Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
groovecoder
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
15 ms
·
31.
▲
by
groovecoder
7y ago
Answered here: https://news.ycombinator.com/item?id=20465981
32.
▲
by
groovecoder
7y ago
Answered here: https://news.ycombinator.com/item?id=20465981
33.
▲
by
groovecoder
7y ago
Answered here: https://news.ycombinator.com/item?id=20465981
34.
▲
by
groovecoder
7y ago
Answered here: https://news.ycombinator.com/item?id=20465981
35.
▲
by
groovecoder
7y ago
Answered here: https://news.ycombinator.com/item?id=20465981
36.
▲
by
groovecoder
7y ago
Answered here: https://news.ycombinator.com/item?id=20465981
37.
▲
by
groovecoder
7y ago
Disclaimer: Firefox sec eng who works on both this feature and Facebook Container ... The new 2.x release of Facebook Container allows people to use "Log in with Facebook". To do so, it adds the site into the Facebook Container so
38.
▲
by
groovecoder
7y ago
Disclaimer: I'm the Firefox sec engineer working on this feature. Just to clear this up: The code for this is actually way simpler and sends no data to either Mozilla nor HIBP. To prevent Firefox from sending data update pings to HIBP,
39.
▲
Next steps in privacy-preserving Telemetry with Prio
(blog.mozilla.org)
6 points
by
groovecoder
7y ago
|
0 comments
40.
▲
by
groovecoder
7y ago
Your initial report emails will always go to the affected email addresses. But future breach alerts will be sent to the Primary address. (If you select that in your preferences.)
41.
▲
by
groovecoder
7y ago
Also, https://www.mozilla.org/en-US/privacy/firefox-monitor/
42.
▲
by
groovecoder
7y ago
https://blog.mozilla.org/security/2018/06/25/scanning-breach...
43.
▲
by
groovecoder
7y ago
By default we don't show: * Sensitive Breaches * "Retired" Breaches * Spam Lists * Fabricated Breaches * non-Verified Breaches https://github.com/mozilla/blurts-server/blob/master/hibp.js..
44.
▲
by
groovecoder
7y ago
Good idea. File it here? https://github.com/mozilla/blurts-server/issues
45.
▲
by
groovecoder
7y ago
Disclaimer: Firefox Monitor dev here. Note: We just released a "V2" of the site that allows you to add multiple email addresses to monitor, and (then) to have all your breach alerts sent to your single primary email address.
46.
▲
by
groovecoder
7y ago
https://monitor.firefox.com/security-tips#after-breach
47.
▲
by
groovecoder
7y ago
Disclaimer: Monitor dev here ... Watch this space: https://github.com/mozilla/blurts-addon/issues/142 ;)
48.
▲
by
groovecoder
7y ago
Please note: the fingerprinting protection in this blog post is different from the resistFingerprinting about:config pref which would affect your entropy bits on panopticlick.
49.
▲
by
groovecoder
8y ago
Huh ... I thought that must be a sensationalist headline but sure enough - a fresh download of Brave browser loads facebook.com on pinterest.com. https://imgur.com/a/M4B9kJ2
50.
▲
by
groovecoder
8y ago
We have wrapped the /scan endpoint in rate-limiting to mitigate and alert on abusive scanning. We are fine-tuning the rate limit as we see more real user traffic coming in.
51.
▲
by
groovecoder
8y ago
Stay tuned! Localization is our next highest-priority enhancement.
52.
▲
by
groovecoder
8y ago
No difference on the site/service side (yet). Stay tuned for more, though! ;)
53.
▲
by
groovecoder
8y ago
Thanks for taking the time to provide feedback. As mentioned in another comment, you can opt-out of the HIBP database here: https://haveibeenpwned.com/OptOut I also filed https://github.com/mozilla/blur
54.
▲
by
groovecoder
8y ago
Thanks for taking the time to provide feedback. As mentioned in another comment, you can opt-out of the HIBP database here: https://haveibeenpwned.com/OptOut I also filed https://github.com/mozilla/blur
55.
▲
by
groovecoder
8y ago
I'm a Mozillian who worked on MDN for 5 years, and now work on Firefox Privacy & Security. Most relevantly, I wrote the patch that implements strict-origin-when-cross-origin Referrer policy in Private Browsing Mode. I certainly tru
56.
▲
by
groovecoder
8y ago
There are known trackers involved with non-consensual crypto-jacking, and fingerprinting. Those domains can be blocked completely.
57.
▲
Same-Site Cookies in Firefox 60
(blog.mozilla.org)
15 points
by
groovecoder
8y ago
|
1 comments
58.
▲
by
groovecoder
8y ago
We ran a breakage study near the end of last year. First-Party Isolation (FPI) did have the highest breakage scores: ~18-19% of users reported problems with it, and 9-10% of FPI users disabled the study. Those are low relative numbers, but
59.
▲
Internet Health Report 2018
(internethealthreport.org)
5 points
by
groovecoder
8y ago
|
0 comments
60.
▲
by
groovecoder
9y ago
That's an interesting threat model for this particular defense. Cliqz has done some interesting research in this area of detecting (and stripping) unsafe data elements. http://josepmpujol.net/public/papers/puj
More ›