Profile for max
About max
Fields
- website
- https://hi.ls
- tootfinder
- searchable
Bio
mitmproxy developer, doing security things at Google. TLS, web, networks, and open source.
- Joined
- Posts
- 292
- Followed by
- 312
- Following
- 294
Stats
Letting LLMs churn out SIMD-optimized Rust is such a unholy cheatcode. Holy crap, speed and quality are mindblowing. 🤯
Those EOL announcements were way more fun when they affected shitty brands I didn't buy from. 🥲
https://www.bose.com/soundtouch-end-of-life
Four hours of complex async Rust code. Really gnarly stuff.
Runs flawlessly on first compile.
🦀 🫡🫡🫡🫡🫡
I'm in love with 🇨🇭. Gigachad SBB stops the delayed incoming train at the border (keep shit out of the system), spontaneously organizes replacement service within Switzerland, adds an extra stop to flex, and then apologizes for a one minute delay they will make up on the way. 🫡
The German mind cannot comprehend. Any of those four cute icons and I would have already given up on Deutsche Bahn.
mitmproxy 12 is out! 🚀 It’s now possible to modify the prettified representation of binary protocols. Editing Protobufs is now as easy as editing YAML, no .proto schema needed. 🙌
https://mitmproxy.org/posts/releases/mitmproxy-12/
mitmproxy 11.1.2 is out, everyone should upgrade! We fixed a rather nasty SSRF-style vulnerability affecting mitmweb (CVE-2025-23217). mitmproxy and mitmdump users are unaffected.
https://github.com/mitmproxy/mitmproxy/security/advisories/GHSA-wg33-5h85-7q5p

We now support *Local Capture Mode* on Windows, macOS, and - new - Linux! This allows users to intercept local applications even if they don't have proxy settings.
On Linux, this is done using eBPF and https://aya-rs.dev/, more details are at https://mitmproxy.org/posts/local-capture/linux/. Super proud of this team effort. 😃

Gaurav - my Google Summer of Code student - has all the details: https://mitmproxy.org/posts/releases/mitmproxy-11/. Awesome to have such a fantastic mitmproxy community. ☺️
mitmproxy 10.4 is out! 🚀 Lots of bugfixes, and a first preview of our new Capture Tab in mitmweb! Matteo Luppi is working on this as his Google Summer of Code project. Super excited for how this will look like at the end of the summer. 🤩
https://mitmproxy.org/posts/releases/mitmproxy-10.4/
Step 1: Roll your eyes at people using CDNs.
Step 2: Realize that you are one of them. 🫣
pdoc users who do `--math`, please upgrade to the latest release ASAP to fix a security vulnerability!
https://github.com/mitmproxy/pdoc/security/advisories/GHSA-5vgj-ggm4-fg62
Today's progress: Adding a note to https://github.com/sponsors/mhils that we won't put a sponsor's logo on mitmproxy.org if we feel that they don't align with our values. Apparently some not-so-great places have discovered it's great for SEO or something. Immensely grateful to be in a position that allows me to just say no.
Special day today: Celebrating my grandpa's 100th birthday! 🥳🎂🎈
ZRH ✈️ CPH, on my way to https://denmark2024.honeynet.org. Can't wait to see everyone again! 🤩
TFW when you open your dependency's GitHub repo and you see the last commit from four hours ago is fixing your exact issue. FOSS can't get much better than that. 🤩
Come work with us on mitmproxy this summer! 🚀 Google Summer of Code is a unique opportunity to get into open source with a nice stipend attached. We have Rust, Python, and TypeScript projects.
https://github.com/mitmproxy/mitmproxy/issues/6589
Writing highly-concurrent Go code feels like caveman programming when coming from Rust. You better not forget a lock somewhere. 😬