Sign in

Tim Perry

@pimterry.fyi
756 followers 756 following 208 posts

Founder of httptoolkit.com (@httptoolkit.com), Node.js core collaborator, tech speaker, drummer, mountain biker and dad. 🇬🇧/🇨🇦 living in 🇪🇸

PostsRepliesMedia
Tim Perry @pimterry.fyi · 29/09/2026
Node.js going to the moon at @nodeconf.eu 📈
251
Reposted by Tim Perry
HTTP Toolkit @httptoolkit.com · 23/09/2026
If you're using custom system CAs on Android for TLS - whether that's for HTTPS debugging, ad blocking or local testing - there's trouble brewing. Let's talk about the latest Android 17 changes and how to keep things working:
httptoolkit.com
Android 17 enables certificate transparency, and breaks custom CAs
Do you want to know what your phone is sending & receiving? Nowadays, that means you need to control who it trusts. In modern connections everything sent &...
032
Reposted by Tim Perry
polytoken dot dev @polytoken.dev · 15/09/2026
nobody else has the steel moral core to tell you the truth in release notes
- Some bugs removed.
- More bugs added.
31088161
Tim Perry @pimterry.fyi · 08/09/2026
I know we're all worried about quantum computing breaking encryption etc etc, but on the bright side: isn't it going to be cool when every old locked-down IoT device that only accepts updates from a server that no longer exists can be resurrected by faking the cert on your own personal quantum box?
111
Tim Perry @pimterry.fyi · 24/08/2026
Coming soon to a Node.js near you: a small issue I spotted on Friday and fixed with a tiny little change now makes every typical small API response with Node.js ~10% faster for free: github.com/nodejs/node/... 🚀
github.com
http: improve performance for end() with known-length string by pimterry · Pull Request #65466 · nodejs/node
When you call end(data) on an outgoing HTTP request, we previously wrote the data, and then ran _send('', ...) just to trigger flushing the headers, which resulted in an extra zero-byte wri...
1132
Tim Perry @pimterry.fyi · 22/08/2026
Just bought my ticket to @nodeconf.eu for the end of September! Very excited for this, lots & lots of interesting things happening in the Node.js community right now. Who else is coming?
491
Reposted by Tim Perry
Sam Rose @samwho.dev · 13/08/2026
This might be the most beautiful thing I've read in my life. What a privilege to be alive in 2026. ordinaryabundance.com
ordinaryabundance.com
Ordinary Abundance
A walk through a modern apartment, through the eyes of the people for whom everything in it was new.
13590221
Reposted by Tim Perry
Andrew Nesbitt @andrewnez.bsky.social · 24/07/2026
Interview with a Maintainer nesbitt.io/2026/07/24/i...
nesbitt.io
Interview with a Maintainer
Episode 214 of Green Squares.
3123
Tim Perry @pimterry.fyi · 23/07/2026
I do lots of long-ish horizon work (e.g. OpenSSL PRs I can't actually use for years after merging). Remarkable how bad LLMs are at even considering this as an option. Quick fix every time, even if there's a clear long-term right answer we should do instead. Does not bode well for the ecosystem...
100
Tim Perry @pimterry.fyi · 23/07/2026
Made my first PR to an IETF standard draft: github.com/quicwg/qmux/.... End result will be a bit inconvenient for all involved 😂 but better to fix it now!
github.com
Fix hex encoding of protocol magic number by pimterry · Pull Request #69 · quicwg/qmux
The intended magic number string was changed to from QS0 to QMX when the spec was renamed (#14) and the description shows this correctly, but the hex value was not updated anywhere. The magic numbe...
040
Tim Perry @pimterry.fyi · 09/07/2026
Nearly 5 years of work later, I've successfully closed the Node.js TLS fingerprinting issue: github.com/nodejs/node/.... As of Node 26.4.0, it's possible to match most common TLS fingerprints in Node directly. I've published a library to do all the hard work here: github.com/httptoolkit/...
github.com
GitHub - httptoolkit/node-tls-impersonate: TLS fingerprint control within Node.js's normal networking APIs
TLS fingerprint control within Node.js's normal networking APIs - httptoolkit/node-tls-impersonate
011
Reposted by Tim Perry
HTTP Toolkit @httptoolkit.com · 30/06/2026
Have you seen testserver.host/? As part of building HTTP Toolkit I often need a remote servers for testing edge cases, so I've built one! Now fairly mature & stable. It's httpbin.org plus badssl.com plus lots of extras.
testserver.host
Testserver
Endpoints can be combined using double-dashes, e.g. expired--revoked--http2--tls-v1-2.{domain} will return an expired and revoked certificate, use TLSv1.2, and then negotiate HTTP/2 on the connection.
142
Reposted by Tim Perry
Ronja Pilgaard @ronjap.bsky.social · 31/05/2026
Jeg er til det her oplæg, og der er stuvende fyldt. Det er konferencens fjerde dag, folk er trætte og kunne sove længe. Men folk kommer hele tiden ind. De sidder på gulvet og står nede bagved. Det her kommer til at kunne ses i journalistik rundt om i Europa i fremtiden 🥳
042
Tim Perry @pimterry.fyi · 28/05/2026
I'm speaking at @journalismarena.eu's Dataharvest conf in Belgium this weekend! I'll be teaching investigative journalists how to intercept, interpret & scrape mobile app network traffic, it's going to be a lot of fun 😀 Anybody else I know here attending? Would be great to meet up #dataharvest26
dataharvest26.sched.com
Dataharvest 2026 - the European Investigative Journalism Conference: Unlocking the apps: How can you scrape d...
View more about this event at Dataharvest 2026 - the European Investigative Journalism Conference
141
Tim Perry @pimterry.fyi · 21/05/2026
Staged publishing for npm! Finally 🙏 I'm only just starting to test it now, but in theory at least this + trusted publishing could very significantly tighten up the security posture for lots of packages. Would be fantastic to see the current wave of attacks slow down a bit.
docs.npmjs.com
Staged publishing for npm packages | npm Docs
Documentation for the npm registry, website, and command-line interface
032
Reposted by Tim Perry
Firefox for Web Developers @webdevs.firefox.com · 18/05/2026
Chrome shipped an LLM Prompt API to the web platform. At Mozilla, we oppose this API. Here's why:
18419122
Reposted by Tim Perry
P(aul) Frazee @pfrazee.com · 13/05/2026
Somewhere there's a CEO stuck in a meeting that's in desperate need of amazon gift cards, completely unable to get their team to answer their texts
1146928
Reposted by Tim Perry
Jake Archibald @jakearchibald.com · 06/05/2026
So, Chrome's "web standard" Prompt API: Mozilla: Opposed WebKit: Opposed Microsoft: Several concerns W3C TAG: Several concerns Developers: Mostly negative Chrome: Ships anyway. A sad time for web standards. But, I guess someone at Google will get promoted, so 'every cloud…'
43998170
Reposted by Tim Perry
The C Programming Language @c-official.bsky.social · 04/05/2026
Tip: NEVER use a random number. A non deterministic "solution" is unworthy of the divine touch of a turing machine
518733
Tim Perry @pimterry.fyi · 29/04/2026
I've been thinking about simonomi.dev/blog/color-c.... Whipped up a quick prototype for HTTP Toolkit's hex view - what do you think? Interesting and more useful than monochrome, or just visually noisy? See if you can guess what each file type is here - answers in the alt text 😀
A hex view with bytes coloured by value - in this case a favicon (lots of 00 at the start, then repeating patterns later).A hex view with bytes coloured by value - in this case HTML (lots of ascii values with similar colours, and quite a few symbols for the < > etc)A hex view with bytes coloured by value - in this case protobuf - a mix of ascii strings and very low 0X bytes.
021
Tim Perry @pimterry.fyi · 29/04/2026
Just created my first Azure account to migrate HTTP Toolkit from certs to Microsoft's new 'Artifact Signing' setup (azure.microsoft.com/en-us/produc...). The UI is eye opening... Flashback 10 years in UI, impossible navigation, endless "Please update from X"/"Did you know Y is now Z" banners, wow 😬
azure.microsoft.com
Azure Artifact Signing (formerly Trusted Signing) | Microsoft Azure
Secure your applications with Artifact Signing (formerly Azure Trusted Signing), a fully managed end-to-end signing service for code, documents, and applications.
100
Tim Perry @pimterry.fyi · 21/04/2026
HTTP Toolkit is now on the @fsfe.org major donor list! fsfe.org/donate/thank... They're doing great work right now like fsfe.org/news/2026/ne... - if you're also keen on open platforms & interoperability do please donate to support them too ❤️
fsfe.org
Apple keeps challenging its interoperability obligations under the DMA - FSFE
A new FSFE report exposes how 56 interoperability requests under the Digital Markets Act have produced no concrete solutions by Apple, and how their declin...
010
Reposted by Tim Perry
Paulus Schoutsen @paulusschoutsen.nl · 13/04/2026
WebSerial has landed in Firefox Nightly !! 🎉 Enable it in about:config and it all just works as expected. Took a brand new ESP32 and had a new Bluetooth proxy added to Home Assistant within 2 minutes 👌
37613
Reposted by Tim Perry
Filippo Valsorda @filippo.abyssdomain.expert · 06/04/2026
Two papers came out last week that suggest classical asymmetric cryptography might indeed be broken by quantum computers in just a few years. That means we need to ship post-quantum crypto now, with the tools we have: ML-KEM and ML-DSA. I didn't think PQ auth was so urgent until recently.
words.filippo.io
A Cryptography Engineer’s Perspective on Quantum Computing Timelines
The risk that cryptographically-relevant quantum computers materialize within the next few years is now high enough to be dispositive, unfortunately.
11303123
Tim Perry @pimterry.fyi · 05/04/2026
Damn I got this as well! Just assumed it was spam and ignored this (and the LinkedIn follow up) turns out I dodged a bullet 😅
OpenFort slack invite
0142
Tim Perry @pimterry.fyi · 31/03/2026
Finally bit the bullet and bought more RAM! The rumours are true, the prices really are excruciating, more than 4x the price I paid for the other stick 18 months back 🥲
100
Tim Perry @pimterry.fyi · 25/03/2026
In case you want to understand your TLS clients in depth from Node.js, there's a new v2 release of read-tls-client-hello now live: github.com/httptoolkit/... Also now supported on testserver.host at testserver.host/tls/client-h..., so you can test & debug clients themselves directly.
github.com
GitHub - httptoolkit/read-tls-client-hello: A pure-JS module to read TLS client hello data and calculate TLS fingerprints from an incoming socket connection.
A pure-JS module to read TLS client hello data and calculate TLS fingerprints from an incoming socket connection. - httptoolkit/read-tls-client-hello
010
Tim Perry @pimterry.fyi · 19/03/2026
I've been playing around with agent-powered HTTP debugging -there's a lot of potential here... Even just with minimal data, Claude gets a really good understanding of flows very quickly, amazing for exploring. A quick summary of overall traffic & state flow across ~160 requests & responses:
Claude output:

Summary of the state flow

  Edge launches (no state)
      │
      ├─→ Bing qbox (cookieless) ──→ Bing sets MUID + 9 others
      │
      ├─→ SmartScreen (token in Authorization header, no cookies)
      │
      └─→ GET reddit.com
           │ 301 → www.reddit.com (no cookies set on redirect)
           │
           └─→ GET www.reddit.com
                │ Sets: loid, session_tracker, csrf_token, token_v2, csv, edgebucket
                │
                ├─→ POST /svc/shreddit/events  ← sends all 6 cookies back
                │   └─ response refreshes session_tracker
                │
                ├─→ POST /svc/shreddit/graphql  ← sends all 6 cookies (with updated session_tracker)
                │   └─ response refreshes session_tracker again
                │
                ├─→ GET /svc/shreddit/feeds/popular-feed  ← sends all 6 cookies
                │   └─ response refreshes session_tracker again
                │
                ├─→ POST alb.reddit.com/track  ← NO cookies (cross-subdomain, no-cors)
                │
                └─→ GET www.redditstatic.com/*  ← NO cookies (CDN, different domain)

  The key insight is that Reddit bootstraps the entire anonymous session in a single response — one page load sets up identity (loid), session tracking, CSRF protection, an auth JWT, A/B bucketing, and a
  cookie format version — and then every subsequent same-origin request carries all of that state forward, with session_tracker being the only one that gets continuously rotated.
202
Reposted by Tim Perry
Mozilla @mozilla.org · 18/03/2026
Mozilla Festival is coming back to Barcelona. 28–30 October 2026 at Recinte Fabra i Coats. Sign up to be first to know when tickets drop⚡ #MozFest mzl.la/47PLTG9
1236
Tim Perry @pimterry.fyi · 16/03/2026
Do I know anybody at GitHub who can help me get HTTP Toolkit into the student pack? I'm happy to do free accounts for students, I've filled out the form a couple of times - they never reply, but students keep endlessly emailing me to ask me if it's included.
001
Reposted by Tim Perry
Node.js @nodejs.org · 10/03/2026
Node.js is moving to one major release per year starting with Node 27! 🚀 ✅ Simpler: Every release becomes LTS. ✅ Predictable: Version numbers now align with the year. ✅ New: A 6-month Alpha channel for early testing. bit.ly/4rnosLg
nodejs.org
Node.js — Evolving the Node.js Release Schedule
Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.
423360
Tim Perry @pimterry.fyi · 15/03/2026
Continuing the epic battle to fix TLS fingerprinting in Node (bsky.app/profile/pimt...), I opened two more PRs this week enabling cert compression in Node (github.com/nodejs/node/...) and direct native access to OpenSSL for addons (github.com/nodejs/node/...). With that, it's basically there!
github.com
Enable compression in OpenSSL and add opt-in certificate compression support for TLS connections by pimterry · Pull Request #62217 · nodejs/node
Until now, we&#39;ve fully disabled all compression features in OpenSSL via no-comp. This PR: Removes no-comp from our OpenSSL build, so we can use some compression features. This is required beca...
150
Tim Perry @pimterry.fyi · 04/03/2026
Wow, I sure am glad we have such diversity in the CSS world and that AIs consider all of the options fairly, instead of hypothetically being hyper focused on any specific library.
Which UI styling approach do you prefer?

  1. Tailwind + shadcn/ui (Recommended)
     Tailwind for utility CSS + shadcn/ui (Radix-based) for accessible, customizable components. Best native feel
     with full control.
  2. Tailwind + Radix UI
     Tailwind for styling + raw Radix primitives. More manual work but maximum flexibility.
  3. Ionic + Tailwind
     Ionic provides native-quality components and transitions out of the box. Heavier but purpose-built for
     Capacitor apps.
120
Reposted by Tim Perry
Open Web Advocacy @open-web-advocacy.org · 03/03/2026
⚠️ LAST CALL TO WRITE TO CMA: 5pm TODAY ⚠️ Under the current proposal, Apple can keep iOS and iPhone functionality exclusive to its own apps and services. If you want fair access to APIs for competing apps and browsers email 📧 mobilesms@cma.gov.uk See: open-web-advocacy.org/blog/apples-... 🧵👇️(1/5)
⚠️LAST CALL TO WRITE TO CMA:  5pm TODAY ⚠️
DEMAND FAIR ACCESS on iOS
Equal API Access to All Apps
Equal Performance and Privileges
Enforceable Deadlines & Oversight
FAILURE MEANS:
Developers can’t compete with Apple’s Apps & Hardware
Apple keeps features to themselves
Browsers & the Web won’t be able to compete
Sets Global Precedent for weak digital legislation
Less Competition = More Expensive + Worse Quality for consumers
👇 Read more, OWA blog link below
183
Tim Perry @pimterry.fyi · 02/03/2026
Magic link login is fine, session expiry is fine, but for the love of god please don't do both. If you have to re-auth every week, there is little more frustrating that blocking the process waiting for an email so I can click a button, over and over and over...
100
Reposted by Tim Perry
James Snell @jasnell.me · 27/02/2026
After implementing web streams in multiple runtimes, supporting them for years, talking with other implementers, dealing with issues... I think it's well past time we talked about something better blog.cloudflare.com/a-better-web...
blog.cloudflare.com
We deserve a better streams API for JavaScript
The Web streams API has become ubiquitous in JavaScript runtimes but was designed for a different era. Here's what a modern streaming API could (should?) look like.
58329
Tim Perry @pimterry.fyi · 26/02/2026
This looks very exciting: endowment.dev
endowment.dev
Open Source Endowment — World's First Endowment Fund for OSS
The Open Source Endowment provides truly sustainable funding for critical open source software through a community-driven endowment model.
000
Tim Perry @pimterry.fyi · 24/02/2026
Everybody's favourite "save me from myself" git hook (github.com/pimterry/git...) has the first new major feature in nearly 5 years: it'll now validate and catch unintended git pushes too 😀
github.com
GitHub - pimterry/git-confirm: :question: Git hook to catch placeholders and temporary changes (TODO / @ignore) before you commit or push them.
:question: Git hook to catch placeholders and temporary changes (TODO / @ignore) before you commit or push them. - pimterry/git-confirm
110
Reposted by Tim Perry
HTTP Toolkit @httptoolkit.com · 23/02/2026
Wouldn't it be nice if HTTP compression suddenly got 90% better for a whole bunch of common web scenarios? Dictionary Compression is here to save the day: httptoolkit.com/blog/diction...
httptoolkit.com
Dictionary Compression is finally here, and it's ridiculously good
Dictionary compression could completely change how applications send data over the web. It's recently gained broad support, and offers absurd real-world...
021
Reposted by Tim Perry
alex benzer @alexbenzer.com · 26/01/2026
2026 is the year Bluesky and the Atmosphere really come alive here's what's next bsky.social/about/blog/0...
bsky.social
What's Next at Bluesky - Bluesky
As we head into 2026, we're entering a new phase for the Bluesky app. Last year was about scaling through rapid growth and getting the fundamentals in place. This year is about leaning into what's wor...
1541835358
Tim Perry @pimterry.fyi · 09/12/2025
My AI code generation has decided it can generate an inline private key pair by itself, and I think we might be in trouble...
Node.js code that loads TLS & crypto, starts defining a KEY variable with BEGIN PRIVATE KEY, and then loops on the same 'random' string forever...
010
Reposted by Tim Perry
Lex Lofthouse @loftio.co.uk · 05/12/2025
Happy Cloudflare is down once again to all who celebrate
Screenshot of a Cloudflare site that says "500 Internal Server Error – Cloudflare"
12611
Reposted by Tim Perry
Ian Coldwater 🧊🚫 @lookitup.baby · 03/12/2025
A perfect CVSS 10 🧑🏻‍🍳💋 CVE-2025-55182: Unauthenticated remote code execution vulnerability in React Server Components The vuln is in versions 19.0, 19.1.0, 19.1.1, and 19.2.0: react-server-dom-webpack react-server-dom-parcel react-server-dom-turbopack Upgrade immediately!
react.dev
Critical Security Vulnerability in React Server Components – React
The library for web and native user interfaces
18286119
Tim Perry @pimterry.fyi · 04/12/2025
Being hit by my first DDOS attack right now, it's all quite exciting!!!
100
Reposted by Tim Perry
HTTP Toolkit @httptoolkit.com · 24/11/2025
Big milestone: HTTP Toolkit just crossed one million downloads! 🚀 Honestly I didn't think it'd ever get this far, I'm blown away. A huge thanks to all the users, contributors & supporters over the years ❤️. Onwards!
021
Reposted by Tim Perry
Andrey Sitnik @en.sitnik.es · 24/11/2025
Europe has plenty of problems that need solving. But it’s surprising how the brain-virus of ‘Europe only produces regulations’ has taken root. In reality, EU exports are higher than the US and comparable to China’s. Or in supercomputing, Europe ranks 2nd in the world.
2349
Tim Perry @pimterry.fyi · 24/11/2025
Just in case Shia-Hulud is making you paranoid as well, did you know you can link SSH keys to a Yubikey? ssh-keygen -t ed25519-sk -O resident -C "you@example.com" Requires a tap to confirm any git push. Even if malware steals your ssh key files, they're useless without the physical key.
100
Reposted by Tim Perry
tweety fish @sifu.tweety.fish · 18/11/2025
cloudflare's on-duty IT staff bangs on the doors which I have padlocked from the inside as I calmly break open lava lamp after lava lamp and drink the contents
172096546
Tim Perry @pimterry.fyi · 18/11/2025
These AWS & Cloudflare mega-outages are honestly embarrassing as an industry. Eugh. What are we doing??? We have so many tools & processes for ensuring reliability, but somehow two vendors can each single-handledly wipe everything out anytime.
130