Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Frederik Braun �

@freddy@social.security.plumbing
mastodon 4.7.3
  • Open on social.security.plumbing

A web/browser security nerd. Working on security for Firefox and the web at Mozilla. Taught web security at Ruhr Uni Bochum.

I often spend my summer on multi-week #bikepacking trips with the family.

The posts here are my own and I do not speak for my employer

1781 Followers
633 Following
50 Posts
Joined May 05, 2022
Website:
https://frederikbraun.de/
Location:
Berlin, Germany :club_mate:
Pronouns:
he/him
Signal username:
freddy.{default HTTPS port}
Open post
Frederik Braun � @freddy@social.security.plumbing
· 2w ago
When you tell us that it's not your fault, because the mistake was made by AI, you are not actually getting any absolution. In fact, you just admit that you did not check the thing that was supposed to be _your_ work.
19
0
8
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 2w ago

It's Interop'27 season! See the currently proposed focus areas for browsers to work on wide interoperability by the end of 2027.

A friendly person has suggested we focus on the Sanitizer API https://github.com/web-platform-tests/interop/issues/1336 which is great. But I'd love browsers to go even further:

  1. Support other "positions" than just setHTML (e.g., prepend, append etc)
  2. Trusted Types createParserOptions to prescribe a sanitizer instead of returning HTML texts

More here https://github.com/web-platform-tests/interop/issues/1416

GitHub

Web Sanitizer API · Issue #1336 · web-platform-tests/interop

Description The setHTML() method inserts HTML into the DOM in a way that prevents cross-site scripting attacks. The parseHTML() method of the Document object provides an XSS-safe method to parse an...

2
1
1
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 2mo ago
Für alle die sich jetzt das Lied von Danger Dan angehört haben: Man kann ja klein anfangen. Einfach mal den Kiez verschönern, mit Aufklebern oder bedruckter Kleidung. Zum Beispiel Geflüchteten zeigen, das sie Willkommen sind. Oder lauft mit Regenbogen und freundlichem Gesicht herum. Sticker und Shirts gibt’s zum Beispiel bei @blackmosquito@systemli.social. Aber die sind natürlich nicht die einzigen. Tut was!
39
0
21
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 3mo ago
RE: https://mastodon.social/@JulianOliver/116731404722832495 Reminder that Let’s Encrypt is a wonderful miracle but also a single point of failure. Nobody’s stopping you from starting a local clone of Let’s Encrypt in your country. With technology like Certificate Transparency, it’s pretty safe to use whatever available certificate authority is available to folks anyway.
mastodon.social

Julian Oliver: "A bit disappointed to see ISRG/LetsEncrypt fall i…" - Mastodon

57
1
65
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 2mo ago
Got an email from a young and aspiring security researcher on career advice in the age of LLM. Hitting reply on gmail gives me a complete auto-generated LLM-suggested response with the full complete career advice. Wtf is wrong with people. Who thought building this would actually help anyone? I sent them my personal advice and added the slop as a "P.S. This is what gmail auto-generated". Just couldn't bear not pointing out the stupidity.
23
0
12
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 3mo ago
Do you obsessively care about web performance? You can save one whole RTT by putting HTTPS (and H2/H3) support right in your DNS. Also gives you a bit more privacy (sometimes, it depends. Terms & Conditions apply) See https://savearoundtrip.com/ for more. (HT @mxinden@mastodon.social)
savearoundtrip.com

savearoundtrip

Publish an HTTPS DNS record. Let browsers reach HTTP/3 on the first connection instead of wasting a round trip.

36
0
29
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 2mo ago
Firefox Networking team is looking for a student worker in Germany. Needs to be enrolled in a university. 20/hr per week. Great team! https://www.mozilla.org/en-US/careers/position/gh/8068406/
mozilla.org
16
0
53
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 2mo ago
Der Doppelpunkt fürs gendern: Weil markdown schon Unterstrich und Sternchen reserviert hat. #lifeprotip ##fuersiegetestet
6
4
1
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 2mo ago
Replying to
@fribbledom@mastodon.social a nice quip, but don’t let anyone make you think that. the gym instructors are wild enthusiast. Find a comparable reference, who is not a sporty teenager. you can do it :)
9
2
0
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 3mo ago
Replying to
@afelia@chaos.social wo wirft man Geld ein - Spende an aula e.V.? wieviel Honorar ist so eine Podiumsdiskussion in etwa?
6
0
1
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 3mo ago
Replying to
@WPalant@infosec.exchange so, given the internet has been taken over by machines, do we go somewhere else? 😁
3
7
0
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 3mo ago
Oh cool, over 50% of all traffic that cloudflare is seeing appears to be from bots. This chart only shows 4 weeks, querying for more doesn't work as it appears they just started collecting this kind of data. Source: https://radar.cloudflare.com/explorer?dataSet=http&groupBy=bot_class&filters=contentType%253DHTML&dt=28d
radar.cloudflare.com
3
0
1
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 2mo ago
Replying to
@raptor@infosec.exchange @saelo@chaos.social https://www.youtube.com/watch?v=maWnIKH3JQI

Meet the Hackers: Samuel Groß | State of Browser/JavaScript Engine Exploitation

2
1
0
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 5mo ago

Where do the people hang that read our hacks blog post and then went through all of the bugs that we opened up? Really eager for the deeper, informed takes now :) https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/

Behind the Scenes Hardening Firefox with Claude Mythos Preview – Mozilla Hacks - the Web developer blog
Mozilla Hacks – the Web developer blog

Behind the Scenes Hardening Firefox with Claude Mythos Preview – Mozilla Hacks - the Web developer blog

New details about what we found, and how agentic harnesses are now able to reproduce real bugs and dismiss false positives.

5
4
4
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 2mo ago
Replying to
@WPalant@infosec.exchange ja. Vielleicht wird es daher (und mit den ganzen LLMs die am liebsten Markdown reden) zum nächsten HTML4, was parsing angeht :-)
1
0
0
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 2mo ago
Replying to
@WPalant@infosec.exchange habe leider schon alles gesehen, im fedi und sonst so. Zuviel markdown-dialekte, zuviel parser im Zoo.
1
2
0
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 2mo ago
Replying to
@WPalant@infosec.exchange I guess it’s implied
1
0
0
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 2mo ago
Replying to
@msfjarvis@fantastic.earth looks like that was a good advice, thanks. Also, comparing opencode with pi, the latter seems to be so much nicer
1
1
0
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 3mo ago
Replying to
@WPalant@infosec.exchange yeah, I didn't mean you should literally vandalize data centers... :)
1
1
0
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 3mo ago
Replying to
@WPalant@infosec.exchange hmmm... be the change you want to see in the world, I guess?
1
3
0
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 3mo ago
Replying to
@kzar@floss.social @WPalant@infosec.exchange yeah. probably just offline. actually matches my weekend plans. perfect.
1
0
0
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 3mo ago
Replying to
@isotopp@infosec.exchange @maxschrems@mastodon.social @noybeu@mastodon.social Mmmmh, lecker Popcorn 🍿
1
0
0
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 4mo ago
Replying to
@mhoye@cosocial.ca THIS metaphor! Just heard a related, incredibly mindblowing talk where Sergey Bratus (Prof at Dartmouth), said we could shift away from engineering mentality ("everything is broken, sure. Go build a better one") to a medical one ("information on this new pathogen in itself is useful research. Do go on.") - or put differently: we are all pest doctors now :D
2
6
0
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 5mo ago
Replying to
...update. the luggage did arrive a day later.
2
2
0
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 5mo ago
Replying to
@yoasif@mastodon.social You'll see attachments in some of the bugs. We asked the LLM to propose a patch, but it was real people who were assigned to the bug and they were of course free to pick a different approach. As with all patches in Firefox, we need a human author and another human to review the patch. https://firefox-source-docs.mozilla.org/contributing/ai-coding.html
firefox-source-docs.mozilla.org

Firefox AI Coding Policy — Firefox Source Docs documentation

2
1
0
1
Open post
Frederik Braun � @freddy@social.security.plumbing
· 4mo ago
Replying to
@eniko@mastodon.gamedev.place you can do that to almost any input search field, including wikipedia, dictionaries and your fedi instance :)
1
0
0
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 4mo ago
Replying to
@mhoye@cosocial.ca giving up has never looked so appealing 😅🥲😢😭
1
8
0
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 5mo ago
Replying to
@nik@toot.teckids.org danke dir, Nik
1
0
0
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 5mo ago
Replying to
@gabrielesvelto@mas.to good.
1
0
0
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 5mo ago
Replying to
@nf3xn@mastodon.social what? Are you trolling? The links to bugzilla have test cases for all of the twelve. Every one or them clearly, deterministically reproducing with ASAN.
1
1
0
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 5mo ago
Replying to
@skryking@infosec.exchange @AlesandroOrtiz@infosec.exchange less valid from bug bounty, given we found them first? :) might change over time of course
1
0
0
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 5mo ago
Replying to
@AlesandroOrtiz@infosec.exchange https://attackanddefense.dev/2026/03/13/bug-bounty-program-updates-2026.html :)
Attack & Defense

Bug Bounty Program Updates 2026

The Firefox bug bounty program is the longest-running security bug bounty program. Born out of Netscape’s bug bounty program, we’ve been awarding ingenious security research for over two decades, helping keep our hundreds of millions of users safe.

1
5
0
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 5mo ago
Replying to
@AlesandroOrtiz@infosec.exchange yeah, we will see how things go. Due to *gestures wildly* recent events, we also had a bit less submissions, so… 🤷‍♂️
1
1
0
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 3mo ago
Tried to debug a perl project I inherited using a local LLM. I have a M4 Max with 64GB. Running with opencode and often times getting stupid loops of the model trying the same thing over and over again or "Iä Iä Cthulu Ftaghn" output. Tried GPT-OSS 20B, Qwen3.5 9B which were completely terrible. Qwen 3.6 40B was better but horribly slow. Am I doing something wrong or are local models really this stupid?
0
4
0
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 5mo ago
Replying to
@endareth@disobey.net as written in the post, our harness did an evaluation to weed out false positives. All high severity bugs were deterministoccally reproducable (eg using addresssanitizer). At first, we had some of bugs where the attack requires non-default and obscure preferences in about:config. Once we had proper post-processing for default/unsopported config it just continued producing new and valuable findings of high severity. Still does.
0
0
0
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 4mo ago
Replying to
@tante@tldr.nettime.org @tieber@mastodon.social 🤩
0
0
0
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 5mo ago
Replying to
Maybe provide a hard and complex binary target that requires the participant to actually use an LLM and build their own harness? 🤔
0
0
0
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 5mo ago
Replying to
@yoasif@mastodon.social @HeNeArXn@chaos.social You can just click the bugs and see the attachments? :)
0
2
0
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 2w ago
Replying to
@gaz@infosec.exchange nice try, Gareth
0
1
0
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 5mo ago
Replying to
@yoasif@mastodon.social @HeNeArXn@chaos.social Yeah, I don't think we can share the tools but happy to answer questions :)
0
0
0
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 5mo ago
Replying to
@nf3xn@mastodon.social I don’t need to convince unknown-to-me internet people. So far, we have been more transparent than any other software I can think of. Try it out for yourself or don’t. :)
0
0
0
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 2mo ago
@cure53@infosec.exchange @gaz@infosec.exchange look what I just walked by :D
0
1
1
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 4mo ago
Replying to
@mhoye@cosocial.ca we seem to agree :)
0
0
0
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 5mo ago
Replying to
RE: https://social.security.plumbing/@freddy/116534213887768480 @enigmatico@mk.absturztau.be
social.security.plumbing

Frederik Braun �: "@yoasif@mastodon.social You'll see attachments in…" - security.plumbing

0
0
0
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 2mo ago
Replying to
As always, if we know each other, I am happy to be your referal.
0
0
0
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 2mo ago
Replying to
@buherator@infosec.place I think it’s too convenient to dismiss it as hype and marketing
0
1
0
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 3mo ago
Replying to
@cwebber@social.coop clearly the solution is not to run software at all.
0
0
0
0
Open post
Frederik Braun � @freddy@social.security.plumbing
· 5mo ago

RE: @kattascha@chaos.social

@sveawindwehr@d-64.social 👀😊

chaos.social

Katharina Nocun: "Übrigens: Ich freue mich immer ganz besonders übe…" - chaos.social

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 21:41:51 UTC