Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
HerraBRE
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
Duppy: A RFC2136 dynamic DNS update server
(github.com)
1 points
by
HerraBRE
3y ago
|
0 comments
2.
▲
by
HerraBRE
6y ago
This is neat! DoH/DoT over Tor will provide stronger security and privacy guarantees across the board, but a well run .odns (anycast, good caches) could probably provide better performance. The .odns anonymity is strictly weaker than D
3.
▲
by
HerraBRE
7y ago
To expand on this slightly, and illustrate: I'm going to go out on a limb, and assert that THE most common attack performed against peoples' e-mail, is a jealous person who knows their partner's password logging on to their e
4.
▲
by
HerraBRE
7y ago
I wrote [most of] Mailpile. I'll check back here now and then and try to answer any questions folks have.
5.
▲
by
HerraBRE
7y ago
That's an interesting idea. I'd hesitate to implement it though, because of secondary risks. It would need to be thought through very carefully, and there are a whole bunch of abuse scenarios that would need to be avoided or mitig
6.
▲
by
HerraBRE
7y ago
Unless your adversary has a time machine, deleting from the server protects your past e-mails from any server-side compromise. That's not nothing. :-) But you're right there are trade-offs. If you don't have good backups, you
7.
▲
by
HerraBRE
9y ago
This is still a muddled view of things. In pay-for-click, advertisers are paying for advertising which is effective. The click is how that is measured. There are other ways to measure effectiveness, but measuring clicks is simple and reliab
8.
▲
by
HerraBRE
9y ago
Why do you say it was censored and removed? It's dropped down to page two, but that's perfectly normal once something has been on the front page for a while.
9.
▲
by
HerraBRE
9y ago
Neither of us knows this, so we may as well stop arguing about it. What we do know, is that running the servers and hiring all those engineers costs money, and their revenue is almost entirely ads. I don't think it's a stretch to
10.
▲
by
HerraBRE
9y ago
That is not how Google's business works. Advertisers quite literally pay for clicks. That was part of how Google disrupted the market back in the day; most other advertising networks were selling "impressions", but Google was
11.
▲
by
HerraBRE
9y ago
It's still a means to an end. You don't pay with your data, you "pay" by interacting with ads. Consider that Google actually became super profitable well before all the detailed tracking started. You grossly underestimat
12.
▲
by
HerraBRE
9y ago
I actually feel it's misleading and wrong at a very fundamental level; this was the only thing I disagreed with in the whole press release! Consumers "pay" for Google's services by giving ads attention so the ads have va
13.
▲
by
HerraBRE
9y ago
This is a legitimate concern. I would not put it past Facebook (or other businesses which are addicted to harvesting user data) to behave badly against networks like this. However, for the sake of their reputations they'd still probabl
14.
▲
by
HerraBRE
9y ago
If the social contract says "delete things when you see a delete message", then that's useful in a federated environment. Only bad actors will disobey and they will have to modify their software in order to do so. This doesn&
15.
▲
by
HerraBRE
9y ago
People keep saying that. Lots and lots of species will go extinct before we do. And it will be our fault . Sure, the hunk of rock we call a planet will go on, and life will go on, but claiming we are the only casualty here is profoundly wr
16.
▲
by
HerraBRE
10y ago
Mostly it meant SREs tended to be older than other engineers at Google (I was an SRE there for a while), I think by an average of nearly a decade. Broad experience, depth on a few topics. It's not impossible at all, it just takes time.
17.
▲
by
HerraBRE
10y ago
It's not mentioned in the article, but there is an underlying point that affects hiring for roles like this: you need people who can and will admit they don't know everything and will ask for help rather than wing it. "Rock
18.
▲
by
HerraBRE
10y ago
This attitude is harmful. Although new and better protocols is a worthy area of research and development, we should also improve the tools people are already using. Note I said research: I do not consider the current crop of secure messagin
19.
▲
by
HerraBRE
10y ago
Mailvelope is a much better choice if your goal is to interact with the existing OpenPGP ecosystem; E2E was using ECC keys only if I recall, which makes their crypto incompatible with many other OpenPGP setups. The E2E promise was that with
20.
▲
by
HerraBRE
10y ago
Thank you for injecting some optimism. :-) I'm disappointed and cynical about this.
21.
▲
by
HerraBRE
10y ago
If this is all that has happened since August, well, the commit speaks for itself: https://github.com/e2email-org/e2email/commit/434f99c66efe49... Hopefully there's more to come! :-P
22.
▲
by
HerraBRE
10y ago
It looks like Google just pulled the plug on this: https://security.googleblog.com/2017/02/e2email-research-pro... HN submission: https://news.ycombinator.com/item?id=13728327 (Genuinely hoping so
23.
▲
by
HerraBRE
10y ago
This appears to be a weak attempt to spin as positive the news that Google have abandoned the end-to-end project... mysteriously posted when everyone is busy processing the SHA1 and Cloudbleed news. From the post: E2EMail is not a Google p
24.
▲
by
HerraBRE
10y ago
Thank you for sharing your experience, it's enlightening. I'm glad you're in a better place now.
25.
▲
by
HerraBRE
10y ago
The parent comment may seem a bit flippant, but the underlying question is a good one - why do talented, non-toxic people seek employment with companies that are well known to have such terrible culture? I'm not in the Valley, so all t
26.
▲
by
HerraBRE
10y ago
Thanks for the shout out. We're not ready for public consumption yet though, still working on it. We always need more developers and "skilled" testers though!
27.
▲
by
HerraBRE
10y ago
Something you didn't mention, which I suspect is a major factor in why promoting FOSS alternatives proves surprisingly difficult in education. I remember when I was in university students were acutely aware that tools like PhotoShop, M
28.
▲
by
HerraBRE
10y ago
Consider that without privacy, people fighting for civil rights may be unable to safely coordinate and organize themselves well enough to make progress.
29.
▲
by
HerraBRE
10y ago
I think it was actually a nice nod to all the folks who haven't got that much experience, and maybe felt silly for not understanding the code snippet. :)
30.
▲
by
HerraBRE
10y ago
I didn't give examples, because it's not my field and because I wasn't interested in the inevitable quibbling about minor details. But I do know people that do that sort of work, and I also know that when I went looking for a
More ›