Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
bugmen0t
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
18 ms
·
211.
▲
by
bugmen0t
11y ago
The author is missing the point of the Tor Browser. They don't try to make fingerprinting impossible. They want to make the outcome uniform across all users. See "Strategies for Defense: Randomization versus Uniformity" in th
212.
▲
by
bugmen0t
11y ago
https://github.com/Kinto/kinto.js/
213.
▲
by
bugmen0t
11y ago
Mozilla allows almost every job to be remote and Firefox is written in C/C++. I'm sure there must be other companies :)
214.
▲
by
bugmen0t
11y ago
The browser must not know the content (or the hash of the content) of files on your intranet (or any other domain that is not the one you are visiting right now.) See https://annevankesteren.nl/2015/02/same-origi
215.
▲
by
bugmen0t
11y ago
https://github.com/w3c/webappsec/issues/477
216.
▲
by
bugmen0t
11y ago
"On a failed integrity check, an error event is thrown. Developers wishing to provide a canonical fallback resource (e.g., a resource not served from a CDN, perhaps from a secondary, trusted, but slower source) can catch this error eve
217.
▲
by
bugmen0t
11y ago
0. evil.com hosts evil.js, <script src=evil.js integrity=foo>. 1. you visit evil.com and the browser stores evil.js with the cache key "foo". 2. you visit victim.com which has an XSS vulnerability, but victim.com thinks it i
218.
▲
by
bugmen0t
11y ago
For static resources, it's nothing more than sending this HTTP header "Acess-Control-Allow-Origins: *". We reached out to jQuery and code.jquery.com does this for a few months now.
219.
▲
by
bugmen0t
11y ago
We've been toying with this idea in earlier revisions of the spec, basically using the hash as a cache key and not loading the same file from websiteB if it has already been loaded form websiteA. Unfortunately, this could be used as a
220.
▲
by
bugmen0t
11y ago
spec co-editor here. SRI returns false (i.e. non-matching integrity) for scripts (or stylesheets) that do not enable CORS and are not same-origin [1]. Otherwise, an attacker could just disable CORS to bypass SRI. flies away [1] https:&#x
221.
▲
by
bugmen0t
11y ago
The bug impact description is completely false. Mozilla has "corporate confidential" bugs behind the @mozilla.com email check, but everything with a security rating is restricted to specific accounts that have been explicitly vouc
222.
▲
by
bugmen0t
11y ago
You must be looking for the Underhanded Crypto Contest: The Underhanded Crypto Contest is a competition to write or modify crypto code that appears to be secure, but actually does something evil. See https://underhandedcrypto.com
223.
▲
by
bugmen0t
12y ago
There are so much more emojis just in this block, I think it could be squeezed down to at least half as many.
224.
▲
by
bugmen0t
12y ago
> (N.B.: This is mostly exploratory work and as such doesn't really try to be cross browser - your best bet is a recent Chrome or Chromium, but some clocks work in recent Firefox or Safari.) works well in Firefox.
225.
▲
by
bugmen0t
12y ago
it has its problems here and there, but 2.0 on the Flame is really nice!
226.
▲
by
bugmen0t
12y ago
Are these codes in any particular order?
227.
▲
by
bugmen0t
12y ago
Attesting software (i.e. JavaScript, even from third parties) might be possible if https://w3c.github.io/webappsec/specs/subresourceintegrity/ gains traction.
228.
▲
by
bugmen0t
13y ago
You can have closed-source or you can have secure. This is the former.
229.
▲
by
bugmen0t
13y ago
two comments from a German: 1) Most of this applies to Bavaria, not to the rest of Germany. The US isn't just Texas, you know ;) 2) All - I repeat - ALL generalizations are wrong :-)
230.
▲
by
bugmen0t
13y ago
</conspiracy> This one explains the issue quite well: http://www.reddit.com/r/RTLSDR/comments/1le3if/so_i_discover... Learn your electronics and don't believe in rumors ;)
231.
▲
by
bugmen0t
13y ago
There's a pluggable no-login audio-version of this already present today: Mozilla's TowTruck: https://towtruck.mozillalabs.com/