Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
crunchatized
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
crunchatized
8y ago
In the more expensive devices, are the arbitrary new private keys imported from the computer it's plugged into? If the new keys are generated on the hardware you don't trust, it'd still be the same problem, since the private
32.
▲
by
crunchatized
8y ago
Like GP said, that would give away which accounts have WebAuthn enabled on them, since those without it would send you straight to the password prompt instead. But more importantly, phishing sites will always tell you 'your key succeed
33.
▲
by
crunchatized
8y ago
Solely going by GP's summary, nothing needs to be 'registered with the hardware' because the public/private keypair is deterministically generated on-the-fly, cheaply, with a PRNG every time it's needed. Only two th
34.
▲
by
crunchatized
8y ago
Looking it up, I think the more accurate term is actually "partner repacks." [1] They're versions of Firefox shipped with different default settings and/or an extension included by default at install time, IIUC. Though r
35.
▲
by
crunchatized
8y ago
Well, an advertising company doesn't care about protecting your privacy from themselves as the threat. But protecting you from rival data-miners like unscrupulous ISPs could actually help their business model, if you want to look at
36.
▲
by
crunchatized
8y ago
Well, Mozilla engineers wouldn't be the ones in charge of, or benefiting from, shutting down the Tor Browser fork, would they? So why would they need to include that kind of (incredibly distant, virtually pie in the sky) goal on their
37.
▲
by
crunchatized
8y ago
Chrome extensions [1], and Firefox WebExtensions [2], can have background scripts that can continue running even when the browser window is closed. So in theory, with a p2p filesharing extension, you may not have to keep any browser window
38.
▲
by
crunchatized
8y ago
OEM configs have never been enough to implement everything they need in Tor Browser. They eventually started their uplift effort [1], to upstream all the patches and features they've added to it, so that they can possibly just use OE
39.
▲
by
crunchatized
8y ago
They're still real technical terms for describing underlying technology that have been appropriated as increasingly stretched marketing terms. It's almost like the euphemism treadmill. As laypeople hear the technical terms repeate
40.
▲
by
crunchatized
9y ago
Law and medicine are more people-oriented, while tech is more things-oriented, so that could account for the differences between the industries. There have been studies on the gender differences in interests along the Things-versus-People d
41.
▲
by
crunchatized
9y ago
If that's a cause of the disparity, would it show as large numbers dropping their first course after meeting their classmates, or not enrolling in the course in the first place? Of course it also starts before college enrollment. AP co
42.
▲
by
crunchatized
9y ago
The extra irony is that's because computer programming was considered "women's work" in those early days, as basically a form of clerical work, like being a secretary. So it was one of the few occupations that was tradit
43.
▲
by
crunchatized
9y ago
Is it concerning yet that they haven't put up their semi annual warrant canary, actually? The last two times, they had it updated by January 14th [0] and July 8th.[1] [0] https://web.archive.org/web/20170114100401&
44.
▲
by
crunchatized
9y ago
At least it only works on chromium-based browsers. Firefox fixed the supercookie problem when opening up a private browsing session back in Firefox 34.0.5 after it was discovered. Which then makes the HSTS preload list and HTTPS Everywhere
45.
▲
by
crunchatized
9y ago
Yeah the only true part there was 'no evil cache entries.' Chrome's incognito mode even explicitly warns that it does not defend against your ISP/employer/school (aka any man-in-the-middle). All incognito does is ke