Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
lemonade
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
38 ms
·
31.
▲
by
lemonade
13y ago
I agree that the term is bad taste and not really a good metaphor anyway. Slavery was about people trading and legally owning other people, and nowadays refers to a certain type of adult relationship. Both of them do not adequately describe
32.
▲
by
lemonade
13y ago
I think the opposite is true. Don't make me join Facebook or Twitter to use any service. I won't. And not offering something without joining some other service and reporting your online life to specific profiling companies (tying
33.
▲
by
lemonade
13y ago
With a small caveat for HTML5 apps where you can install a verified version of specific code you trust in your browser or your phone. And Node.js applications which run on the server side in a controllable version. But above is just a nuanc
34.
▲
by
lemonade
13y ago
This is called certificate pinning (a.k.a. Trust On First Use or TOFU). If you use Firefox, just install Certificate Patrol. If you are interested in the rationale, and how you can use technologies like DANE to make it even better, read the
35.
▲
by
lemonade
13y ago
Very useful list. None of these have anything running as a service you can try out easily, I guess that would be a Bad Idea anyway as this kind of tools might either accidentally cause stuff to happen to a server, or be used as part of an a
36.
▲
by
lemonade
13y ago
These days mail clients like Thunderbird warn you for large attachments, and prompt you to use some other solution. Even better: using the built in XMPP-client they could easily send you infinitely sized files at you@yourdomain.com - if onl
37.
▲
by
lemonade
13y ago
You could safely mail me, though. We use the same stack you do, plus DANE for advertising the fingerprint of the certificate to make sure the connection to the mail server is not MitM-ed. And (open)DMARC for giving feedback to mail origins
38.
▲
by
lemonade
13y ago
I think it is a best practise. Surely, moving to another service provider is fully legit. However, a hijack with a rogue certificate (say from an undiscovered Diginotar) would not be visible to users - thereby exposing their credentials. So
39.
▲
by
lemonade
13y ago
https://www.eff.org/observatory "Browsers trust a very large number of these CAs, and unfortunately, the security of HTTPS is only as strong as the practices of the least trustworthy/competent CA. Before publishing this data, we attempted
40.
▲
Certificate Authority change at HN from Comodo to Entrust. No warning?
7 points
by
lemonade
13y ago
|
8 comments
41.
▲
19 year old webpage with favorite Electronic Commerce WWW resources
(virtualschool.edu)
1 points
by
lemonade
13y ago
|
0 comments
42.
▲
Office document directly in the browser
(opendocumentformat.org)
5 points
by
lemonade
13y ago
|
0 comments
43.
▲
Calculate your Facebook value
(scan.thepoweroffacebook.com)
2 points
by
lemonade
14y ago
|
0 comments
44.
▲
What about that other open source Blink project
(plus.google.com)
1 points
by
lemonade
14y ago
|
0 comments
45.
▲
by
lemonade
14y ago
Also if the certificate is published in the DNS, and available through DANE (using DNSSEC)? That would be very disappointing.
46.
▲
by
lemonade
14y ago
If you want a command line client, try the sip example client that is part of the SIP SIMPLE client SDK at http://sipsimpleclient.com . If you want a GUI you can try Blink ( http://icanblink.com ). Both work great with Sylk server ( http:/