Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
markild
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
18 ms
·
181.
▲
by
markild
14y ago
I know how this works, but it's quite depressing to see the "Packet roundtrip CA to Netherlands" unchanged throughout the years.
182.
▲
by
markild
14y ago
In this case, if understand the concept correctly, it would be iTunes that pins the certificate authority for the iTunes server. One would still be vulnerable of a corrupt CA. The only solution to this would be to issue all certificates fro
183.
▲
by
markild
14y ago
Absolutely. I wish they would address the topic, though. I interpret this article as if they mean that HTTPS solves all censoring and content sensing issues, regardless.
184.
▲
by
markild
14y ago
This seems to assume that the certificate chain in the software available within China is not compromised (aka, "obvious" way to detect MITM). I honestly don't know if this is a fair assumption or not, it just strikes me as weird that it is
185.
▲
by
markild
14y ago
Very true, but let's not forget that [0] > The HEAD method is identical to GET except that the server MUST NOT return a message-body in the response. and that > The metainformation contained in the HTTP headers in response to a HEA
186.
▲
by
markild
14y ago
All the filter stuff will be applicable for Wireshark as well though.
187.
▲
by
markild
14y ago
Exactly. It's interesting to note that "big money" source control like Microsoft TFS also suffers from this issue. Being fully dependent on Github, if it goes belly up, you need to reconfigure where people push to, that's it.
188.
▲
by
markild
14y ago
At the moment, it seems that you need to use Tumblr for blog posts, the author also mentions maybe extending it to Wordpress. I think the entire idea here is that it is an aggregator of sorts. The site itself contains nothing that does not
189.
▲
by
markild
14y ago
I believe that in most common distributions, both curl and wget will be supplied with ca-certificates out of the box. e.g > $ dig +short ssl.example.com > 123.456.789.012 > $ curl -I https://123.456.789.012/foo.bar > curl: