Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ekr____
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
121.
▲
by
ekr____
11mo ago
There were a number of things going on with TLS 1.3 and paring down the algorithm list. First, we both wanted to get rid of static RSA and standardize on a DH-style exchange. This also allowed us to move the first encrypted message in 1-RTT
122.
▲
by
ekr____
11mo ago
Mozilla spun up a whole new entity (Mozilla.ai) to do AI stuff, so doing AI stuff outside of Firefox is already baked into the equation, whatever you think of this particular thing.
123.
▲
by
ekr____
11mo ago
> Yes I understand all of that, but I still choose to trust free services less. Well, you can choose to do whatever you want, but given that you're posting to a public forum, it would be helpful if you actually explained your reason
124.
▲
by
ekr____
11mo ago
Thanks for explaining. I think this concern is reflects a misunderstanding of how the security of the WebPKI works. Specifically, any CA can issue certificates for your domain whether you are their customer or not. What that means is that i
125.
▲
by
ekr____
11mo ago
TLS 1.0 actually is slightly different from SSLv3.
126.
▲
by
ekr____
11mo ago
What does it mean not to trust Let's Encrypt in this case? What is it you are concerned they will do?
127.
▲
by
ekr____
11mo ago
Not quite. The name was changed from SSL to TLS as part of the adoption in IETF. I imagine different people had different motivations, but in part it was a signal that it was going to be controlled by IETF rather than Netscape. As far as co
128.
▲
by
ekr____
11mo ago
> What is the supported way? The settings UI. > > you shouldn't complain that Mozilla changed the prefs and reenabled these features. > Then they should provide a reliable way of getting what I want. As I said in the commen
129.
▲
by
ekr____
11mo ago
I know I'm a broken record on this topic, but messing with prefs directly is not a supported way of configuring Firefox, so if you do this, you shouldn't complain that Mozilla changed the prefs and reenabled these features. It
130.
▲
by
ekr____
1y ago
I think we agree here: protocols built on top of UDP often build their own ad hoc reliability layer, as opposed to having an explicit one like TCP, QUIC, or SCTP.
131.
▲
by
ekr____
1y ago
Well, WebTransport is built on top of QUIC, and so the overhead is actually reasonably comparable to that for WebRTC.
132.
▲
by
ekr____
1y ago
I agree with you about the category error. In all fairness, though, there are quite a few application protocols which are built directly on top of UDP with no explicit intermediate transport layer. DNS, RTP, and even sometimes SIP come imme
133.
▲
by
ekr____
1y ago
I would argue with "only". Full queues are only one reason you get packet drops. For example, packets can be damaged in transmission. This isn't common but that's not the same as saying it doesn't happen.
134.
▲
by
ekr____
1y ago
That's what these zero-knowledge proof systems are designed to provide. But obviously, if you want to fly an airplane we need to verify that the credential was actually issued to the person standing in front of us and they didn't
135.
▲
Government IDs for age assurance: from selfies to zero-knowledge proofs
(educatedguesswork.org)
2 points
by
ekr____
1y ago
|
2 comments
136.
▲
by
ekr____
1y ago
You also can't fork the update channel, so you're starting from scratch with 0 market share.
137.
▲
by
ekr____
1y ago
It's important to realize that about:config flags aren't part of the official configuration interface, so there really aren't any guarantees about how the system will behave if you frob one. Generally, updates are designed s
138.
▲
by
ekr____
1y ago
This is only a tiny part of the trainwreck that is IETF and IETF-adjacent document nomenclature. IETF documents start as Internet-Drafts, which officially are just draft documents that can be changed at any time. As a practical matter, some
139.
▲
by
ekr____
1y ago
I think there's a fair argument to be made that this was a bad decision on Postel's part, because it made it harder to have good diagrams as well as mathematical formula, and of course it also meant that we couldn't render ma
140.
▲
by
ekr____
1y ago
Almost none of them. There are a number of problems with trying to learn networking from the RFCs. First, they're specifications, not tutorials, so they just assume that you have a lot of background that you otherwise have to infer. Se
141.
▲
by
ekr____
1y ago
Other countries tend to have only one or two contests, which makes counting easier. In the US, it's very common to have 10s of contests on a ballot, and it's much more efficient to count via optical scan. You can still have high c
142.
▲
by
ekr____
1y ago
The problem with hand counting is that it scales very poorly. Specifically, the cost of hand counting is the product of the number of ballots times the number of contests on each ballot. US elections tend to have a very large number of cont
143.
▲
by
ekr____
1y ago
This is less about technology than it is about process. Specifically: 1. California allows mail in ballots to be counted if they arrive up to 7 days after the election. 2. California requires a 1% manual tally. This can take a really long t
144.
▲
by
ekr____
1y ago
There's not one California system. Each jurisdiction inside California picks its own system out of those which are certified. https://www.sos.ca.gov/elections/ovsta/frequently-requested-... For example, LA us
145.
▲
by
ekr____
1y ago
I don't think it's correct to say that browser vendors don't think it's worth solving. For instance, Martin Thomson from Mozilla has done some thinking about it. https://docs.google.com/document/u&#x
146.
▲
by
ekr____
1y ago
Certificate verification in Firefox happens at a layer way above HTTP and TLS (for those who care, it's in PSM), so which QUIC library is used is basically not relevant. The reason that Firefox -- and other major browsers -- make self-
147.
▲
by
ekr____
1y ago
Firefox is a browser and so (1) people at Mozilla are comfortable with HTTP and (2) there has been a lot of investment in making the HTTP stack good. You will also notice that the lead author of DNS over HTTPS [0] was a Mozilla employee. [
148.
▲
by
ekr____
1y ago
This is correct. The right way to think of DoH is as part of a package of mechanisms (including ECH) that collectively are designed to close network-based leakage of browsing history. Used alone, it has some value but that value is limited.
149.
▲
by
ekr____
1y ago
I'm not sure that this mechanism delivers the desired privacy benefit, and it's quite hard to make sure it does so. For example, the paper you cite here uses consistent hashing, where you hash the domain name and then divide by K
150.
▲
by
ekr____
1y ago
Actually, DoH doesn't change the situation here one way or the other, it's just a transport. It's true, that Firefox's approach to DoH ("trusted recursive resolver") does. centralize traffic some, but DoH need
More ›