Hej!
We are thrilled to announce Hack.lu CTF 2025 starts on Friday, October 17.
Top teams can win prizes from our sponsors: OffensiveCon, Zellic, PortSwigger, Binary Ninja, and HackTheBox.
All information on flu.xxx
@freddyb.bsky.social
I work on manager/security things for a non-profit software company. I love my family, my bike and reading books. You can also find me on Mastodon as @freddy@security.plumbing, which I consider my primary account. Homepage: https://frederikbraun.de/
Hej!
We are thrilled to announce Hack.lu CTF 2025 starts on Friday, October 17.
Top teams can win prizes from our sponsors: OffensiveCon, Zellic, PortSwigger, Binary Ninja, and HackTheBox.
All information on flu.xxx
Eine riesige Verbesserung der Lebensqualitรคt. Vielen Dank fรผr Ihren Einsatz! An wen schreibe ich einen hรถflichen Brief, dass die Ladebereiche vielleicht einen abgesenkten Bordstein fรผr einfacheres Entladen bekommen kรถnnten? InfraVelo oder Bezirksamt? Oder reicht hier? ;-)
26.09.2025 09:35 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0Text exceeds alt capacity.
I'm in a phenomenal talk on gender inequality in cybersecurity this morrning and this is such a great cheat sheet for intersectional fair employment.
01.08.2025 00:35 โ ๐ 179 ๐ 60 ๐ฌ 5 ๐ 1firefox container tabs are lowkey goated when $11/year VPS in dublin w/ socks5 over ssh is the vibe
25.07.2025 22:07 โ ๐ 154 ๐ 7 ๐ฌ 6 ๐ 1Wait, container tabs support individual proxy settings?
25.07.2025 23:27 โ ๐ 4 ๐ 2 ๐ฌ 1 ๐ 0We just opened the Call-for-Papers for the German OWASP Day 2025. The event will be held November 25th-26th in Dรผsseldorf.
god.owasp.de/2025/cfp.html
We're looking for all sorts of presentations about web security and beyond for an audience of builders, breakers and defenders.
cut my heap into pieces, this is my crash report:
allocation, no alignment
don't give a fuck if it faults on assignment
this is fatal abort()
CUT MY LIST IN TWO PIECES
THATโS HOW YOU START QUICKSORT
Closed the 6th floor. 3&4 are still going. Berlin and Toronto are the last offices.
31.05.2025 05:32 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0it's still the mozilla office ๐
28.05.2025 06:59 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0Echt Hammer, wie schรถn die Radwege sind. Aber wieso sind diese Fahrrad-Symbole so erhaben. Hรคtte man die nicht auch in glatt hingekriegt? Frage als absoluter Laie :)
26.05.2025 07:53 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0Just watched the talk video. well explained! So sad, that there are so many findings. Would you say most DOM-based XSS is mostly `innerHTML =` or what do people usually do?
25.05.2025 17:38 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0thank you!
25.05.2025 14:25 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0Do you intend to write it up as a blog post? Unfortunately, itโs not self-explanatory with slides? I am curious:) ps: Reminds me of frederikbraun.de/xss-digital-....
24.05.2025 17:25 โ ๐ 3 ๐ 0 ๐ฌ 1 ๐ 0end of an era ๐ blog.glitch.com/post/changes...
I know Glitch is working on project export but if you're git-capable, I built a tool that will mass-git-clone your public glitch projects: github.com/potch/glitch...
This is a complaint about the default. Defaults matter. You should know that.
22.05.2025 04:40 โ ๐ 2 ๐ 0 ๐ฌ 1 ๐ 0Pfff, you're four days late. We fixed this already on Saturday ๐
21.05.2025 18:42 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0Uh, pwn2own was...today? And we're shipping a bugfix release also today? Cool.
Update your Firefoxes, please :D
blog.mozilla.org/security/202...
We just published @firefox.com updates to fix the exploits used at the Pwn2Own contest yesterday and today. Both contestants achieved RCE in our content process but did not escape the sandbox.
blog.mozilla.org/security/202...
We have an initial plan for talks and breakout sessions at the Web Engines Hackfest 2025: github.com/Igalia/weben...
โข Monday: 9 talks and the W3C Web Apps WG F2F
โข Tuesday & Wednesday: 23 breakout sessions in 3 parallel tracks
There might be still small changes, but it gives a good overall picture.
The blue & white diamonds are the flag of Bavaria, which is very much not Berlin ๐ en.wikipedia.org/wiki/Bavaria
14.05.2025 08:18 โ ๐ 2 ๐ 0 ๐ฌ 3 ๐ 0I made this diagram for a talk on encrypted messaging I recently gave, and I didnโt get to use it in the talk. I figured Iโd share it here because I think it tells a story.
10.05.2025 12:45 โ ๐ 94 ๐ 30 ๐ฌ 11 ๐ 4New blog post: With Carrots & Sticks - Can the browser handle web security? https://frederikbraun.de/madweb-keynote-2025.html - This is the blog version of my keynote from MADWeb 2025 earlier this year. It's about how web security could become the browser's responsibility.
10.04.2025 10:43 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0Blog post about the road to HTTPS-First in Firefox. 
Early reports show an uptick in encrypted traffic by at least 1.5% for our global users. ๐
attackanddefense.dev/2025/03/31/h...
Based on the traffic I see - Mastodon is number 1, then LinkedIn, then Reddit, then Microsoft Teams, then Google, then BlueSky, then Twitter.
31.03.2025 22:38 โ ๐ 10 ๐ 2 ๐ฌ 0 ๐ 0Bon anniversaire ๐
18.03.2025 10:46 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0Nun gut, das probiere ich dann mal :) Ich hoffe auch, dass der heute entdeckte, neu ausgzeichnete Halteplatz fรผr Lieferanten auch noch was bringt. (Oh, Schleppkurve. Da hab ich was gelernt.) Danke!
18.03.2025 10:44 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0Die Ampel ist sowas von Verbesserungswรผrdig. Ich freu mich. Was mir in dem Zug (auch Fuรweg der Schรผler) noch aufgefallen ist, dass die neuen Pรถller an der Kreuzung Rosenheimer zu einer nur einseitigen Verbesserung des รberquerens gefรผhrt haben. Autos parken jetzt oft gegenรผber im nordwestlichen Eck
18.03.2025 07:38 โ ๐ 2 ๐ 0 ๐ฌ 1 ๐ 0Oh, and Firefox 136 also ships vertical tabs. Full release notes here www.mozilla.org/en-US/firefo...
05.03.2025 14:11 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0