Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
bugmen0t
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
15 ms
·
121.
▲
by
bugmen0t
7y ago
I'm skeptical about trusted types. It seems very heavy and needs 100% buy-in to work. Reminds me how CSP was seen as the glorious savior. But so far it only helps the big sites (Google, Facebook Twitter etc)
122.
▲
by
bugmen0t
7y ago
oops yes.
123.
▲
by
bugmen0t
7y ago
They just did a security update last week.
124.
▲
by
bugmen0t
7y ago
It's in page 18. If you have end-to-end encryption you can't sanitize in the client. I mean, you're really just summarizing the presentation. It should be an API that's in the browser. It isn't. So people need to us
125.
▲
by
bugmen0t
7y ago
The text on https://use-application-dns.net/ says that it will be attempted to become a standard through the IETF. But only time will tell.
126.
▲
by
bugmen0t
7y ago
This might be encrypted too in the future. https://tools.ietf.org/html/draft-ietf-tls-esni-04
127.
▲
by
bugmen0t
7y ago
That's an issue with the f-droid build config. Maybe worth filing a bug with them and asking to change it?
128.
▲
by
bugmen0t
7y ago
Maybe you want to opt out of Google activity tracking? When I go to that page it says "No Activity".
129.
▲
by
bugmen0t
7y ago
You likely want a separate domain indeed. See https://security.googleblog.com/2012/08/content-hosting-for-...
130.
▲
by
bugmen0t
8y ago
That's not entirely true. Remembering history is also different from remembering permissions. Firefox should persist those independently from actual URLs in browsing history. And there's a button in settings where you can disable
131.
▲
by
bugmen0t
8y ago
If you need less abstractions over protocols, you might look into [mio]( https://github.com/carllerche/mio ).
132.
▲
by
bugmen0t
8y ago
What I like about this list, is that it's opinionated and thus terse. Take note that some of these tips are either not considered good practice or even harmful depending on your locale. E.g., the data protection standards in the EU are
133.
▲
by
bugmen0t
8y ago
He still works on browsers, but blogs less. You can see his contributions on GitHub.
134.
▲
by
bugmen0t
8y ago
Of all people, the folks here on hacker news, are in the best situation to change that. Be vocal! Use your influence! And if you have the means: donate!
135.
▲
by
bugmen0t
8y ago
What's also amazing, is that if you sign up for a Firefox Account you get privacy preserving sync: The data is encrypted & decrypted on your devices. Mozilla doesn't get to see your data.
136.
▲
by
bugmen0t
8y ago
6) Even better: Built-in Tracking Protection can likely serve the same use case and gives you better performance, because jumping into JavaScript code and back for every request is costly (it's not a high cost, depending on hardware th
137.
▲
by
bugmen0t
8y ago
There are some regions in the world, where you're better off with a DoH server that Mozilla has leverage with (because of a business contract). Most notable, this doesn't hold true for Europe, where you do have a good contract w
138.
▲
by
bugmen0t
8y ago
If you're the admin, you can disable DoH through a group policy, no?
139.
▲
by
bugmen0t
8y ago
But this isn't about:config. This is in settings.
140.
▲
by
bugmen0t
8y ago
Nope. Mozilla blog says: > "Moving forward, we are working to build a larger ecosystem of trusted DoH providers, and we hope to be able to experiment with other providers soon." More in < https://blog.mozilla.org&#
141.
▲
by
bugmen0t
8y ago
https://github.com/carols10cents/rustlings
142.
▲
by
bugmen0t
8y ago
Rust+WebAssembly is excellent.
143.
▲
by
bugmen0t
8y ago
In Web Security: - The Tangled Web ( http://lcamtuf.coredump.cx/tangled/ ) You can look at the Web Application Hacker's Handbook or the Browser Hacker's Handbook, if you want. But TTW tops them all.
144.
▲
by
bugmen0t
8y ago
Not super reliably. But try this one: https://github.com/mozfreddyb/test-firstpartyisolation
145.
▲
by
bugmen0t
8y ago
This paper has all the gory details: https://www.researchgate.net/publication/315848178_Extending...
146.
▲
by
bugmen0t
8y ago
every SSO is different. But mine all worked.
147.
▲
by
bugmen0t
8y ago
TLDR: in my experience: very little.
148.
▲
by
bugmen0t
8y ago
They seem to be doing well, generally: < https://duckduckgo.com/traffic>
149.
▲
by
bugmen0t
8y ago
Firefox has a list of all "about:" pages at about:about
150.
▲
by
bugmen0t
8y ago
Reminds me of Firefox Container Tabs and other advanced ffeatures
More ›