The S in interoperability (https://frederikbraun.de/the-s-in-interoperability.html): A blog post about standards, their proliferation and the issues that arive over time.
Freddy
@freddyb.bsky.social
manager/security things for Firefox. love my family, my bike and reading books. You can also find me on Mastodon as @freddy@security.plumbing, which I consider my primary account. Homepage: https://frederikbraun.de/
The S in interoperability (https://frederikbraun.de/the-s-in-interoperability.html): A blog post about standards, their proliferation and the issues that arive over time.
New Blog post: "Multiple things can be true at the same time" - frederikbraun.de/feels-and-ll... Dear reader, I am sure you have read a lot of blog posts about AI in the past weeks or months. This is my post.…
Multiple things can be true at the same time
Multiple things can be true at the same time
frederikbraun.de
Major announcement: My highly successful Applied Cryptography course taught last year at the American University of Beirut is returning as an online course, available for FREE for any qualifying student from any Lebanese university! Read more + apply today — and please spread the word!
Applied Cryptography: Free Online Course for 50 Lebanese University Students This Summer
We're opening 50 spots for students at Lebanese universities to take the Applied Cryptography course online, completely free of charge, starting June 2026. Applications are open now.
symbolic.software
Next up, 'Improving the Trustworthiness of Javascript on the Web', presented by Michael Rosenberg, Giulio Berra, Ezzudin Alkotob, and Dennis Jackson #realworldcrypto
Composing Sanitizer configurations (https://frederikbraun.de/composable-sanitizers.html): The HTML Sanitizer API allows multiple ways to customize the default allow list and this blog post aims to describe a few variations and tricks we came up with while writing the specification.
New blog post: Perfect types with `setHTML()` - https://frederikbraun.de/perfect-types-with-sethtml.html - TLDR: Use require-trusted-types-for 'script'; trusted-types 'none'; in your CSP and nothing besides setHTML() works, essentially removing all DOM-XSS risks....
I was invited to join the @shoptalkshow.com podcast and talk about my favorite topic. The HTML Sanitizer API and `setHTML()`. Give it a spin in your favorite podcast player :) shoptalkshow.com/704/
704: Sanitizer API with Frederik Braun
We talk with Frederik Braun from Mozilla about the Sanitizer API, how it works with HTML tags and web components, what it does with malformed HTML, and where CSP fits in alongside the Sanitizer API…
shoptalkshow.com
this is your regular reminder that centralized, single-ownership social media is doomed
⚡ I've been contributing micro-optimisations to Go's standard library in my spare time: github.com/golang/go/co... 💸 I don't intend to stop any time soon, but if you benefit from my work and would like to support it, consider sponsoring me on GitHub: github.com/sponsors/jub... #golang #OpenSource
Sponsor @jub0bs on GitHub Sponsors
infosec enthusiast • Go developer & trainer • minimalist • chaotic good • trying to make sense of the Web • he/him
github.com
The Open Source Cryptography Workshop is returning for 2026, before Real World Crypto in Taipei. We are calling for session proposals, both presentations and hands-on workshops, on topics of interest to those who work on and with open source crypto. oscwork.shop/2026 #oscw #rwc #oscw2026 #rwc2026
OSCW 2026: Taipei, Taiwan :: Open Source Cryptography Workshop
OSCW 2026 will take place 8 March 2026, the day before Real World Crypto
oscwork.shop
Hey #39c3. Come see my lightning talk on a safe variant for `.innerHTML ` that is built right into the browser. Tomorrow (day 2), at approximately 12:25 - events.ccc.de/congress/202...
[39c3] Lightning Talks - Tag 2
- **Lightning Talks Introduction** - **Chaos auf der Schiene: Die Wahrheit hinter den Verspätungen** — *poschi* - **EventFahrplan - The 39C3 Fahrplan App for Android** — *tbsprs* - **Quantum computing...
events.ccc.de
Hey #39c3, chat me up if you want to talk about web security, browser security. I will be one of the tall dudes with a Firefox hoodie :)
lol, bsky wanting everyone's my birthday. Follow me on mastodon, you cowards.
New blog post: Why the Sanitizer API is just `setHTML()` - https://frederikbraun.de/why-sethtml.html
New blog post. Something off-topic to feed the search engine. A bug in Lego Star Wars: The Complete Saga (2007). https://frederikbraun.de/lego-star-wars-complete-saga-c3po-bug.html
I don't know who needs a kitty headbutt right now, but here's one for you
Firefox nightly introduces the setHTML() method. Which is like a native DOMPurify. You can easily test it here: portswigger-labs.net/mxss/ Set HTMLSanitizer ✅ Auto update ✅ I'm trying to break it, I encourage you to break it too
I'm in a phenomenal talk on gender inequality in cybersecurity this morrning and this is such a great cheat sheet for intersectional fair employment.
firefox container tabs are lowkey goated when $11/year VPS in dublin w/ socks5 over ssh is the vibe
happy VPN configuration day to all who celebrate
We just opened the Call-for-Papers for the German OWASP Day 2025. The event will be held November 25th-26th in Düsseldorf. god.owasp.de/2025/cfp.html We're looking for all sorts of presentations about web security and beyond for an audience of builders, breakers and defenders.
German OWASP Day 2025
god.owasp.de
cut my heap into pieces, this is my crash report: allocation, no alignment don't give a fuck if it faults on assignment this is fatal abort()