Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
bugmen0t
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
22 ms
·
181.
▲
by
bugmen0t
9y ago
It's unlikely to be abused by am attacker, if it requires starting Firefox with a certain environment variable. Chrome has the same thing with a command line switch. Useful for some internal unit/integration tests for release and
182.
▲
by
bugmen0t
9y ago
It is.
183.
▲
by
bugmen0t
9y ago
I know the American Dream story of somone small being big corporations is appealing, but s/Solopreneur/Team/.
184.
▲
by
bugmen0t
9y ago
I agree with Hanno here. There are great tools to make the CAs behave or at least make their mistakes being easily spotted: Name Constraints, DNS CAA records, Certificate Transparency and, if you must, HPKP and much more.
185.
▲
by
bugmen0t
9y ago
Funny that almost everyone in this threat seems to "get" Differential Privacy and thinks of it as a good tool. But when it was discussed for Mozilla Firefox everybody was appalled and enraged. (Thread at https://news.yc
186.
▲
by
bugmen0t
9y ago
That doesn't make it any less confusing in 2017
187.
▲
by
bugmen0t
9y ago
If you download a Mozilla build of Firefox into somewhere user-writable, like ~/opt/, it will update itself.
188.
▲
by
bugmen0t
9y ago
The linked paper to RAPPOR is really, really noteworthy here. In essence, Firefox will ask itself whether it visited website X and flip a coin and if it's heads, it will lie to the server and send a random boolean. If it's tail,
189.
▲
by
bugmen0t
9y ago
An upcoming Firefox release will get built-in U2F support, no need for an add-on. It already supports a softtoken (I.e., implemented in software) behind a pref. Works well for me on e.g., GitHub. But that's unlikely ever to be enabled
190.
▲
by
bugmen0t
9y ago
meet worked well for me the other day on Firefox Nightly (57)
191.
▲
by
bugmen0t
9y ago
But the flexibility did not come for free! Whenever they changed internal interfaces, they'd either have to create a clone, call it interface2 or break all extensions using them. That's for internal interfaces. The new model also
192.
▲
by
bugmen0t
9y ago
There are some noteworthy security problems with Flash in principle. If website.com embeds a flash file from flash.example, it will run in the context of flash.example, the embedee. If website.com embeds JavaScript from js.example, the cod
193.
▲
by
bugmen0t
9y ago
This is mostly against phishing. A phisher can get users to insert a token from a USB device or a text into evil.com. But U2F uses public key crypto, so your token derived for evil.com is not the same as for github.com
194.
▲
by
bugmen0t
9y ago
You don't really[1] need to install this, if you're using Firefox. Just set the prefs 'security.webauth.u2f' and 'security.webauth.u2f_enable_softtoken' to true. [1] (Unless you need the token to live in your M
195.
▲
by
bugmen0t
9y ago
> Mozilla effectively bans extensions they don't like since the made signed extensions mandatory. Not true. They sign very liberally and you can even host signed extensions for your own users exclusively without listing them on ad
196.
▲
by
bugmen0t
9y ago
yup. 30ish for a full compile, less with ccache and other tricks. Rebuilds 2-3 minutes.
197.
▲
by
bugmen0t
9y ago
The backstory here is that Thunderbird devs would like to be faster but have a hard time working against the Gecko changes that breaks their build. Sure Thunderbird kind-of works, as in it's "done", but people find Security
198.
▲
by
bugmen0t
10y ago
Yeah, it was discussed in the W3C WebAppSec group, but there are many unsolved challenges. This article sums it up really, really well: https://hillbrad.github.io/sri-addressable-caching/sri-addre...
199.
▲
by
bugmen0t
10y ago
Sure, there's retire.js at https://retirejs.github.io/retire.js/
200.
▲
by
bugmen0t
10y ago
websites can be made immutable: https://hacks.mozilla.org/2017/01/using-immutable-caching-to...
201.
▲
by
bugmen0t
10y ago
I, as someone who worked on the SRI spec find this incredibly disappointing as well. We've tried to reduce this to "must be publicly cachable", but attacks have proven us wrong. And unfortunately, there are too many hosts tha
202.
▲
by
bugmen0t
10y ago
Addendum To be completely honest: Only reach out if you have solutions for any of the problems or can reduce what you want down to something that is solvable with these problems in mind. If your solution does not live on the web , you'
203.
▲
by
bugmen0t
10y ago
Folks in W3C webappsec are interested, but the cross-origin security problems are hard. We'd love feedback from developers as to what is still useful without breaking the web. Read this doc and reach out! https://hillbrad.gi
204.
▲
by
bugmen0t
10y ago
Two notes: 2) There is interest and progress on securing web applications: - For early research papers look into 'Privilege Separation in HTML5 Applications' by Devdatta Akhawe et al. < https://www.usenix.org/sys
205.
▲
by
bugmen0t
10y ago
Most wifi hardware supports being both AP and client at the same time. This way, I've extended my wifi signal for just 20 bucks (Bought a netgear ex2700 and flashed openwrt. I made it join my existing wifi and create an AP with a disti
206.
▲
by
bugmen0t
10y ago
What you are looking for is called "remote attestation". (In open source software the solution to this problem is "well, you could always just host your own instance" ;))
207.
▲
by
bugmen0t
10y ago
Tracking like this does not work when you use Firefox with Containers :) See https://wiki.mozilla.org/Security/Contextual_Identity_Projec...
208.
▲
by
bugmen0t
10y ago
Btw, this web page has a nice overview of what security indicators look like on different web browsers: http://lock-museum.herokuapp.com/
209.
▲
by
bugmen0t
10y ago
I'd argue this is a good reason to browse from within a virtual machine :-)
210.
▲
by
bugmen0t
10y ago
TLDR: No.
More ›