P.S. this account is write-only. I will only post announcements and blog post links. If you want to reach me, try mastodon or email m
17.01.2026 10:05 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0@freddyb.bsky.social
manager/security things for Firefox. love my family, my bike and reading books. You can also find me on Mastodon as @freddy@security.plumbing, which I consider my primary account. Homepage: https://frederikbraun.de/
P.S. this account is write-only. I will only post announcements and blog post links. If you want to reach me, try mastodon or email m
17.01.2026 10:05 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0this is your regular reminder that centralized, single-ownership social media is doomed
17.01.2026 10:05 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0โก I've been contributing micro-optimisations to Go's standard library in my spare time: github.com/golang/go/co...
๐ธ I don't intend to stop any time soon, but if you benefit from my work and would like to support it, consider sponsoring me on GitHub: github.com/sponsors/jub...
#golang #OpenSource
The Open Source Cryptography Workshop is returning for 2026, before Real World Crypto in Taipei. We are calling for session proposals, both presentations and hands-on workshops, on topics of interest to those who work on and with open source crypto. oscwork.shop/2026 #oscw #rwc #oscw2026 #rwc2026
06.01.2026 10:30 โ ๐ 1 ๐ 2 ๐ฌ 0 ๐ 0decoder hosted the session.
30.12.2025 19:02 โ ๐ 2 ๐ 0 ๐ฌ 0 ๐ 0Oh noes. Well see you next time, I suppose? On the upside, the talk was recorded. :)
30.12.2025 19:01 โ ๐ 2 ๐ 0 ๐ฌ 0 ๐ 0Hey #39c3. Come see my lightning talk on a safe variant for `.innerHTML ` that is built right into the browser. Tomorrow (day 2), at approximately 12:25 - events.ccc.de/congress/202...
27.12.2025 23:12 โ ๐ 11 ๐ 2 ๐ฌ 1 ๐ 0Hey #39c3, chat me up if you want to talk about web security, browser security. I will be one of the tall dudes with a Firefox hoodie :)
27.12.2025 23:10 โ ๐ 4 ๐ 1 ๐ฌ 0 ๐ 0lol, bsky wanting everyone's my birthday.
Follow me on mastodon, you cowards.
New blog post: Why the Sanitizer API is just `setHTML()` - https://frederikbraun.de/why-sethtml.html
07.12.2025 22:14 โ ๐ 42 ๐ 17 ๐ฌ 0 ๐ 0New blog post. Something off-topic to feed the search engine. A bug in Lego Star Wars: The Complete Saga (2007). https://frederikbraun.de/lego-star-wars-complete-saga-c3po-bug.html
07.12.2025 14:00 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0We had a first good outcome already (via Twitter). While `data` URLs are not what I would consider an XSS in the page, I still see it as a confusion that we should address head on. We have an issue filed in github.com/WICG/sanitiz... :)
04.11.2025 15:53 โ ๐ 2 ๐ 0 ๐ฌ 0 ๐ 0(Terms and conditions apply. Bounty payouts are at the discretion of the bug bounty committee etc. etc. But yes. Bugs in the sanitizer are eligible.)
03.11.2025 19:53 โ ๐ 2 ๐ 0 ๐ฌ 0 ๐ 0I don't know who needs a kitty headbutt right now, but here's one for you
03.11.2025 00:07 โ ๐ 32 ๐ 6 ๐ฌ 0 ๐ 0YES! :)
03.11.2025 19:49 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0Firefox nightly introduces the setHTML() method. Which is like a native DOMPurify. You can easily test it here:
portswigger-labs.net/mxss/
Set HTMLSanitizer โ
Auto update โ
I'm trying to break it, I encourage you to break it too
Hej!
We are thrilled to announce Hack.lu CTF 2025 starts on Friday, October 17.
Top teams can win prizes from our sponsors: OffensiveCon, Zellic, PortSwigger, Binary Ninja, and HackTheBox.
All information on flu.xxx
Eine riesige Verbesserung der Lebensqualitรคt. Vielen Dank fรผr Ihren Einsatz! An wen schreibe ich einen hรถflichen Brief, dass die Ladebereiche vielleicht einen abgesenkten Bordstein fรผr einfacheres Entladen bekommen kรถnnten? InfraVelo oder Bezirksamt? Oder reicht hier? ;-)
26.09.2025 09:35 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0Text exceeds alt capacity.
I'm in a phenomenal talk on gender inequality in cybersecurity this morrning and this is such a great cheat sheet for intersectional fair employment.
01.08.2025 00:35 โ ๐ 177 ๐ 57 ๐ฌ 3 ๐ 1firefox container tabs are lowkey goated when $11/year VPS in dublin w/ socks5 over ssh is the vibe
25.07.2025 22:07 โ ๐ 154 ๐ 6 ๐ฌ 6 ๐ 1Wait, container tabs support individual proxy settings?
25.07.2025 23:27 โ ๐ 5 ๐ 2 ๐ฌ 1 ๐ 0We just opened the Call-for-Papers for the German OWASP Day 2025. The event will be held November 25th-26th in Dรผsseldorf.
god.owasp.de/2025/cfp.html
We're looking for all sorts of presentations about web security and beyond for an audience of builders, breakers and defenders.
cut my heap into pieces, this is my crash report:
allocation, no alignment
don't give a fuck if it faults on assignment
this is fatal abort()
CUT MY LIST IN TWO PIECES
THATโS HOW YOU START QUICKSORT
Closed the 6th floor. 3&4 are still going. Berlin and Toronto are the last offices.
31.05.2025 05:32 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0it's still the mozilla office ๐
28.05.2025 06:59 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0Echt Hammer, wie schรถn die Radwege sind. Aber wieso sind diese Fahrrad-Symbole so erhaben. Hรคtte man die nicht auch in glatt hingekriegt? Frage als absoluter Laie :)
26.05.2025 07:53 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0Just watched the talk video. well explained! So sad, that there are so many findings. Would you say most DOM-based XSS is mostly `innerHTML =` or what do people usually do?
25.05.2025 17:38 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0thank you!
25.05.2025 14:25 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0