Image

Dr.-Ing. Florian Hantke

Researcher, Hacker, Foodie, IT Security Consultant, CTF Player, Web Developer

© 2026 Florian Hantke

Built with Jekyll - Design based on HTML Codex

Loading...

Hi! I'm Florian 👋

I'm a Postdoc at Northeastern University SecLab, and a security consultant specializing on web (application) and network security. I earned my PhD (Dr.-Ing.) from Saarland University while conducting research at CISPA's Secure Web Application Group. During my journey, I did an internship at Brave, where I explored privacy improvements within the browser. Previously, I studied computer science at Friedrich-Alexander Universität Erlangen-Nürnberg in Germany and at Universidade Federal do Paraná in Brazil and worked as security consultant at SEC Consult. During my freetime, I enjoy practicing IT security in CTFs with FAUST and analyzing programs I personally use to help make the Web a safer place. It's for that reason, I actively advocate for better IT security laws.

Apart from hacking in front of my computer, I also love spending time climbing with my friends, cooking a delicious meal to relax, or taking some pictures. As a researcher, I am fortunate to travel frequently which gives me the chance to explore new cuisines and discover new meals and recipes to add to my collection 😊

Work Experience

Postdoctoral Researcher

Northeastern University, Boston | Since Aug. 2026

Building up on my web measurement research experience during my doctoral, I am currently employed by Engin Kirda working on web, network, and email security measurements.

Research Intern

Brave | May 2025-Aug. 2025

Together with Pete Snyder, I am working on and exploring improved privacy features directly within the browser.

Doctoral Researcher

CISPA Helmholtz Center for Information Security | Apr. 2022-Aug. 2026

During my doctoral, I worked in the group of Ben Stock. My research focused on responsible and reproducible web security measurements.

Security Consultant

Freelancer | Since Apr. 2022

As an IT security consultant, I assist companies in developing their security strategy to protect against cyber threats. I specialize in web application penetration testing.

Associate Security Consultant

SEC Consult Group | Oct. 2020–Mar. 2022

In my previous role as a security consultant at SEC Consult, I conducted a variety of penetration tests and security assessments for clients. My work helped to identify vulnerabilities and risks in their IT systems, allowing them to take appropriate measures to mitigate potential threats.

Research Assistant

Friedrich-Alexander-University of Erlangen-Nürnberg | May 2019–Sep. 2020

I was a research assistance at the FAU IT Security Infrastructures Lab and developed a programming interface to acquire and analyze forensic data in critical infrastructure using Volatility and the Sleuth Kit. I also did research on forensics options in UEFI with EDK II.

Working Student

Siemens | Feb. 2017–Feb. 2019

I was a working student at Siemens. Mostly I developed SQL reports and automated our main task - license clearing - with Python scripts and Java tools.

Education and Courses

Doctorate (summa cum laude)

Saarland University | Apr. 2022-Jun. 2026

Master

Friedrich-Alexander-Universität Erlangen-Nürnberg | Oct. 2018-Mar. 2022

Master (Exchange)

Universidade Federal do Paraná, Brazil | Aug. 2019-Dec. 2019

Bachelor

Friedrich-Alexander-Universität Erlangen-Nürnberg | Oct. 2014-Mar. 2018

eWPT

eLearn Security

Professional Service

Program Committee
  • 36th USENIX Security Symposium (USENIX'27) 2026/27
  • European Symposium on Security and Privacy (EuroS&P'26) 2026
  • Mensch und Computer Short Paper AC (MuC'26) 2026
  • 20th USENIX WOOT Conference on Offensive Technologies (WOOT'26) 2026
  • 19th USENIX WOOT Conference on Offensive Technologies (WOOT'25) 2025
Journal Reviewer
  • ACM Transactions on Privacy and Security 2024 2024
Poster Committee
  • European Symposium on Security and Privacy (EuroS&P'26) 2026
  • European Symposium on Security and Privacy (EuroS&P'25) 2025
Artifact Evaluation Committee
  • 33th USENIX Security Symposium (USENIX'24) 2024
Ethics Committee
  • Saarland University Since Oct. 2025

Academic Publications

You can also find all publications on Google Scholar.

Reflection, Education, Consistency: Towards Best Ethics Practices At Security And Privacy Conferences

Florian Hantke, Rafael Mrowczynski, Ben Stock

Conference on Computer and Communications Security (CCS'26)

Read more...
VDPCollect: Vulnerability Disclosure Programs as a Complement to Web Security Measurements

Philip Decker, Florian Hantke

Asia Conference on Computer and Communications Security (AsiaCCS'26)

Read more...
LEAKYLINKS: Measuring the Security and Privacy Risks of URL Scanning Services

Ali Mustafa, Jannis Rautenstrauch, Florian Hantke, Shubham Agarwal, Stefano Calzavara, Ben Stock

Symposium on Security and Privacy 2026 (S&P'26)

Read more...
Web Execution Bundles: Reproducible, Accurate, and Archivable Web Measurements

Florian Hantke, Peter Snyder, Hamed Haddadi, Ben Stock

USENIX Security Symposium (Usenix'25)

Read more...
Where Are the Red Lines? Towards Ethical Server-Side Scans in Security and Privacy Research

Florian Hantke, Sebastian Roth, Rafael Mrowczynski, Christine Utz, Ben Stock

Symposium on Security and Privacy 2024 (S&P'24)

Read more...
You Call This Archaeology? Evaluating Web Archives for Reproducible Web Security Measurements

Florian Hantke, Stefano Calzavara, Moritz Wilhelm, Alvise Rabitti, Ben Stock

Conference on Computer and Communications Security (CCS'23)

Read more...
HTML violations and where to find them: a longitudinal analysis of specification violations in HTML

Florian Hantke, Ben Stock

Internet Measurement Conference (IMC'22)

Read more...
How can data from fitness trackers be obtained and analyzed with a forensic approach?

Florian Hantke, Andreas Dewald

Wacco, European Symposium on Security and Privacy (EuroS&PW'20)

Read more...

Public Appearances

A selection of talks and media appearances.

📰 Cowboys und Computer

.inf 14 | Das Informatik-Magazin

Check it out.
🎙️ Datensicherheit - Hackerangriffe bedrohen Kita-Betreiber

Deutschlandfunk

Check it out.
📰 Sicherheitsleck bei KigaRoo - Über zwei Millionen Kita-Daten im Netz

Netzpolitik.org

Check it out.
🎥 Was lange währt, wird endlich gut? Die Modernisierung des Computerstrafrechts

38C3

Check it out.
🎥 „Well, What Would You Say if I Said That You Could?” - Scanning for Vulnerabilities Without Getting Into Trouble

German OWASP Day 2024

Check it out.
🎙️ Server-Side-Scanning mit Florian Hantke

TL;DR

Check it out.
🎙️ Pen tester, vulnerability researcher, cybersecurity doctoral candidate

Cybersecurity Advisors Network

Check it out.

Blog Posts

A selection of published blog posts. You can also find all my posts on Medium.

Till Breach Do Us Part
The Uninvited Guest at Your Wedding

Picture this, you’ve just had the perfect wedding. The vows were spoken, the dance floor was packed, but something was wrong...

Cliche Writeup — ångstromCTF 2022
Mutation XSS in DOMPurify and marked

Last weekend, I played the ångstromCTF 2022 with my team FAUST. During the CTF, I came across a relatively simple constructed but clever web challenge that I want to...

Hacking the University in a Few Steps
Escalating a Wrong Date to Get Code Execution

A couple of weeks ago, I was about to continue my application to my University. This is the story of how a wrong date has led to RCE on a university server.

Intigriti — XSS Challenge 0621
XSS via WebAssembly

The Challenge While scrolling through my Twitter feed, I saw a new post from Intigriti — a fresh XSS Challenge. Since I had some free time, I decided to give it a try. In the following...

Intigriti — XSS Challenge 0321
XSS with CSRF Bypass

It was March and Intigriti published a new XSS challenge. Since good XSS challenges are always a way to learn new interesting methods, I gave it a try. XSS The challenge website...

Reversing and analyzing the cooking app KptnCook
My Recipe Collection

I like cooking, it is somewhat relaxing to take some time off and create a delicious meal. So a friend recommended to me an app called KptnCook...

How photovoltaic system data ends up online
Another IoT Story

My parents bought a photovoltaic system developed to produce and use their own energy. Of course, as with every IoT-device nowadays, one may use an App to monitor the produced data. However, ...

Teaching

A selection of recent teaching roles.

Software Vulnerabilities and Security (SoftVulnSec)
  • Co-Lecturer Northeastern University 2026
Foundations of Web Security
  • Teaching Assistant Saarland University 2026
  • Teaching Assistant Saarland University 2025
  • Teaching Assistant Saarland University 2024
Web Application Security
  • Co-Lecturer Telekom Cyber Security Professional Training 2026
  • Teaching Assistant Telekom Cyber Security Professional Training 2025
  • Teaching Assistant Telekom Cyber Security Professional Training 2024
The Web Security Seminar
  • Advisor Saarland University 2024
  • Advisor Saarland University 2023
  • Advisor Saarland University 2022

Supervised Students

A list of theses I have supervised. If you are interested in a web security or hacking-related topic, feel free to get in touch. As a first step, you will be asked to prepare a short thesis proposal.

Niklas Beierl

Master's thesis 2026

A Qualitative Look Into Ethics Boards' Assessments of Security and Privacy Research

Philip Decker

Master's thesis 2025

Bug Bounty - A Sweet Treat for Web Security Research

Moritz Lübken

Master's thesis 2024

Designing a competition to observe hackers' strategies

Philip Decker

Bachelor's thesis 2023

Bug-Bounty Metamorphose - A Study on the Development Of Programs and Providers

Moritz Wilhelm

Master's thesis 2023

A Song of Trust and Archives: Assessing the Dependability of Web Archives for Reproducible Web Security Measurements

© 2026 Florian Hantke

Built with Jekyll - Design based on HTML Codex