Tim Perry
@pimterry.fyi
Founder of https://httptoolkit.com (@httptoolkit.com), Node.js core collaborator, tech speaker, drummer, mountain biker and dad. 🇬🇧/🇨🇦 living in 🇪🇸
I do lots of long-ish horizon work (e.g. OpenSSL PRs I can't actually use for years after merging). Remarkable how bad LLMs are at even considering this as an option. Quick fix every time, even if there's a clear long-term right answer we should do instead. Does not bode well for the ecosystem...
Made my first PR to an IETF standard draft: github.com/quicwg/qmux/.... End result will be a bit inconvenient for all involved 😂 but better to fix it now!
Fix hex encoding of protocol magic number by pimterry · Pull Request #69 · quicwg/qmux
The intended magic number string was changed to from QS0 to QMX when the spec was renamed (#14) and the description shows this correctly, but the hex value was not updated anywhere. The magic numbe...
github.com
Nearly 5 years of work later, I've successfully closed the Node.js TLS fingerprinting issue: github.com/nodejs/node/.... As of Node 26.4.0, it's possible to match most common TLS fingerprints in Node directly. I've published a library to do all the hard work here: github.com/httptoolkit/...
GitHub - httptoolkit/node-tls-impersonate: TLS fingerprint control within Node.js's normal networking APIs
TLS fingerprint control within Node.js's normal networking APIs - httptoolkit/node-tls-impersonate
github.com
Have you seen testserver.host/? As part of building HTTP Toolkit I often need a remote servers for testing edge cases, so I've built one! Now fairly mature & stable. It's httpbin.org plus badssl.com plus lots of extras.
Testserver
Endpoints can be combined using double-dashes, e.g. expired--revoked--http2--tls-v1-2.{domain} will return an expired and revoked certificate, use TLSv1.2, and then negotiate HTTP/2 on the connection.
testserver.host
Jeg er til det her oplæg, og der er stuvende fyldt. Det er konferencens fjerde dag, folk er trætte og kunne sove længe. Men folk kommer hele tiden ind. De sidder på gulvet og står nede bagved. Det her kommer til at kunne ses i journalistik rundt om i Europa i fremtiden 🥳
I'm speaking at @journalismarena.eu's Dataharvest conf in Belgium this weekend! I'll be teaching investigative journalists how to intercept, interpret & scrape mobile app network traffic, it's going to be a lot of fun 😀 Anybody else I know here attending? Would be great to meet up #dataharvest26
I'm speaking at @journalismarena.eu's Dataharvest conf in Belgium this weekend! I'll be teaching investigative journalists how to intercept, interpret & scrape mobile app network traffic, it's going to be a lot of fun 😀 Anybody else I know here attending? Would be great to meet up #dataharvest26
Dataharvest 2026 - the European Investigative Journalism Conference: Unlocking the apps: How can you scrape d...
View more about this event at Dataharvest 2026 - the European Investigative Journalism Conference
dataharvest26.sched.com
Staged publishing for npm! Finally 🙏 I'm only just starting to test it now, but in theory at least this + trusted publishing could very significantly tighten up the security posture for lots of packages. Would be fantastic to see the current wave of attacks slow down a bit.
Staged publishing for npm packages | npm Docs
Documentation for the npm registry, website, and command-line interface
docs.npmjs.com
Chrome shipped an LLM Prompt API to the web platform. At Mozilla, we oppose this API. Here's why:
Somewhere there's a CEO stuck in a meeting that's in desperate need of amazon gift cards, completely unable to get their team to answer their texts
So, Chrome's "web standard" Prompt API: Mozilla: Opposed WebKit: Opposed Microsoft: Several concerns W3C TAG: Several concerns Developers: Mostly negative Chrome: Ships anyway. A sad time for web standards. But, I guess someone at Google will get promoted, so 'every cloud…'
Tip: NEVER use a random number. A non deterministic "solution" is unworthy of the divine touch of a turing machine
I've been thinking about simonomi.dev/blog/color-c.... Whipped up a quick prototype for HTTP Toolkit's hex view - what do you think? Interesting and more useful than monochrome, or just visually noisy? See if you can guess what each file type is here - answers in the alt text 😀
Just created my first Azure account to migrate HTTP Toolkit from certs to Microsoft's new 'Artifact Signing' setup (azure.microsoft.com/en-us/produc...). The UI is eye opening... Flashback 10 years in UI, impossible navigation, endless "Please update from X"/"Did you know Y is now Z" banners, wow 😬
Azure Artifact Signing (formerly Trusted Signing) | Microsoft Azure
Secure your applications with Artifact Signing (formerly Azure Trusted Signing), a fully managed end-to-end signing service for code, documents, and applications.
azure.microsoft.com
HTTP Toolkit is now on the @fsfe.org major donor list! fsfe.org/donate/thank... They're doing great work right now like fsfe.org/news/2026/ne... - if you're also keen on open platforms & interoperability do please donate to support them too ❤️
Apple keeps challenging its interoperability obligations under the DMA - FSFE
A new FSFE report exposes how 56 interoperability requests under the Digital Markets Act have produced no concrete solutions by Apple, and how their declin...
fsfe.org
WebSerial has landed in Firefox Nightly !! 🎉 Enable it in about:config and it all just works as expected. Took a brand new ESP32 and had a new Bluetooth proxy added to Home Assistant within 2 minutes 👌
Two papers came out last week that suggest classical asymmetric cryptography might indeed be broken by quantum computers in just a few years. That means we need to ship post-quantum crypto now, with the tools we have: ML-KEM and ML-DSA. I didn't think PQ auth was so urgent until recently.
A Cryptography Engineer’s Perspective on Quantum Computing Timelines
The risk that cryptographically-relevant quantum computers materialize within the next few years is now high enough to be dispositive, unfortunately.
words.filippo.io
Damn I got this as well! Just assumed it was spam and ignored this (and the LinkedIn follow up) turns out I dodged a bullet 😅
🚨 New Investigation: Attackers are hunting the maintainers behind Lodash, Fastify, buffer, Pino, mocha, Express, and #Nodejs core, because compromising one of them means write access to packages downloaded billions of times a week. socket.dev/blog/attacke...
Finally bit the bullet and bought more RAM! The rumours are true, the prices really are excruciating, more than 4x the price I paid for the other stick 18 months back 🥲
In case you want to understand your TLS clients in depth from Node.js, there's a new v2 release of read-tls-client-hello now live: github.com/httptoolkit/... Also now supported on testserver.host at testserver.host/tls/client-h..., so you can test & debug clients themselves directly.
GitHub - httptoolkit/read-tls-client-hello: A pure-JS module to read TLS client hello data and calculate TLS fingerprints from an incoming socket connection.
A pure-JS module to read TLS client hello data and calculate TLS fingerprints from an incoming socket connection. - httptoolkit/read-tls-client-hello
github.com
I've been playing around with agent-powered HTTP debugging -there's a lot of potential here... Even just with minimal data, Claude gets a really good understanding of flows very quickly, amazing for exploring. A quick summary of overall traffic & state flow across ~160 requests & responses:
Mozilla Festival is coming back to Barcelona. 28–30 October 2026 at Recinte Fabra i Coats. Sign up to be first to know when tickets drop⚡ #MozFest mzl.la/47PLTG9
Do I know anybody at GitHub who can help me get HTTP Toolkit into the student pack? I'm happy to do free accounts for students, I've filled out the form a couple of times - they never reply, but students keep endlessly emailing me to ask me if it's included.
Node.js is moving to one major release per year starting with Node 27! 🚀 ✅ Simpler: Every release becomes LTS. ✅ Predictable: Version numbers now align with the year. ✅ New: A 6-month Alpha channel for early testing. https://bit.ly/4rnosLg
Node.js — Evolving the Node.js Release Schedule
Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.
nodejs.org
Continuing the epic battle to fix TLS fingerprinting in Node (bsky.app/profile/pimt...), I opened two more PRs this week enabling cert compression in Node (github.com/nodejs/node/...) and direct native access to OpenSSL for addons (github.com/nodejs/node/...). With that, it's basically there!
Enable compression in OpenSSL and add opt-in certificate compression support for TLS connections by pimterry · Pull Request #62217 · nodejs/node
Until now, we've fully disabled all compression features in OpenSSL via no-comp. This PR: Removes no-comp from our OpenSSL build, so we can use some compression features. This is required beca...
github.com
Made my 2nd PR to OpenSSL: github.com/openssl/open.... More than any other project, I feel very cautious about OpenSSL contributions - code & setup is complicated & fiddly, I'm not familiar with their patterns, and boy oh boy is it high-profile if you break it. Hopefully this is an easy one though!
Wow, I sure am glad we have such diversity in the CSS world and that AIs consider all of the options fairly, instead of hypothetically being hyper focused on any specific library.
⚠️ LAST CALL TO WRITE TO CMA: 5pm TODAY ⚠️ Under the current proposal, Apple can keep iOS and iPhone functionality exclusive to its own apps and services. If you want fair access to APIs for competing apps and browsers email 📧 mobilesms@cma.gov.uk See: open-web-advocacy.org/blog/apples-... 🧵👇️(1/5)
Magic link login is fine, session expiry is fine, but for the love of god please don't do both. If you have to re-auth every week, there is little more frustrating that blocking the process waiting for an email so I can click a button, over and over and over...
After implementing web streams in multiple runtimes, supporting them for years, talking with other implementers, dealing with issues... I think it's well past time we talked about something better blog.cloudflare.com/a-better-web...
We deserve a better streams API for JavaScript
The Web streams API has become ubiquitous in JavaScript runtimes but was designed for a different era. Here's what a modern streaming API could (should?) look like.
blog.cloudflare.com