Friend or Foe? TypeScript Security Fallacies
MIT Sloan: Lead AI Adoption Across Your Organization — Not Just Pilot It
AI, Data Science & Business Certificates from Google, IBM & Microsoft
Overview
Google, IBM & Meta Certificates — All 10,000+ Courses at 40% Off
One annual plan covers every course and certificate on Coursera. 40% off for a limited time.
Get Full Access
This conference talk explores whether TypeScript truly delivers on its promise of type security in real-world applications. Discover the common misconceptions developers have about TypeScript's security capabilities, particularly the confusion between development-time and runtime security protections. Learn about insecure TypeScript patterns, how HTTP parameter pollution vulnerabilities can compromise TypeScript codebases, and witness demonstrations of prototype pollution attacks that can bypass even schema validation libraries like Zod. Through practical examples and hands-on coding demonstrations, explore how attackers can exploit TypeScript applications and gain valuable insights into security best practices that can help strengthen your TypeScript codebase against real-world threats.
Syllabus
[VDBUH2025] Liran Tal - Friend or Foe? TypeScript Security Fallacies
Taught by
Devoxx