Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
konklone
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
61.
▲
by
konklone
10y ago
Here's some rationale on why it's worth using HTTPS for everything, even the less sensitive things: https://https.cio.gov/everything/ A lot of people focus on targeted surveillance of people visiting individu
62.
▲
by
konklone
10y ago
As a White House memorandum, that mandate only applies to the executive branch. Though the GSA's HTTPS adoption dashboard does include legislative branch domains, including senate.gov: https://pulse.cio.gov/https/d
63.
▲
by
konklone
10y ago
We're federal government employees (and are allowed to use Slack).
64.
▲
by
konklone
10y ago
I think this is a super important topic, that doesn't get a lot of discussion in the infosec community.
65.
▲
How we get high availability with Elasticsearch and Ruby on Rails
(18f.gsa.gov)
69 points
by
konklone
11y ago
|
29 comments
66.
▲
by
konklone
11y ago
Different branch, though. This policy only covers certain executive branch agencies.
67.
▲
On links to court filings
(esq.io)
4 points
by
konklone
11y ago
|
0 comments
68.
▲
by
konklone
11y ago
> They largely circumvent a lot of the process with help from policy makers at the highest levels. > Even then, I'm pretty sure they don't offer hosting/authorizing deployments from party sources. So they essentially ha
69.
▲
by
konklone
11y ago
er no, #1 should be #1
70.
▲
by
konklone
11y ago
They won't get secure cookies [for the site they're attacking], though they could plausibly redirect the user to a similar-looking HTTPS domain under their control and get permissions requiring a secure origin.
71.
▲
by
konklone
11y ago
I think that instead of HPKP, the parent poster meant to refer to HSTS. If the attacker MITMs an HTTPS request, then they have to provide a forged certificate (whether HSTS is set or not). If the attacker MITMs an HTTP request which would h
72.
▲
by
konklone
11y ago
Users should be able to safely ignore certificate changes. No one should need to install Certificate Patrol to have a safe experience. Of course, if the certificate changes to an untrusted one, the browser should flag it -- and if the serve
73.
▲
by
konklone
11y ago
FWIW, vippy's not referring to the browser extension, but to the federal policy: https://www.whitehouse.gov/blog/2015/06/08/https-everywhere-...
74.
▲
by
konklone
11y ago
> (requirement for citizenship: so many of the great people I know are non citizens, even if many have green cards; drug testing, which doesn't really serve a meaningful purpose) As an 18F employee, I can't speak for USDS, but
75.
▲
by
konklone
11y ago
Yep, and we have some extra 18F-specific information here: https://pages.18f.gov/joining-18f/how-to-apply/
76.
▲
by
konklone
11y ago
> I don't think they work with the FBI, CIA, DEA, DHS etc. Just a small note, immigration is DHS.
77.
▲
by
konklone
11y ago
> I want to give a shout-out to 18F who did a really great job with this. Thanks! We loved the opportunity to assist the Digital Analytics Program (DAP) with the dashboard. They've been around since ~2012 and have been doing the leg
78.
▲
by
konklone
11y ago
> Now, HTTPS everywhere is a dubious project, sorry Konklone Well, I like it. =)
79.
▲
by
konklone
11y ago
> Not sure how Sunlight and EFF spending staff time on something validates or dis-validates a market. They were previously customers of that market. They found it suited their needs better to replace the thing they were purchasing from.
80.
▲
by
konklone
11y ago
> Is 18F sufficiently independent, or this project sufficiently below the radar that it just isn't an issue? Nothing below the radar about it: https://www.whitehouse.gov/blog/2015/06/08/https-ever
81.
▲
by
konklone
11y ago
> People think "The Federal Government" is a monolith, and they could not be more mistaken. It is a collection of individual entities, operating largely independently and often at odds with one another. That's definitely a
82.
▲
by
konklone
11y ago
Full disclosure: I'm the submitter and the creator of these videos. Happy to answer questions or take feedback for future educational work we could be doing.
83.
▲
An Introduction to HTTPS, by 18F and DigitalGov University
(18f.gsa.gov)
67 points
by
konklone
11y ago
|
13 comments
84.
▲
by
konklone
11y ago
Respectfully, @cjoh, that's pretty out of touch. Blue State, Salsa, all of those vendors charge money and create necessarily limited ecosystems. EFF and Sunlight collaborated to create the data ecosystem necessary for this project in o
85.
▲
Policy to Require Secure Connections Across Federal Websites and Web Services [pdf]
(whitehouse.gov)
3 points
by
konklone
11y ago
|
0 comments
86.
▲
The pulse of the federal .gov space
(pulse.cio.gov)
11 points
by
konklone
11y ago
|
0 comments
87.
▲
by
konklone
12y ago
> Logs are good, but packets and flows are better. Trust, but verify. shrug You're not wrong, but it's more important to have wires that can be trusted than to have wires that can be perfectly audited.
88.
▲
by
konklone
12y ago
> I will not speculate on your real intentions here, but i will let you know that everything you have done looks like you have ulterior motives. The post you made, while wordy, utterly fails as an excuse or even apology, the last of whic
89.
▲
by
konklone
12y ago
As of launch day, we started specifying a 5 minute cache time: https://github.com/GSA/analytics.usa.gov#deploying-the-app We might increase that over time, but having fixes take effect within 5 minutes while the site i
90.
▲
by
konklone
12y ago
Google claims not to, that they anonymize the IP before it ever hits disk: https://support.google.com/analytics/answer/2763052?hl=en You have to trust Google to follow through, but my understanding is this was ori
More ›