@freddy@security.plumbing avatar

freddy

@freddy@security.plumbing

👨‍👩‍👧‍👦 Dad // 👨‍💻 Security Engineer & Manager for Mozilla Firefox // ⛺🚴 Cyclist // co-founded CTF team fluxfingers in '07. // opinions are my own and I do not speak for my employer.

This profile is from a federated server and may be incomplete. Browse more on the original instance.

netzpolitik_feed, to random German
@netzpolitik_feed@chaos.social avatar

Für das Standardisierungsgremium IETF ist es neu, sich mit Themen wie Stalking zu beschäftigen. Doch bei der Diskussion um einen Standard für Standort-Tracker war genau das notwendig. Mallory Knodel sagt im Interview mit @anneroth, die Standards-Community sollte stolz darauf sein, jetzt auch gesellschaftliche Auswirkungen miteinzubeziehen. https://netzpolitik.org/2024/interview-zu-standort-trackern-google-und-apple-kooperieren-lieber-als-ein-verbot-zu-riskieren/

freddy,
@freddy@security.plumbing avatar

@netzpolitik_feed @anneroth So wichtig, dass sich Zivilgesellschaft in Foren für technische Standards einbringt. Wer sich in zB W3C oder WHATWG einbringen möchte und eine kurze Orientierung sucht, darf mich jederzeit fragen. Ich helfe gerne.

freddy,
@freddy@security.plumbing avatar

@anneroth @littledetritus @netzpolitik_feed Leider nicht. Gibt es da ne Lobby oder ähnliches wo man einfach ohne Ticket dazu kommen kann? Ich wohne in der Nähe und könnte mich morgen (Mittwoch) zwischen 13 und 14:30 Uhr dazumogeln oder irgendwann späten nachmittag/abend. 🙂

freddy,
@freddy@security.plumbing avatar

@littledetritus @anneroth @netzpolitik_feed dann machen wir doch morgen Abend. 17 oder 18 Uhr lieber?

freddy, to til
@freddy@security.plumbing avatar

Oh #TIL. The whole "AI" scraping bots are obviously not paying attention to nofollow, noindexand so on. So now all kind of "SEO" spam prevention stuff you do on your websites is pointless now. Cool, cool, cool.

freddy, to random
@freddy@security.plumbing avatar

Oooh, exciting job. Firefox desktop integration is looking for a software engineer. This includes sandboxing and other cool operating system APIs! Remote wherever we can hire people (e.g., not in Antarctica). https://grnh.se/a506ffe01us

freddy, to random
@freddy@security.plumbing avatar

Firefox Roadmap shared on Mozilla Connect

https://connect.mozilla.org/t5/discussions/here-s-what-we-re-working-on-in-firefox/td-p/57694

Highlights:

  • tab grouping, vertical tabs
  • new profile management system
  • customizable new tab wallpapers
  • settings/menu rehaul

Also doubling down on our successful initiatives in performance, privacy & security.

That being said, we are driven by our awesome community. So bring your comments and questions to the Mozilla Connect thread :))

swiefling, (edited ) to security
@swiefling@hci.social avatar

Privacy matters! But what if the tools meant to protect us are being misused? Our latest study (to appear ARES '24) reveals surprising facts about HTTP Client Hints (HTTP CHs) on the Web. [THREAD]

Paper + Website: https://rbainfo.org/clienthints

freddy,
@freddy@security.plumbing avatar

@swiefling I believe this has been a criticism of Client Hints from the get go and one of the reasons why it’s not implemented in all browser engines.

freddy, to random
@freddy@security.plumbing avatar

Our amazing Firefox networking team is looking for a student worker. This is exclusive to folks who are enrolled into a university in Germany. Your future colleagues are fun, the code is C++ and the browser is private. We have an office in Berlin, but remote is also OK https://www.mozilla.org/en-US/careers/position/gh/5963661/ (please share widely)

freddy, to random
@freddy@security.plumbing avatar

Want to work on Firefox code and don't know where to start?

Our team has some "good first bugs", take a look here: https://bugzilla.mozilla.org/buglist.cgi?quicksearch=ALL%20keywords%3Agood-first-bug%20component%3A%22DOM%3A%20Security%22%20status%3Anew&list_id=17015159

First, make sure that your system is able to build Firefox as per our instructions https://firefox-source-docs.mozilla.org/setup/index.html (
If you hit a problem, there's an introduction chat here https://wiki.mozilla.org/Matrix)

MoritzGiessmann, to random
@MoritzGiessmann@mastodon.social avatar

@freddy Mal angenommen man wollte auf Firefox-Basis ein Theme bauen, das sich so verhält wie der Arc Browser (Tab Split View, Seitliche Tabs, Overall look and feel). Glaubst du das ist mit vertretbarem Aufwand machbar, oder eher nicht?

freddy,
@freddy@security.plumbing avatar

@MoritzGiessmann "vertretbar" ist ein schwieriges Wort. Wenn man weiß was man anfassen muss, ist es "nur frontend web kram". Aber unklar wie groß dieses "wenn" ist.

Ich glaube das effektivste ist, wenn du ca, 2 Stunden pro Woche hast, kannst du dich als open source Mitarbeiter am aktuellen Sideview Feature beteiligen.

freddy,
@freddy@security.plumbing avatar

@MoritzGiessmann … Um zu gucken ob das für dich in die richtige Richtung geht: Firefox Nightly installieren. In about:config die sidebar enabled pref finden und setzen. Über addons.mozilla.org sideview installieren. Ein "vertical tabs" addon deiner wahl dazu (treestyle tabs oder sideberty). Dann überlegen wie viel dir fehlt. (2/2)

MoritzGiessmann, to ama German
@MoritzGiessmann@mastodon.social avatar

I spent a considerable amount of time in WiFi captive portals. #ama

freddy,
@freddy@security.plumbing avatar

@MoritzGiessmann Did Firefox's portal detection kick in? If so, did it help you? If not, do you know why?

freddy, to random
@freddy@security.plumbing avatar

Hey, Firefox didn’t do downloads right in the last week or so. If that happened to you, then I wanna say we're sorry and Firefox 125.0.2 is available as of right now. Go to Help/About Firefox to trigger an immediate update.

freddy, to random
@freddy@security.plumbing avatar

Daughter was drawing me a sick note. Hooray, no work today.

mhoye, to random
@mhoye@mastodon.social avatar

Since I see that a notable VC-famous is now telling us that he wish he'd "stood by" Eich way back, I'd like to tell you a true fact that situation: Eich didn't lose the CEO's job for his (reprehensible) Prop-8 donation.

Everyone wants to believe that's true, because fits nicely into narratives a number of invested camps want to believe, whether it's somebody being ousted for reprehensible views the woke SJW mob somehow pulling down a great leader (tm) but that's not what happened.

freddy,
@freddy@security.plumbing avatar

@nadim @mhoye I worked there back then. I know Mike. You know me. 🤷
At the same time, everyone has their biases and gripes and opinions. That’s OK.

freddy, to random
@freddy@security.plumbing avatar

Hey everyone who feels like they should stop reading hacker news and still want to properly procrastinate, go to https://lobste.rs/ instead. That’s all.

freddy, to random
@freddy@security.plumbing avatar

Last night, about 21 hours ago, Manfred Paul demonstrated a security exploit targeting Firefox 124 at pwn2own.

In response, we have just published Firefox 124.0.1 (and Firefox ESR 115.9.1) containing the security fix.

Please update your foxes! 🦊

Kudos to all the countless people postponing their sleep and working towards resolving this so quickly! Really impressive teamwork again. Also, kudos to Manfred for pwning Firefox again :)

kev, (edited ) to random
@kev@fosstodon.org avatar

@niqwithq talks about segregating your email and not publishing your personal email where possible. One email address ain't gonna cut it these days.
https://kevquirk.com/email-privacy

freddy,
@freddy@security.plumbing avatar

@kev @niq random email addresses is a cool feature. I wish my favorite browser would copy that.

freddy,
@freddy@security.plumbing avatar

@kev @niq oh wait no. We do that with Firefox relay. 🤣

squidfunk, to random
@squidfunk@fosstodon.org avatar
freddy,
@freddy@security.plumbing avatar

@squidfunk guess we can all stop assuming that interactions on the net have any amount of care and deliberation in them. Assuming good faith now requires overcoming a threshold of impact / semantics, instead of the "someone put time and effort into a carefully written comment"

freddy, to random
@freddy@security.plumbing avatar

Layoffs suck.
Go hire a Mozillian you managers out there. They are all good people.

freddy, to random
@freddy@security.plumbing avatar

In https://crbug.com/1472898, someone a cool bug in Chrome.
Looks like some pages like https://chrome.google.com /webstore* have extra privileges to do things normal web pages can't do. To make that work safely, the browser needs to disallow WebExtensions to work on those privileged pages.
This bug is about how someone found out they can execute code by introducing a trailing dot. E.g., https://chrome.google.com./webstore*

So I wondered, how would that look like in Firefox?

A thread 🧵

freddy,
@freddy@security.plumbing avatar

@WPalant 👏👏👏

I knew there'd be a old bug somewhere. Thank you, sir!

freddy,
@freddy@security.plumbing avatar

@WPalant I think the permission manager used to operate on host names, which lead to some funky problems. I believe I argued for it to use origins (the principals API) briefly after I joined. I think that should solve the trailing dot thing, but slightly differently.

Ah, I found it. https://bugzilla.mozilla.org/show_bug.cgi?id=1066517

freddy,
@freddy@security.plumbing avatar
j9t, (edited ) to random
@j9t@mas.to avatar

A glossary for our field’s rabbit hole. Now also available as a website.

https://webglossary.info

freddy,
@freddy@security.plumbing avatar
  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • InstantRegret
  • mdbf
  • ethstaker
  • magazineikmin
  • cubers
  • rosin
  • thenastyranch
  • Youngstown
  • osvaldo12
  • slotface
  • khanakhh
  • kavyap
  • DreamBathrooms
  • provamag3
  • Durango
  • everett
  • tacticalgear
  • modclub
  • anitta
  • cisconetworking
  • tester
  • ngwrru68w68
  • GTA5RPClips
  • normalnudes
  • megavids
  • Leos
  • lostlight
  • All magazines