Bug Bounty Reports Discussed cover image

Bug Bounty Reports Discussed

From reporting self-XSSes to improving browser security mechanisms - Michał Bentkowski

Sep 6, 2023
Michał Bentkowski, specializes in crazy XSS bugs and now works on improving security of the browsers at Google. They discuss bug prevention efforts, browser updates and serialization issues, transitioning from simple bugs to complex ones, analyzing client-side issues, the discovery of ARP spoofing, the value of diverse backgrounds, prototype pollution in bug bounties, and their plans for a YouTube channel and client-side HTML sanitization.
01:30:29

Podcast summary created with Snipd AI

Quick takeaways

  • Michal Bentkowski transitioned from bug reporter to focusing on preventing and mitigating vulnerabilities in browsers at Google.
  • By updating browser specifications, Michal's team ensures the safety of users regardless of individual application support.

Deep dives

Transition from Bug Reporting to Improving Browser Security

The podcast episode features Michal Benkofsky, a cybersecurity expert who started his career as a bug reporter and eventually transitioned to working at Google to improve browser security mechanisms. Michal shares his background and journey, explaining how he shifted from finding vulnerabilities to focusing on preventing and mitigating them. He discusses his work at Google in the Information and Security Engineering team, where he strives to prevent various bug classes in web platforms by making changes to specifications and browser implementations. The podcast highlights the significance of browser updates and the instant impact they have on enhancing security across various applications.

Remember Everything You Learn from Podcasts

Save insights instantly, chat with episodes, and build lasting knowledge - all powered by AI.
App store bannerPlay store banner