Frederik Braun �

1.7K Followers
615 Following
5.1K Posts

A web/browser security nerd. Working on security for Firefox and the web at Mozilla. Taught web security at Ruhr Uni Bochum.

I'm often spend my summer on multi-week #bikepacking trips with the family.

The posts here are my own and I do not speak for my employer

Websitehttps://frederikbraun.de/
LocationBerlin, Germany :club_mate:
Pronounshe/him
Signal usernamefreddy.{default HTTPS port}
TIL the favicon for https://lobste.rs (@lobsters ) is eerily similar to Lenovo.com :D

RE: https://mastodon.social/@fesshole/116690623225716127

Firefox has "copy clean link" in the context menu, just saying. :)

Would be really cool if there was a non-profit Certificate Transparency co-op that runs ct logs and takes donations. :)
Is there something equivalent to `ufw` for macOS? I have a Mac on a public IP and the built-in firewall is a too ambiguous - I really just want to say "only port A, B and C on interface X" and be done with it.
@freddy you & everyone should check out @bsidesvienna!
also: Vienna in late spring / early summer 😍

RE: https://social.security.plumbing/@freddy/116685551584070386

The presentation will also finally answer the question whether I am a one trick pony. 🫣🤫

Hey, any plans for the end of this month already?
If not, consider visiting the beautiful city of Vienna and joining me at the OWASP AppSec from June 22nd to 26th.

I will be talking about my favorite topic: Cross-Site Scripting (XSS)

My presentation is titled "The Devil is in the Defaults" and I'll share what I think we as web developers, as security engineers, as browser folks and standards people can now do to fix this once and for all ;)

Looks like they switched to LE. It works again.

Apparently the all Hetzner hosted nexclouds are unreachable because the wildcard `*.your-storageshare.de` certificate has expired. Good morning and #hugops. Phone support is overloaded and this is a cert from DigiCert.

If this was Let's Encrypt, I'd at least have the confidence that it's fixable in mere minutes....

Edit: Works again. Yay.