Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
patrickmcmanus
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
31.
▲
by
patrickmcmanus
8y ago
https://bitsup.blogspot.com/2018/05/the-benefits-of-https-fo...
32.
▲
by
patrickmcmanus
8y ago
not in hard-fail mode; but generally yes.
33.
▲
by
patrickmcmanus
8y ago
DoH on QUIC is probably the end result
34.
▲
by
patrickmcmanus
8y ago
Firefox has both soft-fail and hard-fail modes.. for a soft fail it will fallback to traditional port 53 DNS. Its likely that will be the most common deployment - you need it to deal with captive portals (i.e. the hotel wifi) and other spli
35.
▲
by
patrickmcmanus
8y ago
or a positive privacy impact depending on where you live :)
36.
▲
by
patrickmcmanus
8y ago
we're coming after SNI too. One step at a time. (also, 1] dns leaks are worse than sni leaks as typically more people are exposed to the dns query and 2] HTTP/2 can carry more than one hostname on a connection so some hostnames th
37.
▲
by
patrickmcmanus
8y ago
Everybody is right in this thread :) First, just to avoid confusion, the post linked to this HN article is just about the classic recursive resolver model. That's the scope of what is being experimented with actively. Second, the notio
38.
▲
by
patrickmcmanus
8y ago
Definitely don't want SPOF. Firefox has both soft-fail and hard-fail modes.. for a soft fail it will fallback to traditional port 53 DNS. Its likely that will be the most common deployment - you need it to deal with captive portals and
39.
▲
by
patrickmcmanus
9y ago
yes, quic will make dns over https more resillient to packet loss than a tls based approach.
40.
▲
by
patrickmcmanus
9y ago
one reason: https://www.ietf.org/proceedings/99/slides/slides-99-maprg-f...
41.
▲
by
patrickmcmanus
9y ago
of course dns over https to cloudflare can be mixed on the same h2 connection with other https to the same host. It starts to get interesting. (this is one of the advantages of https vs straight tls)
42.
▲
by
patrickmcmanus
9y ago
this story will evolve as the http ecosystem evolves - but that's part of the point. wrt coalescing/origin/secondary-certificates its a powerful notion to consider your recursive resolver's ability to serve other http tr
43.
▲
by
patrickmcmanus
9y ago
rfc 8336. h2 coalescing. h2 push. caching. it starts to add up to a very interesting story.
44.
▲
by
patrickmcmanus
9y ago
ip addresses in certificates are unusual, but allowed. https://cabforum.org/guidance-ip-addresses-certificates/
45.
▲
Having fun and surprises with IPv6
(huitema.wordpress.com)
4 points
by
patrickmcmanus
9y ago
|
0 comments
46.
▲
A change of lawyers at the FSF
(lwn.net)
2 points
by
patrickmcmanus
10y ago
|
1 comments
47.
▲
by
patrickmcmanus
11y ago
you can claim at most a 3000 loss in a single year.. BUT * you can offset unlimited gains with as many losses as you have - so that's the real value. * you can carry forward losses greater than 3000 to future years. so its not use it o
48.
▲
by
patrickmcmanus
11y ago
it means they can sell the bonds for less (i.e. pay less interest) because one source of competition, depositing the money rather than buying the bond, is less attractive for the captial. As with all credit - that's a great dynamic if
49.
▲
Net neutrality: Discrimination, competition, and innovation in the UK and US
(ora.ox.ac.uk)
3 points
by
patrickmcmanus
11y ago
|
0 comments
50.
▲
TCP without constant Initial Window
(mailarchive.ietf.org)
2 points
by
patrickmcmanus
11y ago
|
0 comments
51.
▲
by
patrickmcmanus
11y ago
seltzer and upgrade your coffee.. and while it isn't exactly health food: nuts, yogurt, apples, and cheese are much better than chips, cookies, and 'bars'.. yogurt apples and cheese will keep for weeks in the fridge.
52.
▲
Let's Encrypt Stats
(letsencrypt.org)
4 points
by
patrickmcmanus
11y ago
|
0 comments
53.
▲
Resilience of Deployed TCP to Blind Off-Path Attacks [pdf]
(icir.org)
7 points
by
patrickmcmanus
11y ago
|
0 comments
54.
▲
Resilience of Deployed TCP to Blind Off-Path Attacks [pdf]
(icir.org)
2 points
by
patrickmcmanus
11y ago
|
0 comments
55.
▲
by
patrickmcmanus
11y ago
this was a decent related read http://www.amazon.com/Bourbon-Empire-Future-Americas-Whiskey...
56.
▲
by
patrickmcmanus
11y ago
more generally - ip over dns https://github.com/yarrick/iodine
57.
▲
by
patrickmcmanus
11y ago
The test server does not actually make sure the h2 test is using h2. If you are using a client that does not have h2 support then you are just using the fallback code on the server and testing h1 against h1. An iphone is a good example :) (
58.
▲
by
patrickmcmanus
11y ago
h2 is better than that.. each request carries a priority, so the server can stop sending one resource and start sending another higher priority one if it becomes available. It can even do this interleaving based on actual data available to
59.
▲
by
patrickmcmanus
11y ago
but pipelines have some real poorly performing cases (head of line blocking, cancel and retry semantics, etc..) that don't apply to h2 - those gotchas aren't represented in this test.
60.
▲
by
patrickmcmanus
11y ago
good analysis. worth mentioning that the h2 test actually respects the congestion window.. this helps both at the sending-too-slow stage, and also at the sending-too-fast stage which can easily be shown with h1 using parallel connections fo
More ›