Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mrex
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
14 ms
·
61.
▲
by
mrex
4y ago
TLS is transport encryption, not a content signature. Ideally, I'd like to see every resource being served along with a signature verifying its authenticity, origin, and suitability for public consumption. Users would then be empowered
62.
▲
by
mrex
4y ago
>This will be instantly defeated by benchmarking the js performance. How common is this behavior for non-malicious websites that a Lockdown mode user is likely to use? It seems to me that if you're loading malicious content from a s
63.
▲
by
mrex
4y ago
How realistic is an "advanced fingerprinting attack", though? I think the more realistic threat model here is presented by ad networks and major websites doing typical types of browser fingerprinting, like canvas, fonts, etc. as w
64.
▲
by
mrex
4y ago
Ways to counter fingerprinting: Offer a spoof mode, make the Lockdown mode browser look to external websites like it isn't in Lockdown mode. Tricky but doable with some site breakage that can always be fixed by disabling Lockdown mode
65.
▲
by
mrex
4y ago
But that's only a single application. Lockdown Mode affects the operation of the entire OS, and all applications that use certain iOS features.
66.
▲
by
mrex
4y ago
I would be beyond shocked if Apple's VR set doesn't include a Thunderbolt port.
67.
▲
by
mrex
4y ago
The same thing doesn't go for many US based companies. What US law requires US companies above a certain minimal (~50 employees) size to "hire" government employees to supervise their operations at the innermost layers? What
68.
▲
by
mrex
4y ago
RSA SecureID has been doing this for decades and decades. They use a not-tremendously-accurate battery backed quartz RTC with some drift compensation built into the server side. There are a ton of other options though. Atomic clock signals
69.
▲
by
mrex
4y ago
Really, is TOTP too much to ask when they are charging $300-$500 for a single replacement key anyway?