Freddy's Avatar

Freddy

@freddyb.bsky.social

I work on manager/security things for a non-profit software company. I love my family, my bike and reading books. You can also find me on Mastodon as @freddy@security.plumbing, which I consider my primary account. Homepage: https://frederikbraun.de/

289 Followers  |  110 Following  |  55 Posts  |  Joined: 12.06.2023  |  1.8003

Latest posts by freddyb.bsky.social on Bluesky

Post image

Hej!

We are thrilled to announce Hack.lu CTF 2025 starts on Friday, October 17.

Top teams can win prizes from our sponsors: OffensiveCon, Zellic, PortSwigger, Binary Ninja, and HackTheBox.

All information on flu.xxx

08.10.2025 15:04 โ€” ๐Ÿ‘ 4    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Eine riesige Verbesserung der Lebensqualitรคt. Vielen Dank fรผr Ihren Einsatz! An wen schreibe ich einen hรถflichen Brief, dass die Ladebereiche vielleicht einen abgesenkten Bordstein fรผr einfacheres Entladen bekommen kรถnnten? InfraVelo oder Bezirksamt? Oder reicht hier? ;-)

26.09.2025 09:35 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
CRLite: Fast, private, and comprehensive certificate revocation checking in Firefox โ€“ Mozilla Hacks - the Web developer blog Firefox is now the first and the only browser to deploy fast and comprehensive certificate revocation checking that does not reveal your browsing activity to anyone (not even to Mozilla). ...
19.08.2025 17:59 โ€” ๐Ÿ‘ 2    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Text exceeds alt capacity.

Text exceeds alt capacity.

I'm in a phenomenal talk on gender inequality in cybersecurity this morrning and this is such a great cheat sheet for intersectional fair employment.

01.08.2025 00:35 โ€” ๐Ÿ‘ 179    ๐Ÿ” 60    ๐Ÿ’ฌ 5    ๐Ÿ“Œ 1

firefox container tabs are lowkey goated when $11/year VPS in dublin w/ socks5 over ssh is the vibe

25.07.2025 22:07 โ€” ๐Ÿ‘ 154    ๐Ÿ” 7    ๐Ÿ’ฌ 6    ๐Ÿ“Œ 1

Wait, container tabs support individual proxy settings?

25.07.2025 23:27 โ€” ๐Ÿ‘ 4    ๐Ÿ” 2    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
German OWASP Day 2025

We just opened the Call-for-Papers for the German OWASP Day 2025. The event will be held November 25th-26th in Dรผsseldorf.

god.owasp.de/2025/cfp.html

We're looking for all sorts of presentations about web security and beyond for an audience of builders, breakers and defenders.

02.07.2025 07:21 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

cut my heap into pieces, this is my crash report:
allocation, no alignment
don't give a fuck if it faults on assignment
this is fatal abort()

31.05.2025 17:26 โ€” ๐Ÿ‘ 442    ๐Ÿ” 77    ๐Ÿ’ฌ 6    ๐Ÿ“Œ 0

CUT MY LIST IN TWO PIECES

THATโ€™S HOW YOU START QUICKSORT

31.05.2025 02:21 โ€” ๐Ÿ‘ 1274    ๐Ÿ” 251    ๐Ÿ’ฌ 14    ๐Ÿ“Œ 7

Closed the 6th floor. 3&4 are still going. Berlin and Toronto are the last offices.

31.05.2025 05:32 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

it's still the mozilla office ๐Ÿ‘‹

28.05.2025 06:59 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Echt Hammer, wie schรถn die Radwege sind. Aber wieso sind diese Fahrrad-Symbole so erhaben. Hรคtte man die nicht auch in glatt hingekriegt? Frage als absoluter Laie :)

26.05.2025 07:53 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Just watched the talk video. well explained! So sad, that there are so many findings. Would you say most DOM-based XSS is mostly `innerHTML =` or what do people usually do?

25.05.2025 17:38 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

thank you!

25.05.2025 14:25 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
XSS in The Digital #ClimateStrike Widget XSS in The Digital #ClimateStrike Widget

Do you intend to write it up as a blog post? Unfortunately, itโ€™s not self-explanatory with slides? I am curious:) ps: Reminds me of frederikbraun.de/xss-digital-....

24.05.2025 17:25 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Important changes are coming to Glitch Weโ€™ve got an important update for the Glitch community today: Weโ€™ll be ending web hosting for your apps on Glitch.

end of an era ๐Ÿ’” blog.glitch.com/post/changes...

I know Glitch is working on project export but if you're git-capable, I built a tool that will mass-git-clone your public glitch projects: github.com/potch/glitch...

22.05.2025 20:26 โ€” ๐Ÿ‘ 16    ๐Ÿ” 3    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 1

This is a complaint about the default. Defaults matter. You should know that.

22.05.2025 04:40 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Pfff, you're four days late. We fixed this already on Saturday ๐Ÿ˜˜

21.05.2025 18:42 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Firefox Security Response to pwn2own 2025 โ€“ Mozilla Security Blog At Mozilla, we consider security to be a paramount aspect of the web. This is why not only does Firefox have a long running bug bounty program but also mature ...

Uh, pwn2own was...today? And we're shipping a bugfix release also today? Cool.

Update your Firefoxes, please :D

blog.mozilla.org/security/202...

17.05.2025 22:06 โ€” ๐Ÿ‘ 8    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Firefox Security Response to pwn2own 2025 โ€“ Mozilla Security Blog At Mozilla, we consider security to be a paramount aspect of the web. This is why not only does Firefox have a long running bug bounty program but also mature ...

We just published @firefox.com updates to fix the exploits used at the Pwn2Own contest yesterday and today. Both contestants achieved RCE in our content process but did not escape the sandbox.
blog.mozilla.org/security/202...

17.05.2025 21:22 โ€” ๐Ÿ‘ 24    ๐Ÿ” 8    ๐Ÿ’ฌ 3    ๐Ÿ“Œ 1
Preview
Home Web Engines Hackfest. Contribute to Igalia/webengineshackfest development by creating an account on GitHub.

We have an initial plan for talks and breakout sessions at the Web Engines Hackfest 2025: github.com/Igalia/weben...
โ€ข Monday: 9 talks and the W3C Web Apps WG F2F
โ€ข Tuesday & Wednesday: 23 breakout sessions in 3 parallel tracks
There might be still small changes, but it gives a good overall picture.

16.05.2025 15:43 โ€” ๐Ÿ‘ 13    ๐Ÿ” 9    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Bavaria - Wikipedia

The blue & white diamonds are the flag of Bavaria, which is very much not Berlin ๐Ÿ˜‰ en.wikipedia.org/wiki/Bavaria

14.05.2025 08:18 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 3    ๐Ÿ“Œ 0
Post image

I made this diagram for a talk on encrypted messaging I recently gave, and I didnโ€™t get to use it in the talk. I figured Iโ€™d share it here because I think it tells a story.

10.05.2025 12:45 โ€” ๐Ÿ‘ 94    ๐Ÿ” 30    ๐Ÿ’ฌ 11    ๐Ÿ“Œ 4

New blog post: With Carrots & Sticks - Can the browser handle web security? https://frederikbraun.de/madweb-keynote-2025.html - This is the blog version of my keynote from MADWeb 2025 earlier this year. It's about how web security could become the browser's responsibility.

10.04.2025 10:43 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
The Evolution of HTTPS Adoption in Firefox We at Mozilla believe that people deserve privacy and one of the most important pieces of web privacy is provided through ubiquitous encryption. Because of this, we shipped HTTPS-First by default as o...

Blog post about the road to HTTPS-First in Firefox.

Early reports show an uptick in encrypted traffic by at least 1.5% for our global users. ๐Ÿ˜Ž

attackanddefense.dev/2025/03/31/h...

02.04.2025 12:19 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Based on the traffic I see - Mastodon is number 1, then LinkedIn, then Reddit, then Microsoft Teams, then Google, then BlueSky, then Twitter.

31.03.2025 22:38 โ€” ๐Ÿ‘ 10    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Bon anniversaire ๐ŸŽˆ

18.03.2025 10:46 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Nun gut, das probiere ich dann mal :) Ich hoffe auch, dass der heute entdeckte, neu ausgzeichnete Halteplatz fรผr Lieferanten auch noch was bringt. (Oh, Schleppkurve. Da hab ich was gelernt.) Danke!

18.03.2025 10:44 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Die Ampel ist sowas von Verbesserungswรผrdig. Ich freu mich. Was mir in dem Zug (auch FuรŸweg der Schรผler) noch aufgefallen ist, dass die neuen Pรถller an der Kreuzung Rosenheimer zu einer nur einseitigen Verbesserung des รœberquerens gefรผhrt haben. Autos parken jetzt oft gegenรผber im nordwestlichen Eck

18.03.2025 07:38 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Oh, and Firefox 136 also ships vertical tabs. Full release notes here www.mozilla.org/en-US/firefo...

05.03.2025 14:11 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@freddyb is following 20 prominent accounts