Elektrine lite

← Feed

Frederik Braun �

freddy@social.security.plumbing

<p>A web/browser security nerd. Working on security for Firefox and the web at Mozilla. Taught web security at Ruhr Uni Bochum.</p><p>I often spend my summer on multi-week <a href="https://social.security.plumbing/tags/bikepacking" class="mention hashtag" rel="tag">#<span>bikepacking</span></a> trips with the family.</p><p>The posts here are my own and I do not speak for my employer</p>

Posts

  • View post

    It&#39;s Interop&#39;27 season! See the currently proposed focus areas for browsers to work on wide interoperability by the end of 2027. A friendly person has suggested we focus on the Sanitizer API https://github.com/web-platform-tests/interop/issues/1336, which is great. But I&#39;d love browsers to go even further: 1. Support other &quot;positions&quot; than just `setHTML` (e.g., prepend, append etc) 2. Trusted Types `createParserOptions` to prescribe a sanitizer instead of returning HTML...

  • View post

    When you tell us that it&#39;s not your fault, because the mistake was made by AI, you are not actually getting any absolution. In fact, you just admit that you did not check the thing that was supposed to be _your_ work.

  • View post

    Another security position at Mozilla. Help manage our (web) bug bounty program on HackerOne as a Senior Security Engineer https://job-boards.greenhouse.io/mozilla/jobs/8088831 (job posting says Germany, but other countries are eligible, use the job search)

  • View post

    Der Doppelpunkt fürs gendern: Weil markdown schon Unterstrich und Sternchen reserviert hat. #lifeprotip ##fuersiegetestet

  • View post

    Für alle die sich jetzt das Lied von Danger Dan angehört haben: Man kann ja klein anfangen. Einfach mal den Kiez verschönern, mit Aufklebern oder bedruckter Kleidung. Zum Beispiel Geflüchteten zeigen, das sie Willkommen sind. Oder lauft mit Regenbogen und freundlichem Gesicht herum. Sticker und Shirts gibt’s zum Beispiel bei @blackmosquito@systemli.social. Aber die sind natürlich nicht die einzigen. Tut was!

  • View post

    Firefox Networking team is looking for a student worker in Germany. Needs to be enrolled in a university. 20/hr per week. Great team! https://www.mozilla.org/en-US/careers/position/gh/8068406/

  • View post

    Got an email from a young and aspiring security researcher on career advice in the age of LLM. Hitting reply on gmail gives me a complete auto-generated LLM-suggested response with the full complete career advice. Wtf is wrong with people. Who thought building this would actually help anyone? I sent them my personal advice and added the slop as a &quot;P.S. This is what gmail auto-generated&quot;. Just couldn&#39;t bear not pointing out the stupidity.

  • View post

    @cure53@infosec.exchange @gaz@infosec.exchange look what I just walked by :D

  • View post

    Tried to debug a perl project I inherited using a local LLM. I have a M4 Max with 64GB. Running with opencode and often times getting stupid loops of the model trying the same thing over and over again or &quot;Iä Iä Cthulu Ftaghn&quot; output. Tried GPT-OSS 20B, Qwen3.5 9B which were completely terrible. Qwen 3.6 40B was better but horribly slow. Am I doing something wrong or are local models really this stupid?

  • View post

    Oh cool, over 50% of all traffic that cloudflare is seeing appears to be from bots. This chart only shows 4 weeks, querying for more doesn&#39;t work as it appears they just started collecting this kind of data. Source: https://radar.cloudflare.com/explorer?dataSet=http&amp;groupBy=bot_class&amp;filters=contentType%253DHTML&amp;dt=28d

  • View post

    Do you obsessively care about web performance? You can save one whole RTT by putting HTTPS (and H2/H3) support right in your DNS. Also gives you a bit more privacy (sometimes, it depends. Terms &amp; Conditions apply) See https://savearoundtrip.com/ for more. (HT @mxinden@mastodon.social)

  • View post

    RE: https://mastodon.social/@JulianOliver/116731404722832495 Reminder that Let’s Encrypt is a wonderful miracle but also a single point of failure. Nobody’s stopping you from starting a local clone of Let’s Encrypt in your country. With technology like Certificate Transparency, it’s pretty safe to use whatever available certificate authority is available to folks anyway.

  • View post

    @b0rk@social.jvns.ca @omarieclaire@mastodon.social congrats!

  • View post

    No plans for end of November yet? Consider joining us at the Owasp Day in Düsseldorf. It’s called German, but lots of talks are in English :-) From: @owasp_de https://infosec.exchange/@owasp_de/115464876256164866

  • View post

    New blog post: Why the Sanitizer API is just `setHTML()` - https://frederikbraun.de/why-sethtml.html

  • View post

    Looking for CTF challenge ideas that are educational but for the age of AI… I feel like I could wrote something monstrous with lots of red herrings, but that might be frustrating. I always liked building CTF challenges that didn’t require guessing and had a clear category and target.

  • View post

    RE: https://chaos.social/@kattascha/116544874792952276 @sveawindwehr 👀😊

  • View post

    Where do the people hang that read our hacks blog post and then went through all of the bugs that we opened up? Really eager for the deeper, informed takes now :) https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/

  • View post

    Anyone in Berlin from whom I can borrow an RTL-SDR (USB, ideally with antenna)? Ideally in West Berlin, near U7 or near Schlesi :)

  • View post

    When we said that we found and fixed hundreds of bugs in Firefox using AI, people were skeptical and said: Where are the bugs? Well, here they are. We are unhiding 12 security bugs that are representative of the issues we have found. https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/.

  • View post

    https://blog.mozilla.org/netpolicy/2026/05/05/mozilla-calls-on-uk-policymakers-to-address-the-roots-of-online-harm-not-undermine-the-open-web/

  • View post

    RE: https://infosec.exchange/@attackanddefense/116115800055258835 Watch this documentary and hear me say that I am not nervous at all and just a tiny bit excited while speaking really fast and gesturing like a mad man. This was awesome!

  • View post

    RE: https://infosec.exchange/@attackanddefense/116418875523198922 Q1 2026 was a very strong quarter for Firefox Security &amp;amp; Privacy. some highlights: - We expanded AI-assisted vulnerability discovery through our collaboration with Anthropic, helping identify and fix a high number of real security issues. - We shipped the Sanitizer API in Firefox 148, making Firefox the first browser to support this stronger defense against XSS. More in the newsletter linked below :)

  • View post

    Hey speakers! If you have some interesting app security story to share, consider submitting to the German OWASP Day CfP. Nice community event run by fine volunteer people. This year, the OWASP Day is in Karlsruhe on September 24th. https://god.owasp.de/2026/en/cfp.html

  • View post

    Who has two thumbs and arrived in Toronto without any luggage because it got stuck in Amsterdam? THIS GUY.

  • View post

    Während die Sanitizer API gerade dabei ist ihren Weg als Pull Request in den WHATWG HTML standard aufzunehmen, vernehme ich dass mein Beitrag zum @workingdraft noch viel viel mehr Hörer braucht. Klickt mal auf https://workingdraft.de/697/ und freut euch über nerdiges HTML/XSS-Gelaber mit @Schepp und mir :)

  • View post

    https://github.blog/news-insights/company-news/an-update-on-github-availability/ 🍿

  • View post

    Someone remind me, why did they remove and deprecate the `&amp;lt;blink&amp;gt;` HTML element but not the `&amp;lt;marquee&amp;gt;` element? Actually, scratch the first part. Why did they remove the former?

  • View post

    Ach ja?! Wenn ihr mich wirklich beeindrucken wollt, zeigt mir euren Schrank mit Tupperdosen. Aber aufgeräumt und ohne fehlende Teile!

  • View post

    I typically recommend people do not pick a Firefox fork because keeping up with security patches is a lot of work and being downstream of our code typically implies a delay. But if you feel like you really have to use a Firefox fork, I suggest you find one that has the means to ship an update within a day. From those I looked at, most did not bring an update based on 150 yet. (Special shout out to the Tor Browser. You&amp;#39;re awesome!)