Max Hils's Avatar

Max Hils

@hi.ls

mitmproxy developer, making cloud more secure at Google. TLS, web, networks, and open source. Mostly active on http://fedi.hi.ls these days, mirroring announcements here.

134
Followers
156
Following
13
Posts
12.01.2025
Joined
Posts Following

Latest posts by Max Hils @hi.ls

The LaTeX Korrektor 2/6: How to make sure everyone thinks your papers are written by AI. ๐Ÿฅฒ

02.12.2025 14:19 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

browsers should be allowed to display the <li> in a <ul> in whatever order they like

18.11.2025 19:45 ๐Ÿ‘ 63 ๐Ÿ” 13 ๐Ÿ’ฌ 7 ๐Ÿ“Œ 1

One of my favorite games just got a free content update ten years after initial release. @metanetsoftware.com is just crazy cool. ๐Ÿ˜

18.10.2025 22:50 ๐Ÿ‘ 3 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
autofix.ci is down ยท Issue #32 ยท autofix-ci/action we're getting Error: getaddrinfo ENOTFOUND api.autofix.ci in the github action and http://autofix.ci also seems down

Thanks for the heads-up! Things should be fixed since yesterday, my registrar screwed up apparently. ๐Ÿ™ˆ (Details: github.com/autofix-ci/a...)

02.10.2025 15:50 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

rust is a language in which you can borrow a cow

24.08.2025 23:05 ๐Ÿ‘ 30 ๐Ÿ” 4 ๐Ÿ’ฌ 3 ๐Ÿ“Œ 0

If you work on HTTP implementations, deploy it at scale, or have a unique perspective or interest in the protocol, you might find other people to talk to at the 2026 HTTP Workshop: https://github.com/HTTPWorkshop/workshop2026?tab=readme-ov-file#2026-http-workshop

20.08.2025 00:55 ๐Ÿ‘ 6 ๐Ÿ” 4 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

You can also put stuff onto the tracks to cause any train to do an emergency break. Granted, attack complexity and stealthiness may be a bit better here, but I can see how they are a bit scared of "we crashed into another train because their stop signal wasn't properly signed" scenarios. :)

14.08.2025 11:22 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

At the beginning of the study, developers forecasted that they would get sped up by 24%. After actually doing the work, they estimated that they had been sped up by 20%. But it turned out that they were actually slowed down by 19%.

10.07.2025 19:46 ๐Ÿ‘ 632 ๐Ÿ” 56 ๐Ÿ’ฌ 3 ๐Ÿ“Œ 12
LazyLock in std::sync - Rust A value which is initialized on the first access.

I really like doc.rust-lang.org/beta/std/syn... for this use case. Derefs to the inner value, so no calling necessary. :)

10.07.2025 02:02 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Preview
The ethics of README ads Iโ€™ve been considering accepting sponsorship again for my projects.

I post on "The ethics of README ads"

willmcgugan.github.io/the-ethics-o...

05.06.2025 09:10 ๐Ÿ‘ 16 ๐Ÿ” 4 ๐Ÿ’ฌ 3 ๐Ÿ“Œ 0

Great topic, your "luxury of being able to turn them down" framing is really nice.

I personally find bulma.io to be an interesting example. With 40 sponsors at $100/month it's getting non-negligible. Great for project sustainability, who am I to judge?

05.06.2025 18:40 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

I this the IPv6 thing people keep talking about? I heard it has larger numbers. ๐Ÿฅธ

14.05.2025 16:22 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Check out pyo3 if you haven't, it's rad

13.05.2025 21:33 ๐Ÿ‘ 2 ๐Ÿ” 2 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

You don't have to write software in c++

10.05.2025 14:34 ๐Ÿ‘ 8 ๐Ÿ” 1 ๐Ÿ’ฌ 2 ๐Ÿ“Œ 0
Mitmproxy 12: Interactive Contentviews

mitmproxy 12 is out! ๐Ÿš€ Itโ€™s now possible to modify the prettified representation of binary protocols. Editing Protobufs is now as easy as editing YAML, no .proto schema needed. ๐Ÿ™Œ

mitmproxy.org/posts/releas...

29.04.2025 21:23 ๐Ÿ‘ 8 ๐Ÿ” 7 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Post image

Also, this seems like a small feature but much appreciated:

30.04.2025 04:24 ๐Ÿ‘ 3 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Mitmproxy 12: Interactive Contentviews

mitmproxy 12 is out! ๐Ÿš€ Itโ€™s now possible to modify the prettified representation of binary protocols. Editing Protobufs is now as easy as editing YAML, no .proto schema needed. ๐Ÿ™Œ

mitmproxy.org/posts/releas...

29.04.2025 21:23 ๐Ÿ‘ 8 ๐Ÿ” 7 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Post image

The next version of Rust might be one of the most transformative to the Rust ecosystem due to support for up-casting of trait objects. This makes `Any` significantly more powerful and potent!

27.03.2025 10:37 ๐Ÿ‘ 90 ๐Ÿ” 15 ๐Ÿ’ฌ 7 ๐Ÿ“Œ 1

0.1 + 0.2 == 0.3

20.03.2025 14:33 ๐Ÿ‘ 183 ๐Ÿ” 40 ๐Ÿ’ฌ 3 ๐Ÿ“Œ 0
Post image Post image

Not sure how I should feel about our new ice cream scoop containing AI. ๐Ÿค”

07.03.2025 19:39 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Chromium GSoC 2025 Project Ideas and Info Chromium GSoC 2025 Project Ideas and Info

Here are the project ideas and info for Chromium:

06.03.2025 17:33 ๐Ÿ‘ 8 ๐Ÿ” 4 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 2

๐ŸŽ‰๐ŸŽ‰๐ŸŽ‰

Really cool effort. I didn't mind TLS fingerprinting back when it was it was used sparingly and carefully to fight actual abuse, but with everyone and their CDN now randomly blocking clients it just needs to die.

06.03.2025 16:30 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Preview
Use empty renegotiate extension instead of SCSV for TLS > 1.0 by pimterry ยท Pull Request #24161 ยท openssl/openssl This PR fixes #18790. This is my very first OpenSSL PR, and day to day I don&#39;t write much C (and zero Perl) so I&#39;d appreciate some careful review! I&#39;ve just emailed a signed CLA to the ...

This is part of an ongoing personal campaign to kill TLS fingerprinting.

With this change + github.com/openssl/open..., OpenSSL TLS traffic won't have any non-configurable distinguishing features, and so I _think_ it should be possible to configure it to exactly match modern browser traffic.

06.03.2025 15:32 ๐Ÿ‘ 2 ๐Ÿ” 1 ๐Ÿ’ฌ 2 ๐Ÿ“Œ 0
Preview
Wachstumseffekte eines kreditfinanzierten Investitionsprogramms Es wird ein kreditfinanziertes รถffentliches Investitionsprogramm fรผr die deutsche Wirtschaft von 600 Milliarden Euro in den nรคchsten 10 Jahren mit dem NiGEM-Modell simuliert. Die Ergebnisse zeigen erhebliche Wachstumseffekte, besonders lรคngerfristig aufgrund der positiven Auswirkungen des hรถheren รถffentlichen Kapitalstocks auf private Investitionsentscheidungen. <BR>Das BIP kรถnnte lรคngerfristig zeitweise um rund 6 % รผber seinem Niveau ohne Investitionsoffensive liegen. AuรŸerdem regt das Programm die private Investitionstรคtigkeit deutlich an, sodass die Unternehmensinvestitionen bis zu 10 % รผber ihr Niveau ohne Programm steigen. Konkret bedeutet das, dass die aufsummierte Wirtschaftsleistung Deutschlands von 2025 bis 2050 um bis zu 4800 Mrd. Euro hรถher ausfallen wรผrde. 2045 lรคge das jรคhrliche Pro-Kopf-BIP um 3600 Euro hรถher, als es ohne das Programm der Fall wรคre. <BR>Zwar erhรถht sich das staatliche Budgetdefizit wรคhrend der zehnjรคhrigen Laufzeit des Programms um etwa 1 % des BIP. Alle

Neu: Unsere @imkinstitut.bsky.social Simulation, was mit Wirtschaftswachstum und Schulden in Deutschland passieren wรผrde, wenn man รผber die kommenden 10 Jahre 600 Mrd. โ‚ฌ zusรคtzlich in die รถffentliche Infrastruktur investieren wรผrde. (1/)

www.imk-boeckler.de/de/faust-de...

06.02.2025 11:42 ๐Ÿ‘ 52 ๐Ÿ” 31 ๐Ÿ’ฌ 3 ๐Ÿ“Œ 5
Preview
Mitmweb API Authentication Bypass Using Proxy Server ### Impact In mitmweb 11.1.0 and below, a malicious client can use mitmweb's proxy server (bound to `*:8080` by default) to access mitmweb's internal API (bound to `127.0.0.1:8081` by default). In...

mitmproxy 11.1.2 is out, everyone should upgrade! We fixed a rather nasty SSRF-style vulnerability affecting mitmweb (CVE-2025-23217). mitmproxy and mitmdump users are unaffected.

github.com/mitmproxy/mi...

06.02.2025 01:34 ๐Ÿ‘ 3 ๐Ÿ” 2 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

now that this is (hopefully) over, I'd like to state the obvious that pestering FOSS maintainers with your misguided compliance issues โ€“ in the holiday season no less โ€“ is not something that gets you on Santa's good list

24.01.2025 08:58 ๐Ÿ‘ 9 ๐Ÿ” 2 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

Sharing rsync instances vulnerable to CVE-2024-12084 RCE (version check only) in our updated daily Accessible Rsync report: shadowserver.org/what-we-do/n...

17,475 instances found vulnerable (out of 146,844) on 2025-01-16. Top affected: US (5K)

dashboard.shadowserver.org/statistics/c...

17.01.2025 10:03 ๐Ÿ‘ 5 ๐Ÿ” 2 ๐Ÿ’ฌ 2 ๐Ÿ“Œ 1

Template Injection needs a fertile breeding ground. :)

14.01.2025 13:22 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Intercepting Linux Applications

mitmproxy 11.1 is out! ๐Ÿฅณ

We now support *Local Capture Mode* on Windows, macOS, and - new - Linux! This allows users to intercept local applications even if they don't have proxy settings.

More details are at mitmproxy.org/posts/local-.... Super proud of this team effort. ๐Ÿ˜ƒ

12.01.2025 13:59 ๐Ÿ‘ 75 ๐Ÿ” 23 ๐Ÿ’ฌ 2 ๐Ÿ“Œ 2