonce CSP, Trusted Types, Fetch Metadata and COOP, with Google's adoption numbers from 2019 to 2023.

  5. Google I/O · Mountain View · 2019 · 60 slides

    Securing web apps with modern platform features

    Four browser features that stop XSS and cross-site attacks: nonce-based CSP, Trusted Types, Fetch Metadata and Cross-Origin Opener Policy.

  6. LocoMocoSec · Kaua'i · 2019 · 56 slides

    Content Security Policy

    A successful mess between hardening and mitigation

    Google's 2018 data: a nonce-based CSP blocked 60 to 80% of reported XSS. Five policy levels, ending at nonce-only.

The full list — 37 talks and lectures since 2009 — lives at ~/talks. Want one of these on your stage? Invite me.