Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
briansmith
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
14 ms
·
91.
▲
by
briansmith
13y ago
I don't know the exact plan since I'm not working on this, but it would be relatively easy for us to do: 1. Insist that the exact build configurations used by Cisco be open-sourced along with the rest of the code. 2. Require that
92.
▲
by
briansmith
13y ago
AFAICT, we (Mozilla) are trying to solve TWO problems: 1. We need a video codec that everybody agrees on for WebRTC. 2. We need a way to play H.264 on Windows XP and other operating systems that don't provide native H.264 playback, for
93.
▲
by
briansmith
13y ago
Interesting. Normally we allow users to override "expired." Was the OCSP server returned "unknown" for the old cert after it expired? One way to check this would be to uncheck the first check box in that dialog box (&quo
94.
▲
by
briansmith
13y ago
Firefox treats an explicit "unknown" OCSP status as equivalent to being revoked, except we don't cache the "unknown" status. Firefox doesn't allow the user to override "revoked." The thinking behind o
95.
▲
by
briansmith
14y ago
First, there are already multiple Firefox extensions that will let you totally control the Referer header. (In general, if there's something that you want to change about Firefox, you should search https://addons.mozilla.org to find a sol
96.
▲
by
briansmith
14y ago
> Nobody expects to have their privacy maliciously and constantly invaded. This is emphatically WRONG behavior. Nobody is disagreeing with either of those two statements. Like I said, DNT isn't Mozilla's final or only answer to the trac
97.
▲
by
briansmith
14y ago
That is a very good question/suggestion. It is a good idea to make the option easier to find. I definitely think it is important to educate more people about the issue. There may some validity to the idea that "the journey is part of the gi
98.
▲
by
briansmith
14y ago
> Or the risk of offending the biggest source of funding? I (a Mozilla employee) can understand why people worry about this, because there does seem to be a conflict of interest here. But, I've never seen anything to indicate that we
99.
▲
by
briansmith
14y ago
Any kind of DOM storage (cookies, localStorage, IndexedDB, etc.) is ephemeral. The browser needs to decide the maximum amount of disk space that it wants to consume, and then when it hits that limit, it needs to start throwing away (garbage
100.
▲
by
briansmith
14y ago
Actually, you'd only need to buy one TLD! Or, you could buy one regular domain and then ask to be put on the public suffix list. I'm guessing that would have the same effect for less money.
101.
▲
by
briansmith
14y ago
I bet it would still work in Firefox but it would be more expensive, because you'd need to purchase a lot of top-level domains to pull it off.
102.
▲
by
briansmith
14y ago
This is some advice from "The Elements of Typographic Style" that is often better to ignore on the web. Vertical rhythm is mostly unimportant EXCEPT when you have text printed back-to-back on paper (you must ensure every line of text aligns
103.
▲
by
briansmith
14y ago
The way pnathan described his app, systemXHR doesn't seem to make sense for it. You usually only need systemXHR when you are writing an app that talks to a third-party server that you cannot control and that you cannot convince to enable CO
104.
▲
by
briansmith
14y ago
You may have TLS 1.0 disabled (Tools > Options > Advanced > Encryption > TLS 1.0). Make sure both of those checkboxes (SSL 3.0 and TLS 1.0) are checked.
105.
▲
by
briansmith
14y ago
IIRC, that is exactly Netflix's interest in the API. Google for the "Netflix use case."
106.
▲
by
briansmith
14y ago
> One thing I would probably do as Archduke, after ordering a 70% tax on cupcakes, is have the bindings only work on HTTPS connections. I am very interested in this idea, not only regarding this API, but also regarding camera/microphone
107.
▲
by
briansmith
14y ago
Please see my other responses in this thread. I recommend people to write up proposals for such APIs and submit them to the W3C working group. It should be simple to specify them because you should literally be able to specify them directly
108.
▲
by
briansmith
14y ago
> Can I ask what the point of enabling websites to create vulnerable cryptosystems is? You yourself noted that Javascript, not this API, is the enabler of vulnerable cryptosystems in web apps. Also, sometimes you want to implement a vul
109.
▲
by
briansmith
14y ago
> The fact that an MITM or XSS can completely undermine this MITM and XSS are problems with many Web APIs. There are already countermeasures for MITM (e.g. TLS) and XSS (e.g. CSP). They are too difficult to use, and we need to make them
110.
▲
by
briansmith
14y ago
I believe you are suggesting that we make a more foolproof API like keyczar. The original idea of DOMCrypt was along those lines as well. I don't think we will be able to avoid specifying and shipping the low-level API at this point. It wou
111.
▲
by
briansmith
15y ago
We've landed an implementation of a draft of the SPDY spec, and that will be available in Firefox Nightly builds [1] tomorrow (or so). In order to test it out, you must change change the network.http.spdy.enabled preference to true in about
112.
▲
by
briansmith
15y ago
The padding for AES cipher suites isn't a significant performance issue. The per-record IV in TLS 1.1 and later, the overhead of the tls-cbc.txt workaround for earlier versions, and/or the extra block(s) of encryption required for HMAC-SHA
113.
▲
by
briansmith
15y ago
This used to be true, but it isn't true any more on modern web browsers. In particular, Firefox improved its caching policies for HTTPS in version 4.
114.
▲
by
briansmith
15y ago
> I don't want Microsoft to win the living room and so won't be supporting them either. I guess unless Wii2 has beautiful graphics we'll be an exclusive PC gaming house. On which PC operating system?
115.
▲
by
briansmith
16y ago
Firefox 4 betas have been shipping with STS support since June. See http://hg.mozilla.org/mozilla-central/rev/5dc3c2d2dd4f
116.
▲
by
briansmith
16y ago
If this caching allows a website to switch from using HTTP to HTTPS within its budget, then I think the net effect is very positive. We can't have bad website administrators/developers holding back real security improvements with their inco
117.
▲
by
briansmith
16y ago
If you don't want your HTTP requests to be cached and/or stored, then you really must use the appropriate Cache-Control directives. IIRC, most browsers have cached HTTPS resources in memory (if not on disk) for a long time, so these kinds o
118.
▲
by
briansmith
16y ago
They are different resources so they are cached separately. There is no standard that says that a cached response for https://foo.org/x can be used for a request to http://foo.org/x .
119.
▲
by
briansmith
16y ago
Firefox 3.x caches (to disk) HTTPS responses with Cache-Control: public. Firefox 4 caches HTTPS responses basically the same way it caches non-TLS HTTP responses. Apparently, IE and Chrome are also doing this more aggressive caching. (I wor
120.
▲
by
briansmith
16y ago
Firefox already has SEED for TLS in the crypto library we use (NSS). AFAICT, the problem now is mostly getting bank websites to change. I believe some Korean banks have indicated that they will start supporting the standard mechanism in add
More ›