Elektrine lite

← Feed

Frederik Braun �

freddy@social.security.plumbing

<p>A web/browser security nerd. Working on security for Firefox and the web at Mozilla. Taught web security at Ruhr Uni Bochum.</p><p>I often spend my summer on multi-week <a href="https://social.security.plumbing/tags/bikepacking" class="mention hashtag" rel="tag">#<span>bikepacking</span></a> trips with the family.</p><p>The posts here are my own and I do not speak for my employer</p>

Posts

  • Post #4248956

    Another security position at Mozilla. Help manage our (web) bug bounty program on HackerOne as a Senior Security Engineer https://job-boards.greenhouse.io/mozilla/jobs/8088831 (job posting says Germany, but other countries are eligible, use the job search)

  • Post #4248905

    Der Doppelpunkt fürs gendern: Weil markdown schon Unterstrich und Sternchen reserviert hat. #lifeprotip ##fuersiegetestet

  • Post #3904973

    Für alle die sich jetzt das Lied von Danger Dan angehört haben: Man kann ja klein anfangen. Einfach mal den Kiez verschönern, mit Aufklebern oder bedruckter Kleidung. Zum Beispiel Geflüchteten zeigen, das sie Willkommen sind. Oder lauft mit Regenbogen und freundlichem Gesicht herum. Sticker und Shirts gibt’s zum Beispiel bei @blackmosquito@systemli.social. Aber die sind natürlich nicht die einzigen. Tut was!

  • Post #3866266

    Firefox Networking team is looking for a student worker in Germany. Needs to be enrolled in a university. 20/hr per week. Great team! https://www.mozilla.org/en-US/careers/position/gh/8068406/

  • Post #3859931

    Got an email from a young and aspiring security researcher on career advice in the age of LLM. Hitting reply on gmail gives me a complete auto-generated LLM-suggested response with the full complete career advice. Wtf is wrong with people. Who thought building this would actually help anyone? I sent them my personal advice and added the slop as a &quot;P.S. This is what gmail auto-generated&quot;. Just couldn&#39;t bear not pointing out the stupidity.

  • Post #3808256

    @cure53@infosec.exchange @gaz@infosec.exchange look what I just walked by :D

  • Post #3688170

    Tried to debug a perl project I inherited using a local LLM. I have a M4 Max with 64GB. Running with opencode and often times getting stupid loops of the model trying the same thing over and over again or &quot;Iä Iä Cthulu Ftaghn&quot; output. Tried GPT-OSS 20B, Qwen3.5 9B which were completely terrible. Qwen 3.6 40B was better but horribly slow. Am I doing something wrong or are local models really this stupid?

  • Post #3552631

    Oh cool, over 50% of all traffic that cloudflare is seeing appears to be from bots. This chart only shows 4 weeks, querying for more doesn&#39;t work as it appears they just started collecting this kind of data. Source: https://radar.cloudflare.com/explorer?dataSet=http&amp;groupBy=bot_class&amp;filters=contentType%253DHTML&amp;dt=28d

  • Post #3331923

    Do you obsessively care about web performance? You can save one whole RTT by putting HTTPS (and H2/H3) support right in your DNS. Also gives you a bit more privacy (sometimes, it depends. Terms &amp; Conditions apply) See https://savearoundtrip.com/ for more. (HT @mxinden@mastodon.social)

  • Post #3300386

    RE: https://mastodon.social/@JulianOliver/116731404722832495 Reminder that Let’s Encrypt is a wonderful miracle but also a single point of failure. Nobody’s stopping you from starting a local clone of Let’s Encrypt in your country. With technology like Certificate Transparency, it’s pretty safe to use whatever available certificate authority is available to folks anyway.

  • Post #2532108

    No plans for end of November yet? Consider joining us at the Owasp Day in Düsseldorf. It’s called German, but lots of talks are in English :-) From: @owasp_de https://infosec.exchange/@owasp_de/115464876256164866

  • Post #2532106

    New blog post: Why the Sanitizer API is just `setHTML()` - https://frederikbraun.de/why-sethtml.html

  • Post #2469438

    Looking for CTF challenge ideas that are educational but for the age of AI… I feel like I could wrote something monstrous with lots of red herrings, but that might be frustrating. I always liked building CTF challenges that didn’t require guessing and had a clear category and target.

  • Post #2469437

    RE: https://chaos.social/@kattascha/116544874792952276 @sveawindwehr 👀😊

  • Post #2436422

    Where do the people hang that read our hacks blog post and then went through all of the bugs that we opened up? Really eager for the deeper, informed takes now :) https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/

  • Post #2248485

    Anyone in Berlin from whom I can borrow an RTL-SDR (USB, ideally with antenna)? Ideally in West Berlin, near U7 or near Schlesi :)

  • Post #2198214

    When we said that we found and fixed hundreds of bugs in Firefox using AI, people were skeptical and said: Where are the bugs? Well, here they are. We are unhiding 12 security bugs that are representative of the issues we have found. https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/.

  • Post #2129335

    https://blog.mozilla.org/netpolicy/2026/05/05/mozilla-calls-on-uk-policymakers-to-address-the-roots-of-online-harm-not-undermine-the-open-web/

  • Post #2075443

    RE: https://infosec.exchange/@attackanddefense/116115800055258835 Watch this documentary and hear me say that I am not nervous at all and just a tiny bit excited while speaking really fast and gesturing like a mad man. This was awesome!

  • Post #2065576

    RE: https://infosec.exchange/@attackanddefense/116418875523198922 Q1 2026 was a very strong quarter for Firefox Security &amp;amp; Privacy. some highlights: - We expanded AI-assisted vulnerability discovery through our collaboration with Anthropic, helping identify and fix a high number of real security issues. - We shipped the Sanitizer API in Firefox 148, making Firefox the first browser to support this stronger defense against XSS. More in the newsletter linked below :)

  • Post #2058672

    Hey speakers! If you have some interesting app security story to share, consider submitting to the German OWASP Day CfP. Nice community event run by fine volunteer people. This year, the OWASP Day is in Karlsruhe on September 24th. https://god.owasp.de/2026/en/cfp.html

  • Post #1994884

    Who has two thumbs and arrived in Toronto without any luggage because it got stuck in Amsterdam? THIS GUY.

  • Post #1994883

    Während die Sanitizer API gerade dabei ist ihren Weg als Pull Request in den WHATWG HTML standard aufzunehmen, vernehme ich dass mein Beitrag zum @workingdraft noch viel viel mehr Hörer braucht. Klickt mal auf https://workingdraft.de/697/ und freut euch über nerdiges HTML/XSS-Gelaber mit @Schepp und mir :)

  • Post #1949363

    https://github.blog/news-insights/company-news/an-update-on-github-availability/ 🍿

  • Post #1885505

    Someone remind me, why did they remove and deprecate the `&amp;lt;blink&amp;gt;` HTML element but not the `&amp;lt;marquee&amp;gt;` element? Actually, scratch the first part. Why did they remove the former?

  • Post #1885504

    Ach ja?! Wenn ihr mich wirklich beeindrucken wollt, zeigt mir euren Schrank mit Tupperdosen. Aber aufgeräumt und ohne fehlende Teile!

  • Post #1785052

    I typically recommend people do not pick a Firefox fork because keeping up with security patches is a lot of work and being downstream of our code typically implies a delay. But if you feel like you really have to use a Firefox fork, I suggest you find one that has the means to ship an update within a day. From those I looked at, most did not bring an update based on 150 yet. (Special shout out to the Tor Browser. You&amp;#39;re awesome!)

  • Post #1784099

    Wow... :) https://xint.io/blog/copy-fail-linux-distributions

  • Post #1671878

    What Mythos access got us. Now public. https://blog.mozilla.org/en/privacy-security/ai-security-zero-day-vulnerabilities/

  • Post #1659242

    New Blog post: &quot;Multiple things can be true at the same time&quot; - https://frederikbraun.de/feels-and-llms.html :: Dear reader, I am sure you have read a lot of blog posts about AI in the past weeks or months. And now I too am writing. Mostly to help me cope with what my kind of hacker people would call out as hypocrisy or cognitive dissonance.