Blog

Thoughts on browser security, privacy, and the open internet

ai security research

Claude: King of the Hill

What happens when AI agents battle as autonomous attackers and defenders in a turn-based security experiment? I built a sandbox with four Claude agents and watched them try to break and fix a vulnerable web app...

coming soon
browser security

Navigation API origin confusion

How I found a logic bug in WebKit's experimental Navigation API using invariant checking instead of traditional crash-based fuzzing...

coming soon