browsers should be allowed to display the <li> in a <ul> in whatever order they like
Max Hils
@hi.ls
mitmproxy developer, making cloud more secure at Google. TLS, web, networks, and open source. Mostly active on http://fedi.hi.ls these days, mirroring announcements here.
One of my favorite games just got a free content update ten years after initial release. @metanetsoftware.com is just crazy cool. 😍
It's time! Today we're celebrating N++'s 10th Anniversary, aka TEN++, with style -- a fancy free update to the game and a Daily Deal on Steam: store.steampowered.com/app/230270/N...
If you work on HTTP implementations, deploy it at scale, or have a unique perspective or interest in the protocol, you might find other people to talk to at the 2026 HTTP Workshop: https://github.com/HTTPWorkshop/workshop2026?tab=readme-ov-file#2026-http-workshop
At the beginning of the study, developers forecasted that they would get sped up by 24%. After actually doing the work, they estimated that they had been sped up by 20%. But it turned out that they were actually slowed down by 19%.
You don't have to write software in c++
If you’re over 30, quote this with some life advice 🤌🏼
mitmproxy 12 is out! 🚀 It’s now possible to modify the prettified representation of binary protocols. Editing Protobufs is now as easy as editing YAML, no .proto schema needed. 🙌 mitmproxy.org/posts/releas...
Mitmproxy 12: Interactive Contentviews
mitmproxy.org
Also, this seems like a small feature but much appreciated:
mitmproxy 12 is out! 🚀 It’s now possible to modify the prettified representation of binary protocols. Editing Protobufs is now as easy as editing YAML, no .proto schema needed. 🙌 mitmproxy.org/posts/releas...
Mitmproxy 12: Interactive Contentviews
mitmproxy.org
The next version of Rust might be one of the most transformative to the Rust ecosystem due to support for up-casting of trait objects. This makes `Any` significantly more powerful and potent!
Here are the project ideas and info for Chromium:
Chromium GSoC 2025 Project Ideas and Info
Chromium GSoC 2025 Project Ideas and Info
docs.google.com
This is part of an ongoing personal campaign to kill TLS fingerprinting. With this change + github.com/openssl/open..., OpenSSL TLS traffic won't have any non-configurable distinguishing features, and so I _think_ it should be possible to configure it to exactly match modern browser traffic.
Use empty renegotiate extension instead of SCSV for TLS > 1.0 by pimterry · Pull Request #24161 · openssl/openssl
This PR fixes #18790. This is my very first OpenSSL PR, and day to day I don't write much C (and zero Perl) so I'd appreciate some careful review! I've just emailed a signed CLA to the ...
github.com
Neu: Unsere @imkinstitut.bsky.social Simulation, was mit Wirtschaftswachstum und Schulden in Deutschland passieren würde, wenn man über die kommenden 10 Jahre 600 Mrd. € zusätzlich in die öffentliche Infrastruktur investieren würde. (1/) www.imk-boeckler.de/de/faust-de...
Wachstumseffekte eines kreditfinanzierten Investitionsprogramms
Es wird ein kreditfinanziertes öffentliches Investitionsprogramm für die deutsche Wirtschaft von 600 Milliarden Euro in den nächsten 10 Jahren mit dem NiGEM-Modell simuliert. Die Ergebnisse zeigen erhebliche Wachstumseffekte, besonders längerfristig aufgrund der positiven Auswirkungen des höheren öffentlichen Kapitalstocks auf private Investitionsentscheidungen. <BR>Das BIP könnte längerfristig zeitweise um rund 6 % über seinem Niveau ohne Investitionsoffensive liegen. Außerdem regt das Programm die private Investitionstätigkeit deutlich an, sodass die Unternehmensinvestitionen bis zu 10 % über ihr Niveau ohne Programm steigen. Konkret bedeutet das, dass die aufsummierte Wirtschaftsleistung Deutschlands von 2025 bis 2050 um bis zu 4800 Mrd. Euro höher ausfallen würde. 2045 läge das jährliche Pro-Kopf-BIP um 3600 Euro höher, als es ohne das Programm der Fall wäre. <BR>Zwar erhöht sich das staatliche Budgetdefizit während der zehnjährigen Laufzeit des Programms um etwa 1 % des BIP. Alle
imk-boeckler.de
mitmproxy 11.1.2 is out, everyone should upgrade! We fixed a rather nasty SSRF-style vulnerability affecting mitmweb (CVE-2025-23217). mitmproxy and mitmdump users are unaffected. github.com/mitmproxy/mi...
Mitmweb API Authentication Bypass Using Proxy Server
### Impact In mitmweb 11.1.0 and below, a malicious client can use mitmweb's proxy server (bound to `*:8080` by default) to access mitmweb's internal API (bound to `127.0.0.1:8081` by default). In...
github.com
now that this is (hopefully) over, I'd like to state the obvious that pestering FOSS maintainers with your misguided compliance issues – in the holiday season no less – is not something that gets you on Santa's good list
Seeing how people are pressuring attrs with the license now showing up where they like, I'm releasing a new version of `pypi-publish` v1.12.4. github.com/pypa/gh-acti... / github.com/pypa/gh-acti... #python #Packaging
Sharing rsync instances vulnerable to CVE-2024-12084 RCE (version check only) in our updated daily Accessible Rsync report: shadowserver.org/what-we-do/n... 17,475 instances found vulnerable (out of 146,844) on 2025-01-16. Top affected: US (5K) dashboard.shadowserver.org/statistics/c...
mitmproxy 11.1 is out! 🥳 We now support *Local Capture Mode* on Windows, macOS, and - new - Linux! This allows users to intercept local applications even if they don't have proxy settings. More details are at mitmproxy.org/posts/local-.... Super proud of this team effort. 😃
Intercepting Linux Applications
mitmproxy.org