Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jaas
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
12 ms
·
91.
▲
by
jaas
5y ago
Head of Let's Encrypt here. The question of whether or not revocation should happen has to be asked whenever a certificate compliance issue is being discussed, regardless of how serious the issue is. That is a normal part of the proces
92.
▲
by
jaas
5y ago
I think you are missing the “according to me” (the person you are working for) part of the sentence. In this thought experiment, like the rat, you have no say in what constitutes being treated “well enough.”
93.
▲
by
jaas
5y ago
I think this story about the rat and what it did is cool, it makes me happy, but I do agree with OP that the language of the story misrepresents the reality of the situation. If I was given total control over your life and made you work for
94.
▲
ISRG Prio Services for Preserving Privacy in Covid-19 EN Apps
(abetterinternet.org)
2 points
by
jaas
5y ago
|
0 comments
95.
▲
by
jaas
5y ago
I'm sure that's a big part of it. The old-style extensions were so powerful because they could put their API tentacles very deep into the rendering engine. Mozilla paid a huge price for allowing that though - it was very difficult
96.
▲
by
jaas
5y ago
As someone who used to be involved in the decision to not implement native context menus, and did a bunch of work on the non-native ones, I want to try to explain why this took a long time. It has nothing to do with engineering resources, a
97.
▲
Preparing Rustls for Wider Adoption
(abetterinternet.org)
230 points
by
jaas
5y ago
|
132 comments
98.
▲
by
jaas
6y ago
It’s probably private because it is used for internal systems. It’s probably .com because it’s for Mozilla Corporation as opposed to Mozilla Foundation.
99.
▲
by
jaas
6y ago
Executive Director of ISRG here. To provides some more clarity on how this partnership works... ISRG plans and coordinates investments in moving open source software to memory safe languages. We have a strong preference for working on these
100.
▲
by
jaas
6y ago
Rust is going to be used often, but we are open to other choices when they make sense. Since most unsafe code is C or C++, Rust usually makes the most sense for rewriting one component at a time. It integrates with C and C++ very cleanly be
101.
▲
by
jaas
6y ago
I'm the head of ISRG, the "middle man" entity you're referring to. We have a memory safety initiative in which we plan and fund projects to move popular open source software to memory safe languages. For each plan we mak
102.
▲
by
jaas
6y ago
(Executive Director of ISRG here) > What is left out of the title is that they do not provide funding to the current authors/maintainers of these open source projects. Instead, they fund an organization that will rewrite these tools
103.
▲
Preparing to Issue 200M Certificates in 24 Hours
(letsencrypt.org)
215 points
by
jaas
6y ago
|
101 comments
104.
▲
A Memory Safe TLS Module for the Apache HTTP Server
(abetterinternet.org)
16 points
by
jaas
6y ago
|
2 comments
105.
▲
by
jaas
6y ago
Just so everyone here is aware re: pricing... If you buy through a VAR and/or Dell reps you don't pay the price on the website. What you actually pay is typically significantly lower. I don't think anyone actually buys server
106.
▲
by
jaas
6y ago
Fixed!
107.
▲
by
jaas
6y ago
We didn't go with the 64-core chips because they have significantly lower clock speeds. Dual 32-core chips give us plenty of cores while keeping clocks higher for single-threaded performance. You are correct that the price of the CPUs
108.
▲
The database servers powering Let's Encrypt
(letsencrypt.org)
529 points
by
jaas
6y ago
|
226 comments
109.
▲
by
jaas
6y ago
It's great that they took the time to write this up even though the conclusion is that it doesn't work. Too much valuable information is lost because people don't value negative results enough.
110.
▲
by
jaas
6y ago
Let's Encrypt & Prio Services (ISRG) | Full-time | 100% Remote (United States or Canada) | Software Engineer (SRE) We’re looking for an additional software engineer for our Site Reliability Engineering (SRE) team. Maybe that’s you!
111.
▲
Extending Android Device Compatibility for Let's Encrypt Certificates
(letsencrypt.org)
1 points
by
jaas
6y ago
|
0 comments
112.
▲
by
jaas
6y ago
It's easy, we have no trouble at all. Training more is simple once you have one or two people with experience. No luck needed.
113.
▲
ISRG Prio Services for Privacy Respecting Metrics
(abetterinternet.org)
11 points
by
jaas
6y ago
|
0 comments
114.
▲
by
jaas
6y ago
If a page doesn't use HTTPS, even if it is cats, you cannot trust that the traffic has not been modified in transit. You try to load a cat but a network attacker can add malware or mining code or a worse exploit. Every page needs HTTPS
115.
▲
by
jaas
6y ago
The Intel chip in that comparison was released in Q1 2018, almost three years ago now. How is this a helpful comparison? https://ark.intel.com/content/www/us/en/ark/products/130411/...
116.
▲
by
jaas
6y ago
Let's Encrypt| letsencrypt.org | Software Engineer (SRE) | Remote (US or Canada) | Full-Time We’re making HTTPS easier for developers to use, we’re doing it at scale, and we need your help. We’re a first-of-our-kind Certificate Authori
117.
▲
by
jaas
6y ago
EFF is a strong supporter but Let's Encrypt is not an EFF project. Let's Encrypt is owned and run by Internet Security Research Group: https://www.abetterinternet.org/
118.
▲
by
jaas
6y ago
Chuck Feeney is not "officially broke." Per this story he has a couple million set aside for retirement and is living a perfectly happy life with all of his needs met. It seems disrespectful to Feeney's vision for his own lif
119.
▲
by
jaas
6y ago
Because she's a U.S. Senator who may be the Vice President soon. That's why people care, even if you don't. You know that already so please spare us the personal commentary masked as a question.
120.
▲
by
jaas
6y ago
I see a couple of replies saying something like "plain HTTP [still] works fine." Sure, it works in the sense that most of the time the page will load as expected, but it's not safe or reliable. I don't want our standard
More ›