Sign in

Freddy

@freddyb.bsky.social
352 followers 112 following 79 posts

manager/security things for Firefox. love my family, my bike and reading books. You can also find me on Mastodon as @freddy@security.plumbing, which I consider my primary account. Homepage: frederikbraun.de

PostsRepliesMedia
Freddy @freddyb.bsky.social · 11h
How cute :) I showed this picture to my personal in-house fingu fans and they appreciate the color. Where did you see it?
110
Freddy @freddyb.bsky.social · 20/08/2026
My presentation from OWASP AppSec '26 in Vienna is finally public. Watch me talk about XSS and XSS and Cross-Site Scripting, and XSS in this talk titled "The Devil Is In The Defaults: What To Do About XSS" youtube.com/watch?v=b7RlQdvPY3 (It's also about XSS).
youtube.com
YouTube
Share your videos with friends, family, and the world
132
Reposted by Freddy
Freddy @freddyb.bsky.social · 31/05/2026
The S in interoperability (frederikbraun.de/the-s-in-interoper…): A blog post about standards, their proliferation and the issues that arive over time.
021
Freddy @freddyb.bsky.social · 31/05/2026
The S in interoperability (frederikbraun.de/the-s-in-interoper…): A blog post about standards, their proliferation and the issues that arive over time.
021
Freddy @freddyb.bsky.social · 02/05/2026
"finally" 🤣
040
Freddy @freddyb.bsky.social · 24/04/2026
New Blog post: "Multiple things can be true at the same time" - frederikbraun.de/feels-and-ll... Dear reader, I am sure you have read a lot of blog posts about AI in the past weeks or months. This is my post.…
frederikbraun.de
Multiple things can be true at the same time
Multiple things can be true at the same time
052
Freddy @freddyb.bsky.social · 21/04/2026
blog.mozilla.org/en/privacy-s...
blog.mozilla.org
The zero-days are numbered  | The Mozilla Blog
Since February, the Firefox team has been working around the clock using frontier AI models to find and fix latent security vulnerabilities in the browser.
020
Reposted by Freddy
Nadim Kobeissi @nadim.computer · 23/03/2026
Major announcement: My highly successful Applied Cryptography course taught last year at the American University of Beirut is returning as an online course, available for FREE for any qualifying student from any Lebanese university! Read more + apply today — and please spread the word!
symbolic.software
Applied Cryptography: Free Online Course for 50 Lebanese University Students This Summer
We're opening 50 spots for students at Lebanese universities to take the Applied Cryptography course online, completely free of charge, starting June 2026. Applications are open now.
1133
Reposted by Freddy
spooky Deirdre Connolly¹ ² at a distance @durumcrustulum.com · 09/03/2026
Next up, 'Improving the Trustworthiness of Javascript on the Web', presented by Michael Rosenberg, Giulio Berra, Ezzudin Alkotob, and Dennis Jackson #realworldcrypto
171
Freddy @freddyb.bsky.social · 07/03/2026
OK, ok. I'll stop blogging for today. I promise.
000
Freddy @freddyb.bsky.social · 07/03/2026
Composing Sanitizer configurations (frederikbraun.de/composable-sanitiz…): The HTML Sanitizer API allows multiple ways to customize the default allow list and this blog post aims to describe a few variations and tricks we came up with while writing the specification.
010
Freddy @freddyb.bsky.social · 07/03/2026
hat-tip to @shhnjk.bsky.social 🤓
030
Freddy @freddyb.bsky.social · 07/03/2026
New blog post: Perfect types with `setHTML()` - frederikbraun.de/perfect-types-with… - TLDR: Use require-trusted-types-for 'script'; trusted-types 'none'; in your CSP and nothing besides setHTML() works, essentially removing all DOM-XSS risks....
1113
Reposted by Freddy
David Bushell 🪿 @dbushell.com · 03/03/2026
c'mon Safari
HTML Sanitizer API browser support list with unsupported Safari being poked with a stick by the White Ninja meme
01079
Freddy @freddyb.bsky.social · 02/03/2026
I was invited to join the @shoptalkshow.com podcast and talk about my favorite topic. The HTML Sanitizer API and `setHTML()`. Give it a spin in your favorite podcast player :) shoptalkshow.com/704/
shoptalkshow.com
704: Sanitizer API with Frederik Braun
We talk with Frederik Braun from Mozilla about the Sanitizer API, how it works with HTML tags and web components, what it does with malformed HTML, and where CSP fits in alongside the Sanitizer API…
000
Freddy @freddyb.bsky.social · 24/02/2026
we did a thing! Congrats to the team for getting this out.
160
Freddy @freddyb.bsky.social · 17/01/2026
P.S. this account is write-only. I will only post announcements and blog post links. If you want to reach me, try mastodon or email m
000
Freddy @freddyb.bsky.social · 17/01/2026
this is your regular reminder that centralized, single-ownership social media is doomed
110
Reposted by Freddy
jub0bs @jub0bs.com · 30/08/2025
⚡ I've been contributing micro-optimisations to Go's standard library in my spare time: github.com/golang/go/co... 💸 I don't intend to stop any time soon, but if you benefit from my work and would like to support it, consider sponsoring me on GitHub: github.com/sponsors/jub... #golang #OpenSource
github.com
Sponsor @jub0bs on GitHub Sponsors
infosec enthusiast • Go developer & trainer • minimalist • chaotic good • trying to make sense of the Web • he/him
1172
Reposted by Freddy
Anna Weine @an-dante.bsky.social · 06/01/2026
The Open Source Cryptography Workshop is returning for 2026, before Real World Crypto in Taipei. We are calling for session proposals, both presentations and hands-on workshops, on topics of interest to those who work on and with open source crypto. oscwork.shop/2026 #oscw #rwc #oscw2026 #rwc2026
oscwork.shop
OSCW 2026: Taipei, Taiwan :: Open Source Cryptography Workshop
OSCW 2026 will take place 8 March 2026, the day before Real World Crypto
002
Freddy @freddyb.bsky.social · 30/12/2025
decoder hosted the session.
020
Freddy @freddyb.bsky.social · 30/12/2025
Oh noes. Well see you next time, I suppose? On the upside, the talk was recorded. :)
020
Freddy @freddyb.bsky.social · 27/12/2025
Hey #39c3. Come see my lightning talk on a safe variant for `.innerHTML ` that is built right into the browser. Tomorrow (day 2), at approximately 12:25 - events.ccc.de/congress/202...
events.ccc.de
[39c3] Lightning Talks - Tag 2
- **Lightning Talks Introduction** - **Chaos auf der Schiene: Die Wahrheit hinter den Verspätungen** — *poschi* - **EventFahrplan - The 39C3 Fahrplan App for Android** — *tbsprs* - **Quantum computing...
1102
Freddy @freddyb.bsky.social · 27/12/2025
Hey #39c3, chat me up if you want to talk about web security, browser security. I will be one of the tall dudes with a Firefox hoodie :)
041
Freddy @freddyb.bsky.social · 12/12/2025
lol, bsky wanting everyone's my birthday. Follow me on mastodon, you cowards.
000
Freddy @freddyb.bsky.social · 07/12/2025
New blog post: Why the Sanitizer API is just `setHTML()` - frederikbraun.de/why-sethtml.html
04117
Freddy @freddyb.bsky.social · 07/12/2025
New blog post. Something off-topic to feed the search engine. A bug in Lego Star Wars: The Complete Saga (2007). frederikbraun.de/lego-star-wars-com…
000
Freddy @freddyb.bsky.social · 04/11/2025
We had a first good outcome already (via Twitter). While `data` URLs are not what I would consider an XSS in the page, I still see it as a confusion that we should address head on. We have an issue filed in github.com/WICG/sanitiz... :)
github.com
Handling of `<a href="data:...">` · Issue #352 · WICG/sanitizer-api
We allow anchors in the default configuration and only restrict javascript: URLs. data: URLs (especially inside an iframe) might look like XSS: https://x.com/KwanAleister/status/1985542748930523233...
020
Freddy @freddyb.bsky.social · 03/11/2025
(Terms and conditions apply. Bounty payouts are at the discretion of the bug bounty committee etc. etc. But yes. Bugs in the sanitizer are eligible.)
020
Reposted by Freddy
Felladonna @langsec.hacker.gf · 03/11/2025
I don't know who needs a kitty headbutt right now, but here's one for you
0326
Freddy @freddyb.bsky.social · 03/11/2025
YES! :)
110
Reposted by Freddy
Gareth Heyes @garethheyes.co.uk · 03/11/2025
Firefox nightly introduces the setHTML() method. Which is like a native DOMPurify. You can easily test it here: portswigger-labs.net/mxss/ Set HTMLSanitizer ✅ Auto update ✅ I'm trying to break it, I encourage you to break it too
4188
Reposted by Freddy
FluxFingers @fluxfingers.net · 08/10/2025
Hej! We are thrilled to announce Hack.lu CTF 2025 starts on Friday, October 17. Top teams can win prizes from our sponsors: OffensiveCon, Zellic, PortSwigger, Binary Ninja, and HackTheBox. All information on flu.xxx
043
Freddy @freddyb.bsky.social · 26/09/2025
Eine riesige Verbesserung der Lebensqualität. Vielen Dank für Ihren Einsatz! An wen schreibe ich einen höflichen Brief, dass die Ladebereiche vielleicht einen abgesenkten Bordstein für einfacheres Entladen bekommen könnten? InfraVelo oder Bezirksamt? Oder reicht hier? ;-)
110
Reposted by Freddy
John Schanck @susurrusus.bsky.social · 19/08/2025
hacks.mozilla.org
CRLite: Fast, private, and comprehensive certificate revocation checking in Firefox – Mozilla Hacks - the Web developer blog
Firefox is now the first and the only browser to deploy fast and comprehensive certificate revocation checking that does not reveal your browsing activity to anyone (not even to Mozilla). ...
032
Reposted by Freddy
Lesley Carhart @hacks4pancakes.com · 01/08/2025
I'm in a phenomenal talk on gender inequality in cybersecurity this morrning and this is such a great cheat sheet for intersectional fair employment.
Text exceeds alt capacity.
317556
Reposted by Freddy
David Buchanan @retr0.id · 25/07/2025
firefox container tabs are lowkey goated when $11/year VPS in dublin w/ socks5 over ssh is the vibe
61536
Reposted by Freddy
Sune Marcher @me.snemarch.dk · 26/07/2025
Wait, container tabs support individual proxy settings?
152
Freddy @freddyb.bsky.social · 02/07/2025
We just opened the Call-for-Papers for the German OWASP Day 2025. The event will be held November 25th-26th in Düsseldorf. god.owasp.de/2025/cfp.html We're looking for all sorts of presentations about web security and beyond for an audience of builders, breakers and defenders.
god.owasp.de
German OWASP Day 2025
011
Reposted by Freddy
David Buchanan @retr0.id · 31/05/2025
cut my heap into pieces, this is my crash report: allocation, no alignment don't give a fuck if it faults on assignment this is fatal abort()
643975
Reposted by Freddy
Corey Quinn @quinnypig.com · 31/05/2025
CUT MY LIST IN TWO PIECES THAT’S HOW YOU START QUICKSORT
131262248
Freddy @freddyb.bsky.social · 31/05/2025
Closed the 6th floor. 3&4 are still going. Berlin and Toronto are the last offices.
010
Freddy @freddyb.bsky.social · 28/05/2025
it's still the mozilla office 👋
110
Freddy @freddyb.bsky.social · 26/05/2025
Echt Hammer, wie schön die Radwege sind. Aber wieso sind diese Fahrrad-Symbole so erhaben. Hätte man die nicht auch in glatt hingekriegt? Frage als absoluter Laie :)
010
Freddy @freddyb.bsky.social · 25/05/2025
Just watched the talk video. well explained! So sad, that there are so many findings. Would you say most DOM-based XSS is mostly `innerHTML =` or what do people usually do?
110
Freddy @freddyb.bsky.social · 25/05/2025
thank you!
110
Freddy @freddyb.bsky.social · 24/05/2025
Do you intend to write it up as a blog post? Unfortunately, it’s not self-explanatory with slides? I am curious:) ps: Reminds me of frederikbraun.de/xss-digital-....
frederikbraun.de
XSS in The Digital #ClimateStrike Widget
XSS in The Digital #ClimateStrike Widget
130
Reposted by Freddy
potch @potch.me · 22/05/2025
end of an era 💔 blog.glitch.com/post/changes... I know Glitch is working on project export but if you're git-capable, I built a tool that will mass-git-clone your public glitch projects: github.com/potch/glitch...
blog.glitch.com
Important changes are coming to Glitch
We’ve got an important update for the Glitch community today: We’ll be ending web hosting for your apps on Glitch.
1163
Freddy @freddyb.bsky.social · 22/05/2025
This is a complaint about the default. Defaults matter. You should know that.
120
Freddy @freddyb.bsky.social · 21/05/2025
Pfff, you're four days late. We fixed this already on Saturday 😘
010