<<Building on our earlier posts on defenses against web application flaws [ “Automating Web Application Security Testing” , “Meet ratproxy, our passive web security assessment tool” ], we introduce Automatic Context-Aware Escaping (Auto-Escape for short), a functionality we added to …

Reducing XSS by way of Automatic Context-Aware Escaping in Template Systems Read more »

<<For no particular reason other than to celebrate this particular Monday, I wanted to update developers on two Android-related news items. If you’re a developer who will be in the San Francisco Bay Area at the end of May, I …

Developer News Read more »