Sign in

Max Hils

@hi.ls
139 followers 157 following 17 posts

mitmproxy developer, making cloud more secure at Google. TLS, web, networks, and open source. Mostly active on fedi.hi.ls these days, mirroring announcements here.

PostsRepliesMedia
Max Hils @hi.ls · 24/08/2026
We did some AI stuff at work: bughunters.google.com/blog/scaling...
bughunters.google.com
Blog: Scaling Memory Safety: AI-Assisted Rewrites of C/C++ Dependencies to Rust
This blog post describes how we used AI to help us rewrite a C library (giflib) to Rust to mitigate memory safety vulnerabilities.
010
Max Hils @hi.ls · 30/06/2026
Zen mode!
120
Max Hils @hi.ls · 01/06/2026
Update from the team: This is a test domain that incorrectly ended up in production. Fix is rolling out, apologies for the breakage. :)
010
Max Hils @hi.ls · 31/05/2026
Thanks! I can't give you an explanation yet, but I pinged the folks responsible.
100
Max Hils @hi.ls · 02/12/2025
The LaTeX Korrektor 2/6: How to make sure everyone thinks your papers are written by AI. 🥲
010
Reposted by Max Hils
absolute horses @jcoglan.com · 18/11/2025
browsers should be allowed to display the <li> in a <ul> in whatever order they like
76313
Max Hils @hi.ls · 18/10/2025
One of my favorite games just got a free content update ten years after initial release. @metanetsoftware.com is just crazy cool. 😍
030
Max Hils @hi.ls · 02/10/2025
Thanks for the heads-up! Things should be fixed since yesterday, my registrar screwed up apparently. 🙈 (Details: github.com/autofix-ci/a...)
github.com
autofix.ci is down · Issue #32 · autofix-ci/action
we're getting Error: getaddrinfo ENOTFOUND api.autofix.ci in the github action and http://autofix.ci also seems down
120
Reposted by Max Hils
absolute horses @jcoglan.com · 25/08/2025
rust is a language in which you can borrow a cow
3294
Reposted by Max Hils
Mark Nottingham @mnot.net · 20/08/2025
If you work on HTTP implementations, deploy it at scale, or have a unique perspective or interest in the protocol, you might find other people to talk to at the 2026 HTTP Workshop: github.com/HTTPWorkshop/workshop202…
064
Max Hils @hi.ls · 14/08/2025
You can also put stuff onto the tracks to cause any train to do an emergency break. Granted, attack complexity and stealthiness may be a bit better here, but I can see how they are a bit scared of "we crashed into another train because their stop signal wasn't properly signed" scenarios. :)
030
Reposted by Max Hils
METR @metr.org · 10/07/2025
At the beginning of the study, developers forecasted that they would get sped up by 24%. After actually doing the work, they estimated that they had been sped up by 20%. But it turned out that they were actually slowed down by 19%.
363056
Max Hils @hi.ls · 10/07/2025
I really like doc.rust-lang.org/beta/std/syn... for this use case. Derefs to the inner value, so no calling necessary. :)
doc.rust-lang.org
LazyLock in std::sync - Rust
A value which is initialized on the first access.
120
Reposted by Max Hils
Will McGugan @willmcgugan.bsky.social · 05/06/2025
I post on "The ethics of README ads" willmcgugan.github.io/the-ethics-o...
willmcgugan.github.io
The ethics of README ads
I’ve been considering accepting sponsorship again for my projects.
3153
Max Hils @hi.ls · 05/06/2025
Great topic, your "luxury of being able to turn them down" framing is really nice. I personally find bulma.io to be an interesting example. With 40 sponsors at $100/month it's getting non-negligible. Great for project sustainability, who am I to judge?
010
Max Hils @hi.ls · 14/05/2025
I this the IPv6 thing people keep talking about? I heard it has larger numbers. 🥸
010
Reposted by Max Hils
Dylan Storey @dylanstorey.com · 13/05/2025
Check out pyo3 if you haven't, it's rad
022
Reposted by Max Hils
dmnk @dmnk.bsky.social · 10/05/2025
You don't have to write software in c++
281
Reposted by Max Hils
Max Hils @hi.ls · 29/04/2025
mitmproxy 12 is out! 🚀 It’s now possible to modify the prettified representation of binary protocols. Editing Protobufs is now as easy as editing YAML, no .proto schema needed. 🙌 mitmproxy.org/posts/releas...
mitmproxy.org
Mitmproxy 12: Interactive Contentviews
177
Reposted by Max Hils
Jérôme Segura @jeromesegura.com · 30/04/2025
Also, this seems like a small feature but much appreciated:
021
Max Hils @hi.ls · 29/04/2025
mitmproxy 12 is out! 🚀 It’s now possible to modify the prettified representation of binary protocols. Editing Protobufs is now as easy as editing YAML, no .proto schema needed. 🙌 mitmproxy.org/posts/releas...
mitmproxy.org
Mitmproxy 12: Interactive Contentviews
177
Reposted by Max Hils
Armin Ronacher @mitsuhiko.at · 27/03/2025
The next version of Rust might be one of the most transformative to the Rust ecosystem due to support for up-casting of trait objects. This makes `Any` significantly more powerful and potent!
68715
Reposted by Max Hils
Cameron (grooving) @halfpixel.bsky.social · 20/03/2025
0.1 + 0.2 == 0.3
318140
Max Hils @hi.ls · 07/03/2025
Not sure how I should feel about our new ice cream scoop containing AI. 🤔
010
Reposted by Max Hils
Annie Sullivan @anniesullie.com · 06/03/2025
Here are the project ideas and info for Chromium:
docs.google.com
Chromium GSoC 2025 Project Ideas and Info
Chromium GSoC 2025 Project Ideas and Info
084
Max Hils @hi.ls · 06/03/2025
🎉🎉🎉 Really cool effort. I didn't mind TLS fingerprinting back when it was it was used sparingly and carefully to fight actual abuse, but with everyone and their CDN now randomly blocking clients it just needs to die.
110
Reposted by Max Hils
Tim Perry @pimterry.fyi · 06/03/2025
This is part of an ongoing personal campaign to kill TLS fingerprinting. With this change + github.com/openssl/open..., OpenSSL TLS traffic won't have any non-configurable distinguishing features, and so I _think_ it should be possible to configure it to exactly match modern browser traffic.
github.com
Use empty renegotiate extension instead of SCSV for TLS > 1.0 by pimterry · Pull Request #24161 · openssl/openssl
This PR fixes #18790. This is my very first OpenSSL PR, and day to day I don&#39;t write much C (and zero Perl) so I&#39;d appreciate some careful review! I&#39;ve just emailed a signed CLA to the ...
221
Reposted by Max Hils
Sebastian Dullien @sdullien.bsky.social · 06/02/2025
Neu: Unsere @imkinstitut.bsky.social Simulation, was mit Wirtschaftswachstum und Schulden in Deutschland passieren würde, wenn man über die kommenden 10 Jahre 600 Mrd. € zusätzlich in die öffentliche Infrastruktur investieren würde. (1/) www.imk-boeckler.de/de/faust-de...
imk-boeckler.de
Wachstumseffekte eines kreditfinanzierten Investitionsprogramms
Es wird ein kreditfinanziertes öffentliches Investitionsprogramm für die deutsche Wirtschaft von 600 Milliarden Euro in den nächsten 10 Jahren mit dem NiGEM-Modell simuliert. Die Ergebnisse zeigen erhebliche Wachstumseffekte, besonders längerfristig aufgrund der positiven Auswirkungen des höheren öffentlichen Kapitalstocks auf private Investitionsentscheidungen. <BR>Das BIP könnte längerfristig zeitweise um rund 6 % über seinem Niveau ohne Investitionsoffensive liegen. Außerdem regt das Programm die private Investitionstätigkeit deutlich an, sodass die Unternehmensinvestitionen bis zu 10 % über ihr Niveau ohne Programm steigen. Konkret bedeutet das, dass die aufsummierte Wirtschaftsleistung Deutschlands von 2025 bis 2050 um bis zu 4800 Mrd. Euro höher ausfallen würde. 2045 läge das jährliche Pro-Kopf-BIP um 3600 Euro höher, als es ohne das Programm der Fall wäre. <BR>Zwar erhöht sich das staatliche Budgetdefizit während der zehnjährigen Laufzeit des Programms um etwa 1 % des BIP. Alle
35231
Max Hils @hi.ls · 06/02/2025
mitmproxy 11.1.2 is out, everyone should upgrade! We fixed a rather nasty SSRF-style vulnerability affecting mitmweb (CVE-2025-23217). mitmproxy and mitmdump users are unaffected. github.com/mitmproxy/mi...
github.com
Mitmweb API Authentication Bypass Using Proxy Server
### Impact In mitmweb 11.1.0 and below, a malicious client can use mitmweb's proxy server (bound to `*:8080` by default) to access mitmweb's internal API (bound to `127.0.0.1:8081` by default). In...
032
Reposted by Max Hils
Hynek Schlawack @hynek.me · 24/01/2025
now that this is (hopefully) over, I'd like to state the obvious that pestering FOSS maintainers with your misguided compliance issues – in the holiday season no less – is not something that gets you on Santa's good list
092
Reposted by Max Hils
The Shadowserver Foundation @shadowserver.bsky.social · 17/01/2025
Sharing rsync instances vulnerable to CVE-2024-12084 RCE (version check only) in our updated daily Accessible Rsync report: shadowserver.org/what-we-do/n... 17,475 instances found vulnerable (out of 146,844) on 2025-01-16. Top affected: US (5K) dashboard.shadowserver.org/statistics/c...
252
Max Hils @hi.ls · 14/01/2025
Template Injection needs a fertile breeding ground. :)
010
Max Hils @hi.ls · 12/01/2025
mitmproxy 11.1 is out! 🥳 We now support *Local Capture Mode* on Windows, macOS, and - new - Linux! This allows users to intercept local applications even if they don't have proxy settings. More details are at mitmproxy.org/posts/local-.... Super proud of this team effort. 😃
mitmproxy.org
Intercepting Linux Applications
27522