Sign in

Freddy

@freddyb.bsky.social
351 followers 112 following 78 posts

manager/security things for Firefox. love my family, my bike and reading books. You can also find me on Mastodon as @freddy@security.plumbing, which I consider my primary account. Homepage: frederikbraun.de

PostsRepliesMedia
Freddy @freddyb.bsky.social · 20/08/2026
My presentation from OWASP AppSec '26 in Vienna is finally public. Watch me talk about XSS and XSS and Cross-Site Scripting, and XSS in this talk titled "The Devil Is In The Defaults: What To Do About XSS" youtube.com/watch?v=b7RlQdvPY3 (It's also about XSS).
youtube.com
YouTube
Share your videos with friends, family, and the world
132
Reposted by Freddy
Freddy @freddyb.bsky.social · 31/05/2026
The S in interoperability (frederikbraun.de/the-s-in-interoper…): A blog post about standards, their proliferation and the issues that arive over time.
021
Freddy @freddyb.bsky.social · 31/05/2026
The S in interoperability (frederikbraun.de/the-s-in-interoper…): A blog post about standards, their proliferation and the issues that arive over time.
021
Freddy @freddyb.bsky.social · 24/04/2026
New Blog post: "Multiple things can be true at the same time" - frederikbraun.de/feels-and-ll... Dear reader, I am sure you have read a lot of blog posts about AI in the past weeks or months. This is my post.…
frederikbraun.de
Multiple things can be true at the same time
Multiple things can be true at the same time
052
Freddy @freddyb.bsky.social · 21/04/2026
blog.mozilla.org/en/privacy-s...
blog.mozilla.org
The zero-days are numbered  | The Mozilla Blog
Since February, the Firefox team has been working around the clock using frontier AI models to find and fix latent security vulnerabilities in the browser.
020
Reposted by Freddy
Nadim Kobeissi @nadim.computer · 23/03/2026
Major announcement: My highly successful Applied Cryptography course taught last year at the American University of Beirut is returning as an online course, available for FREE for any qualifying student from any Lebanese university! Read more + apply today — and please spread the word!
symbolic.software
Applied Cryptography: Free Online Course for 50 Lebanese University Students This Summer
We're opening 50 spots for students at Lebanese universities to take the Applied Cryptography course online, completely free of charge, starting June 2026. Applications are open now.
1133
Reposted by Freddy
Deirdre Connolly¹ ² @durumcrustulum.com · 09/03/2026
Next up, 'Improving the Trustworthiness of Javascript on the Web', presented by Michael Rosenberg, Giulio Berra, Ezzudin Alkotob, and Dennis Jackson #realworldcrypto
171
Freddy @freddyb.bsky.social · 07/03/2026
OK, ok. I'll stop blogging for today. I promise.
000
Freddy @freddyb.bsky.social · 07/03/2026
Composing Sanitizer configurations (frederikbraun.de/composable-sanitiz…): The HTML Sanitizer API allows multiple ways to customize the default allow list and this blog post aims to describe a few variations and tricks we came up with while writing the specification.
010
Freddy @freddyb.bsky.social · 07/03/2026
New blog post: Perfect types with `setHTML()` - frederikbraun.de/perfect-types-with… - TLDR: Use require-trusted-types-for 'script'; trusted-types 'none'; in your CSP and nothing besides setHTML() works, essentially removing all DOM-XSS risks....
1113
Reposted by Freddy
David Bushell 🪿 @dbushell.com · 03/03/2026
c'mon Safari
HTML Sanitizer API browser support list with unsupported Safari being poked with a stick by the White Ninja meme
01079
Freddy @freddyb.bsky.social · 02/03/2026
I was invited to join the @shoptalkshow.com podcast and talk about my favorite topic. The HTML Sanitizer API and `setHTML()`. Give it a spin in your favorite podcast player :) shoptalkshow.com/704/
shoptalkshow.com
704: Sanitizer API with Frederik Braun
We talk with Frederik Braun from Mozilla about the Sanitizer API, how it works with HTML tags and web components, what it does with malformed HTML, and where CSP fits in alongside the Sanitizer API…
000
Freddy @freddyb.bsky.social · 24/02/2026
we did a thing! Congrats to the team for getting this out.
160
Freddy @freddyb.bsky.social · 17/01/2026
this is your regular reminder that centralized, single-ownership social media is doomed
110
Reposted by Freddy
jub0bs @jub0bs.com · 30/08/2025
⚡ I've been contributing micro-optimisations to Go's standard library in my spare time: github.com/golang/go/co... 💸 I don't intend to stop any time soon, but if you benefit from my work and would like to support it, consider sponsoring me on GitHub: github.com/sponsors/jub... #golang #OpenSource
github.com
Sponsor @jub0bs on GitHub Sponsors
infosec enthusiast • Go developer & trainer • minimalist • chaotic good • trying to make sense of the Web • he/him
1172
Reposted by Freddy
Anna Weine @an-dante.bsky.social · 06/01/2026
The Open Source Cryptography Workshop is returning for 2026, before Real World Crypto in Taipei. We are calling for session proposals, both presentations and hands-on workshops, on topics of interest to those who work on and with open source crypto. oscwork.shop/2026 #oscw #rwc #oscw2026 #rwc2026
oscwork.shop
OSCW 2026: Taipei, Taiwan :: Open Source Cryptography Workshop
OSCW 2026 will take place 8 March 2026, the day before Real World Crypto
002
Freddy @freddyb.bsky.social · 27/12/2025
Hey #39c3. Come see my lightning talk on a safe variant for `.innerHTML ` that is built right into the browser. Tomorrow (day 2), at approximately 12:25 - events.ccc.de/congress/202...
events.ccc.de
[39c3] Lightning Talks - Tag 2
- **Lightning Talks Introduction** - **Chaos auf der Schiene: Die Wahrheit hinter den Verspätungen** — *poschi* - **EventFahrplan - The 39C3 Fahrplan App for Android** — *tbsprs* - **Quantum computing...
1102
Freddy @freddyb.bsky.social · 27/12/2025
Hey #39c3, chat me up if you want to talk about web security, browser security. I will be one of the tall dudes with a Firefox hoodie :)
041
Freddy @freddyb.bsky.social · 12/12/2025
lol, bsky wanting everyone's my birthday. Follow me on mastodon, you cowards.
000
Freddy @freddyb.bsky.social · 07/12/2025
New blog post: Why the Sanitizer API is just `setHTML()` - frederikbraun.de/why-sethtml.html
04117
Freddy @freddyb.bsky.social · 07/12/2025
New blog post. Something off-topic to feed the search engine. A bug in Lego Star Wars: The Complete Saga (2007). frederikbraun.de/lego-star-wars-com…
000
Reposted by Freddy
Felladonna @langsec.hacker.gf · 03/11/2025
I don't know who needs a kitty headbutt right now, but here's one for you
0326
Reposted by Freddy
Gareth Heyes @garethheyes.co.uk · 03/11/2025
Firefox nightly introduces the setHTML() method. Which is like a native DOMPurify. You can easily test it here: portswigger-labs.net/mxss/ Set HTMLSanitizer ✅ Auto update ✅ I'm trying to break it, I encourage you to break it too
4188
Reposted by Freddy
FluxFingers @fluxfingers.net · 08/10/2025
Hej! We are thrilled to announce Hack.lu CTF 2025 starts on Friday, October 17. Top teams can win prizes from our sponsors: OffensiveCon, Zellic, PortSwigger, Binary Ninja, and HackTheBox. All information on flu.xxx
043
Reposted by Freddy
John Schanck @susurrusus.bsky.social · 19/08/2025
hacks.mozilla.org
CRLite: Fast, private, and comprehensive certificate revocation checking in Firefox – Mozilla Hacks - the Web developer blog
Firefox is now the first and the only browser to deploy fast and comprehensive certificate revocation checking that does not reveal your browsing activity to anyone (not even to Mozilla). ...
032
Reposted by Freddy
Lesley Carhart @hacks4pancakes.com · 01/08/2025
I'm in a phenomenal talk on gender inequality in cybersecurity this morrning and this is such a great cheat sheet for intersectional fair employment.
Text exceeds alt capacity.
317556
Reposted by Freddy
David Buchanan @retr0.id · 25/07/2025
firefox container tabs are lowkey goated when $11/year VPS in dublin w/ socks5 over ssh is the vibe
61536
Reposted by Freddy
Sune Marcher @me.snemarch.dk · 26/07/2025
Wait, container tabs support individual proxy settings?
152
Freddy @freddyb.bsky.social · 02/07/2025
We just opened the Call-for-Papers for the German OWASP Day 2025. The event will be held November 25th-26th in Düsseldorf. god.owasp.de/2025/cfp.html We're looking for all sorts of presentations about web security and beyond for an audience of builders, breakers and defenders.
god.owasp.de
German OWASP Day 2025
011
Reposted by Freddy
David Buchanan @retr0.id · 31/05/2025
cut my heap into pieces, this is my crash report: allocation, no alignment don't give a fuck if it faults on assignment this is fatal abort()
643975
Reposted by Freddy
Corey Quinn @quinnypig.com · 31/05/2025
CUT MY LIST IN TWO PIECES THAT’S HOW YOU START QUICKSORT
131263248
Reposted by Freddy
potch @potch.me · 22/05/2025
end of an era 💔 blog.glitch.com/post/changes... I know Glitch is working on project export but if you're git-capable, I built a tool that will mass-git-clone your public glitch projects: github.com/potch/glitch...
blog.glitch.com
Important changes are coming to Glitch
We’ve got an important update for the Glitch community today: We’ll be ending web hosting for your apps on Glitch.
1163
Freddy @freddyb.bsky.social · 17/05/2025
Uh, pwn2own was...today? And we're shipping a bugfix release also today? Cool. Update your Firefoxes, please :D blog.mozilla.org/security/202...
blog.mozilla.org
Firefox Security Response to pwn2own 2025 – Mozilla Security Blog
At Mozilla, we consider security to be a paramount aspect of the web. This is why not only does Firefox have a long running bug bounty program but also mature ...
071
Reposted by Freddy
Dan Veditz @dveditz.bsky.social · 17/05/2025
We just published @firefox.com updates to fix the exploits used at the Pwn2Own contest yesterday and today. Both contestants achieved RCE in our content process but did not escape the sandbox. blog.mozilla.org/security/202...
blog.mozilla.org
Firefox Security Response to pwn2own 2025 – Mozilla Security Blog
At Mozilla, we consider security to be a paramount aspect of the web. This is why not only does Firefox have a long running bug bounty program but also mature ...
3248
Reposted by Freddy
Web Engines Hackfest @webengineshackfest.org · 16/05/2025
We have an initial plan for talks and breakout sessions at the Web Engines Hackfest 2025: github.com/Igalia/weben... • Monday: 9 talks and the W3C Web Apps WG F2F • Tuesday & Wednesday: 23 breakout sessions in 3 parallel tracks There might be still small changes, but it gives a good overall picture.
github.com
Home
Web Engines Hackfest. Contribute to Igalia/webengineshackfest development by creating an account on GitHub.
0139
Reposted by Freddy
Matthew Green @matthewdgreen.bsky.social · 10/05/2025
I made this diagram for a talk on encrypted messaging I recently gave, and I didn’t get to use it in the talk. I figured I’d share it here because I think it tells a story.
119430
Freddy @freddyb.bsky.social · 10/04/2025
New blog post: With Carrots & Sticks - Can the browser handle web security? frederikbraun.de/madweb-keynote-202… - This is the blog version of my keynote from MADWeb 2025 earlier this year. It's about how web security could become the browser's responsibility.
010
Freddy @freddyb.bsky.social · 02/04/2025
Blog post about the road to HTTPS-First in Firefox. Early reports show an uptick in encrypted traffic by at least 1.5% for our global users. 😎 attackanddefense.dev/2025/03/31/h...
attackanddefense.dev
The Evolution of HTTPS Adoption in Firefox
We at Mozilla believe that people deserve privacy and one of the most important pieces of web privacy is provided through ubiquitous encryption. Because of this, we shipped HTTPS-First by default as o...
020
Reposted by Freddy
Kevin Beaumont @doublepulsar.com · 31/03/2025
Based on the traffic I see - Mastodon is number 1, then LinkedIn, then Reddit, then Microsoft Teams, then Google, then BlueSky, then Twitter.
0102
Freddy @freddyb.bsky.social · 05/03/2025
Firefox 136 was just released. As of now, Firefox will open all pages using 🔒https, if possible. If the connection does not succeed (port closed, certificate untrusted etc), the browser will automatically switch back to http.
161
Reposted by Freddy
Alexandria Ocasio-Cortez @aoc.bsky.social · 22/02/2025
They need him to be a genius because they cannot handle what it means for them to be tricked by a fool.
332225444225
Reposted by Freddy
Bob Lord @boblord.bsky.social · 21/02/2025
We're in the consumer HTTPS endgame. We need to finish the job so I can be certain all my mobile traffic is protected. Please join me in asking the OS and browser makers to keep pushing and to finish the job in 2025, perhaps by Halloween! 👻 🔐 buff.ly/41qPpUM
131
Reposted by Freddy
Marcel Böhme @mboehme.bsky.social · 17/02/2025
#FUZZING'25 CALL FOR PAPERS ────── ✨ New OC members: * Ruijie Meng (@ruijiemeng.bsky.social; NUS) * Rohan Padhye (@rohan.padhye.org; CMU). ✨ New paper type: Fuzzing Nuggets (short papers). 🔗 fuzzingworkshop.github.io 📅 20.March (Submission) 📅 17.April (Notification) 📅 28.June (Workshop)
11711
Freddy @freddyb.bsky.social · 18/02/2025
@boblord.bsky.social Did you stop looking at your account on infosec.exchange? I (finally) have a paper for you to preview, if you can tell me your primary email address.
000
Reposted by Freddy
bubu @albertofdr.bsky.social · 29/01/2025
I posted a blog about how browser permissions work. albertofdr.github.io/web-security...
albertofdr.github.io
You Shall Not Get Access 🧙🏻‍♂️: Browser Permissions | WebSec!
Web Security Educational Blog
162
Freddy @freddyb.bsky.social · 31/01/2025
An updated to the Firefox Bug Bounty Hall of Fame for Q4 of 2024 just dropped. Thank you to the many folks who helped keep Firefox secure! 🏆👏 www.mozilla.org/en-US/securi...
mozilla.org
Mozilla Security Bug Bounty Program Hall of Fame
030
Reposted by Freddy
IntentToShip @intenttoship.dev · 15/01/2025
Gecko: Intent to ship: HTTPS-First / HTTPS Upgrades
groups.google.com
Gecko: Intent to ship: HTTPS-First / HTTPS Upgrades
Gecko: Intent to ship: HTTPS-First / HTTPS Upgrades
011
Freddy @freddyb.bsky.social · 13/01/2025
This is your reminder that the HTML specification features the picture of a kitchen sink.
A photo of a kitchen sink surrounded by a large grey border.
The sink is clean but busy and the photo includes a dish rack, cleaning rags and kitchen utensils, like a whisk in the background. The photo features the prominent white uppercase text "THIS SPECIFICATION".

The large grey borders contains references to other specifications, like CSS, SVG, MathML, HTTP, TLS, DOM, JavaScript and many more.
060
Reposted by Freddy
Know Your Meme @knowyourmeme.com · 09/01/2025
On this day 12 years ago, @kcg.bsky.social posted the “This is Fine” comic.
101112254282
Reposted by Freddy
Nicolas Grégoire @agarri.fr · 03/01/2025
Given that simps0n isn’t on Bluesky, allow me to post a link to his excellent weekly ezine 💎 Here’s today’s edition, "AppSec Ezine - 568th" 📚 pathonproject.com/zb/?47a5c4d2...
pathonproject.com
AppSec Ezine
02211