Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Shoothe
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
91.
▲
by
Shoothe
9y ago
I know what the signatures are for but I wonder if there's a simpler way to achieve these objectives. Server authentication: For example XMPP uses client certificates to authenticate servers to other servers (TLS server certificates us
92.
▲
by
Shoothe
9y ago
This pattern was also used by Java and .NET for implementing cheap String.substring calls where all substrings would use the same underlying array with just offsets changed. Unfortunately it turns out that people read entire files into a on
93.
▲
by
Shoothe
9y ago
ActivityPub is like JWT. Simple on the outside but complex inside. For example I wanted to implement a simple server to connect to Mastodon. JSON via HTTP, what could be simpler? Actually it's JSON-LD not JSON. But it doesn't matt
94.
▲
by
Shoothe
9y ago
Mind that there are even more gems hidden inside .NET e.g. modopt/modreq or Constrained Execution Regions.
95.
▲
by
Shoothe
9y ago
Good point. Although I think the design was chosen because of the complexity of infrastructure behind your TLS server. Adding more things for the client to do so that you don't need to trust any intermediaries inside AWS data centers.
96.
▲
by
Shoothe
9y ago
Hmm... But you'll still use TLS for transport so adding mutual auth doesn't really increase the attack surface that much. (it still requires ugly ASN.1 and X.509). Or maybe you suggest using signed requests without TLS (plain HTTP
97.
▲
by
Shoothe
9y ago
Request signing can be easily implemented in JavaScript for API requests with WebCrypto but it's not clear to me in what threat model it would be beneficial because even if they keys are not exportable users don't generally see wh
98.
▲
by
Shoothe
9y ago
Because for Google it's not enough that you have a certificate if your client is using an old unpatched OS and is potentially vulnerable.
99.
▲
by
Shoothe
9y ago
I'm mostly interested in whether it's only signaling that's E2E encrypted or audio/video peer to peer streams between the browsers.
100.
▲
by
Shoothe
9y ago
I haven't checked the source code but generally calls between runtime boundaries are costly (JS to WebAssembly) so it's critical to do all the work in WebAssembly and just return a complete solution at the end.
101.
▲
by
Shoothe
9y ago
It says the calls are end to end encrypted but I thought WebRTC do not have E2E encryption. I would gladly see some technical details there.
102.
▲
by
Shoothe
9y ago
Excellent article and something to really think about.
103.
▲
by
Shoothe
9y ago
Will they automatically double memory on existing droplets or do we need to recreate them from scratch?
104.
▲
by
Shoothe
9y ago
For 15$ at my operator I've got two numbers sharing the same unlimited text, unlimited sms/MMS plan with 30 GB of data. Actually it's 15$ max, if I use less I pay less. The "contract" that I have can be withdrawn wi
105.
▲
by
Shoothe
9y ago
I wouldn't be so sure. I've got a simple email to http service running on AWS and while I'm sending no more than 50 emails to this service I still get billed cents. If I was thinking about running something like this in produ
106.
▲
by
Shoothe
9y ago
OpenPGP is kind of like git - if you understand the underlying concepts (in case of OpenPGP this is RFC 4880) then it is simple. GPG is very old and created in different times so it has many quirks at the implementation and UI level but I f
107.
▲
by
Shoothe
9y ago
WebRTC is inherently peer to peer (except the initial phase of signaling) so it (audio streams) can't be any other way. Conferences in WebRTC are just multiple peer to peer connections.
108.
▲
by
Shoothe
9y ago
OpenPGP applet on Yubikeys also have physical presence proof option: https://developers.yubico.com/PGP/Card_edit.html#_yubikey_4_... . Crucial for safe ForwardAgent!
109.
▲
by
Shoothe
9y ago
That's my experience too (using gpg for ssh). While I remember that gpg agent can die once in a while it's very rare and the benefit of having keys in a separate device and using them on any machine instantaneously is certainly wo
110.
▲
by
Shoothe
9y ago
Firefox supports the FIDO U2F spec to the letter while Chrome requires legacy polyfill script that doesn't use the same exact API. So it's possible to support both but it's not as straightforward as it should be.
111.
▲
by
Shoothe
9y ago
> Now I have one, but how do I handle the loss of one or more keys The same way you handle loss of keys to your home, car, etc. - you buy a second pair. If you're using OpenPGP you can provision them with keys any time so it's
112.
▲
by
Shoothe
9y ago
The blog post you linked to is using the PIV applet on Yubikey. You can do touch based OpenPGP operations on Yubikey too: https://developers.yubico.com/PGP/Card_edit.html#_yubikey_4_...
113.
▲
by
Shoothe
9y ago
That they generate certificates with my name was such a bewildering move (I knew as I monitor CT logs). I had to contact support for them to stop as they admitted there was no UI for that. > Not a huge fan of the CAA UI. I would prefer t
114.
▲
by
Shoothe
9y ago
Thanks for mentioning the page. I'm about to write a simple JSON/HTTP service and decided to use Rust but I was wondering why the author would not use Rust for web services.
115.
▲
by
Shoothe
9y ago
It's interesting because when I read about how Rust can rewrite iterators code into more performant direct loops I thought about Joe's blog posts that mentioned the same efforts for .NET. Also Span<T>. It seems .NET will hav
116.
▲
by
Shoothe
9y ago
Could you clarify which blockchain you are talking about? In Bitcoin nothing is encrypted and keys are used only to sign transactions.
117.
▲
by
Shoothe
9y ago
Last time I checked Cloudflare had incomplete support for CAA (no issuewild or flags). OHV also mentioned they are working on it but that was half a year ago and so nothing.
118.
▲
by
Shoothe
9y ago
You can add OMEMO (XMPP) to the list: https://conversations.im/omemo/
119.
▲
by
Shoothe
9y ago
There is a decentralized review system based on Git. Take a look here: https://github.com/google/git-appraise ...oh, wait...
120.
▲
by
Shoothe
9y ago
Keep in mind that Pidgin supporting many protocols means "lowest common denominator" in several cases. For OMEMO E2E I'd recommend Gajim or (still in alpha but promising) dino.im
More ›