Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
coderobe
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
coderobe
6y ago
Easy, just dox yourself first.
2.
▲
by
coderobe
6y ago
The main creator of this has been posting about his progress for months, personally I've been following its development ever since I first saw it. It's such a neat project that I can totally believe this being entirely organic gro
3.
▲
by
coderobe
6y ago
If the "Get Started" button - the first thing you see on the website without scrolling - does nothing but yield a white page that asks for an email address, you're alienating a lot of interested users.
4.
▲
by
coderobe
6y ago
Attempted unjustified use of donation funds is not really any less questionable just because it didn't get past the treasurer - especially if the treasurer is, uh, constructively dismissed right after. Holding off on the purchase after
5.
▲
by
coderobe
7y ago
>- Security: Can you read my customers' traffic? Yes, anything that (re)terminates TLS will be able to - including this - and there is no way around it short of hosting it on-prem. Marketing it as end-to-end security the way the aut
6.
▲
by
coderobe
7y ago
>As long as the origin has SSL, the communication is secure end-to-end. It cannot be secure end-to-end, as your edge location is quite literally performing a MITM. That aside: How are you validating the TLS cert that the origin present
7.
▲
by
coderobe
7y ago
>SSL is terminated at an edge location that is closest to the users. So this is routing plain text http for most of the connection and at the same time giving the managed edge location direct access to the traffic and a valid tls cer
8.
▲
by
coderobe
7y ago
Been using AndOTP for months and i love that it supports android's keystore and device credentials for authentication. I had switched to it from Authy, which was quite heavy. Aegis' design looks a lot less dense than AndOTP on the
9.
▲
by
coderobe
8y ago
it's a nice quality of life improvement unless you're running low on space. 7+ gb is a lot , especially on embedded devices with low soldered storage - like microsoft's own products! coincidentally instead of offering upgrad
10.
▲
by
coderobe
8y ago
Yes. <body bgcolor=0>
11.
▲
by
coderobe
8y ago
>And besides: If Sinatra starts a server listening for incoming traffic, why does it still seem common to run a regular webserver like nginx in front of that server? This is a common technique used for tls-termination and management of &
12.
▲
by
coderobe
8y ago
a little tape on the camera would do just as well, wouldn't it?
13.
▲
by
coderobe
8y ago
un-AMPed url: https://www.theguardian.com/commentisfree/2015/sep/28/boredo...
14.
▲
by
coderobe
8y ago
How so? If google wanted to save bandwidth, they would simply up the cache time of their page(s), baking some version into the browser only saves the very first load. Doesn't seem like a decent strategy to face potential backlash for b
15.
▲
by
coderobe
8y ago
On a more serious note, > alias www='python -m SimpleHTTPServer 8000' that'll only work on systems where python is python2 > alias speed='speedtest-cli --server 2406 --simple' speedtest-cli automatically selec
16.
▲
by
coderobe
8y ago
This article covers gems like `alias c='clear'` - very handy! scnr
17.
▲
by
coderobe
9y ago
I'm sorry but how is this native ? It's an electron app...
18.
▲
by
coderobe
9y ago
Up in Germany
19.
▲
by
coderobe
9y ago
They ask google to: 'Confirm, with appropriate supporting data, that their bid requests made with QUIC are not anti-competitive, and justify why bid requests are being used by a new and opaque request protocol under conditions where co
20.
▲
by
coderobe
9y ago
I don't think the people that wrote this know how QUIC works and what its benefits are. The problem is not QUIC, it's the request API the adblockers use to filter the content. QUIC is a fast, documented protocol used by way more p
21.
▲
by
coderobe
10y ago
I'm using a Hackintoshed Lenovo Y50-70 (FHD model) running MacOS Sierra and i can only recommend it so far, all of the configurations that are being sold are very compatible with macOS. It even comes with a dedicated GPU which is great
22.
▲
by
coderobe
10y ago
The license is still valid on the latest build BTW.
23.
▲
by
coderobe
10y ago
There should be no A-labels on bare gTLDs, so " https://google" should never make sense (per SSAC053 report - https://www.icann.org/groups/ssac/documents )
24.
▲
by
coderobe
10y ago
the period has to be there because it breaks spec btw
25.
▲
by
coderobe
10y ago
To whoever edited my title: The bug report title is inaccurate. It's specifically about HSTS preloads, which is why my original title stated that instead of "gTLDs".
26.
▲
by
coderobe
10y ago
It would probably work, but it would break spec.
27.
▲
by
coderobe
10y ago
This causes funny behavior like https://pbs.twimg.com/media/C6L3IvsUsAABuyS.jpg:large Chrom(e|ium) will suggest to navigate to http://google if you're opening google.com
28.
▲
HSTS Preload lists cause Chromium to think http://google/ is a valid domain
(bugs.chromium.org)
69 points
by
coderobe
10y ago
|
48 comments
29.
▲
by
coderobe
10y ago
Not necessarily just a field trial. AFAIK it was bundled with a recent ChromeOS update, causing logon to fail when MITM'd
30.
▲
by
coderobe
10y ago
Client and Server exchange a list of capabilities at the beginning of a TLS connection, if the proxy just filters out the protocols/versions it doesn't understand, server/client will agree on a different version (like 1.2).
More ›