Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
gwu78
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
gwu78
10y ago
I prefer http://curvedns.on2it.net This was the original. Other than having to modify their ksh script, it is painless to set up. In my opinion, authoritative nameservers, and therefore DNSCurve forwarders like CurveDNS, are mor
32.
▲
by
gwu78
10y ago
You are reading things into my comments. Whether leaking the domainname in the Client Hello packet bothers a user or not is up to them. I simply brought it up as a consideration. I have a particular dislike for SNI because it requires mod
33.
▲
by
gwu78
10y ago
"I really don't care what you do..." Then why comment? One user expresses dislike for SNI and you feel compelled to respond? If you have your own reasons for liking SNI you could have stated them, but you did not. If I do n
34.
▲
by
gwu78
10y ago
Do you like to make all sorts of assumptions about users, what software they use, what software they "should" use and what software "no one uses"? I don't. Unlike many forum commenters, I do not try to convince peo
35.
▲
by
gwu78
10y ago
Any sslclient that has not been modified to accomodate SNI. As someone else commented, SNI appeared in 2003. Was all SSL-enabled software written after 2003 SNI-enabled? Why not? There are still many https websites that do not require SNI
36.
▲
by
gwu78
10y ago
"If it's a hostname it has to correspond to a valid domain name, right?" If it is listed in the ICANN DNS, maybe. DNS is not mandatory for a website to work. Most of the time I do not use DNS when reading the www. I have my
37.
▲
by
gwu78
10y ago
I do not use Windows. I do not use the kernel or the browser you use. It is not your business what I use anyway. Notice I never said TLS sucks, you did. Maybe I do not care about security and I just like carefully written software by pe
38.
▲
by
gwu78
10y ago
"Getting the hostname from SNI requires TCP sessionalization and at least some form of DPI." I have done it with tcpdump. What does getting the hostname from an encrypted packet require? Assume DNS is not used and there is no reve
39.
▲
by
gwu78
10y ago
Are you saying that programs that extract hostnames like "sniproxy" cannot scale? And you are saying that all hosts have set up reverse DNS and the data is complete and accurate?
40.
▲
by
gwu78
10y ago
Do you understand why I do not like SNI? It has nothing to do with getting these stupid hostnames. It is a modification that needs to be made to software to accomodate the spread of the use of the SNI extension. As a user, I have no need
41.
▲
by
gwu78
10y ago
You assume that DNS is being used. What if the user already has the IP address and knows the hostname? SNI makes gettng the hostnames easier than if they were encrypted as they are without SNI.
42.
▲
by
gwu78
10y ago
I am not suggesting that anyone use something else besides SSL. Use whatever you want to use. I am suggesting that SSL users may want to consider the merits of the SNI extension. Website owners are unlikely to care let alone oppose it.
43.
▲
by
gwu78
10y ago
I would not use SSL. Why spend time learning and fiddling with something that is so flawed? If I was serious about encrypting traffic I would use CurveCP. SSL is simply a nuisance I tolerate to read the www. Every minute I spend learnin
44.
▲
by
gwu78
10y ago
And break the connection. Mission accomplished.
45.
▲
by
gwu78
10y ago
This thread may grow long and maybe turn to the topic of HTTPS. SSL with SNI exposes plaintext hostnames/domainnames on the wire for anyone to read, aggregate and sell, not to mention tamper with. It should be an optional extension
46.
▲
by
gwu78
10y ago
http://www.cultofmac.com/280189/icloud-hacker-calls-apples-r... http://www.mirror.co.uk/news/technology-science/technology/a...
47.
▲
by
gwu78
10y ago
One of the things I like about this choice is one does not need an IDE, at least not with the 2.0. One can do non-graphical (systems) programming on an underpowered computer with no graphics. I statically compile the loader. On BSD at lea
48.
▲
by
gwu78
10y ago
A domain like *.amazonaws.com has nothing to offer that I have ever seen, pure rubbish. Blocking it will stop ads in mobile apps. Cumulatively I think AWS is adding a hefty amount of latency. The way their DNS is configured is often convol
49.
▲
by
gwu78
10y ago
"Privacy? Avoiding malware?" Neither. Those benefits are only side effects.
50.
▲
by
gwu78
10y ago
Default settings use remote, shared DNS caches run by an advertising company. Regardless, this is a step in the right direction. DNS is highly effective for this filtering out advertising. Personally I just run my own authoritative nameser
51.
▲
by
gwu78
10y ago
I constructed a proper URL and submitted an upvote. <a href=" https://news.ycombinator.com/vote?id=13847301&how=up&auth=f4...
52.
▲
by
gwu78
10y ago
If I could upvote this, I would. Text-only browser (no Javascript) means I cannot upvote. This might be an unpopular opinion, but it is one based in real experience: If you can ditch the mouse, then you can ditch the GUI. I have not used a
53.
▲
by
gwu78
10y ago
This is a real gem of a comment: https://news.ycombinator.com/item?id=13571160 "petty abstractions" to assist reusability Layer upon layer upon layer of indirection. I want to be liberated from this mindlessness.
54.
▲
by
gwu78
10y ago
From reading your blog, I detect that you like working in MS Windows. Can your compiler be ported to BSD? Here is the rationale for why this can be useful: BSD can in turn be ported to new hardware with reduced amount of effort, sometimes a
55.
▲
by
gwu78
10y ago
I can confirm that company is Apple.
56.
▲
by
gwu78
10y ago
"How can we recursively find all files with \ name in folder foo?" Whenever someone tries to critique UNIX they always make up these nonsensical problems. No UNIX user would intentionally name a file with a forward slash, a space,
57.
▲
by
gwu78
10y ago
If users were discerning based on the inner workings of this organization, they should be switching their nameservers away from Cloudflare. Quantifying the number of domainnames CF has in their zones before and after this reported incident
58.
▲
by
gwu78
10y ago
I do the same. I have experimented with various solutions. Currently using haproxy. This also fixes problems with clients that are, thankfully, not SNI-capable.
59.
▲
by
gwu78
10y ago
"... encryption without authentication is worthless." I have heard this before, i.e., seen it in HN comments. There are uses for encryption without authentication. I am not an expert on encryption. This is all I will say. In your
60.
▲
by
gwu78
10y ago
Encryption: getting easier every day Authentication: difficult if not practically impossible[1] [1]Outside of organizations where members follow rules. If you agree, then here is a question: Why does SSL, hereafter "TLS",
More ›