Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
phkamp
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
23 ms
·
211.
▲
by
phkamp
11y ago
I'm kind of surprised about this repeated "I just use nginx" argument, it doesn't make sense to me at all. If your site runs fine, in all situations you care about, without FOO, you would be pretty lame if you increased
212.
▲
by
phkamp
11y ago
I have opinions on life on Mars ?
213.
▲
by
phkamp
11y ago
... And now they also need to circumvent Googles cert-pinning and other attempts to twart even legally mandated MiTM proxies... Either all MiTM needs to be outlawed (with actual laws) or protocols need to recognize that laws mandate MiTM so
214.
▲
by
phkamp
11y ago
If you don't need varnish, it would be pretty stupid to start running it...
215.
▲
by
phkamp
11y ago
Are you willing to pay increased taxes, so that FEMA (Or your countrys similar) can afford to run 100.000 servers, in order to "do TLS on Google scale", so that they can get emergency orders out for civil defence ? Have your forgo
216.
▲
by
phkamp
11y ago
Let me just make absolutely clear: It's not my opinion that certain people don't deserve privacy, it is the law of the land, duly enacted and ratified by legitimate governments. If you want to change that, vote.
217.
▲
Bob Briscoe flunks HTTP/2
(lists.w3.org)
2 points
by
phkamp
12y ago
|
0 comments
218.
▲
by
phkamp
12y ago
It is certainly a step in the right direction, my main worry is that the OpenBSD crew has a tendency to to -- SQUIRREL!! and forget their old toy when they spot a new shiny one.
219.
▲
by
phkamp
12y ago
The historical evidence that technology cannot be stopped by lawmakers is very weak, if it even exists in the first place. Very few lawmakers have really tried, and few technologies have been worth it in the first place. The relevant questi
220.
▲
by
phkamp
12y ago
It's certainly not a trivial thing to design, but the "GET https://..." proposal floating around solves a lot of the relatively benign cases (company/school smut-proxies etc.) My point is that HTTP/2 did
221.
▲
by
phkamp
12y ago
No, I'm not saying "lets not even try", I'm saying "Lets try with the right tools for the job: Voting ballots." In the meantime we should not cripple our protocols, hoping that the NSA will go "aahh shuck
222.
▲
by
phkamp
12y ago
You are welcome to that opinion, take it up with your lawmakers, vote based on it, or run for office yourself to make it reality. Just don't think you will make such proxies disappear with technical means -- in particular not where the
223.
▲
by
phkamp
12y ago
NSA does what the do because lawmakers told them to and gave them the money -- you cannot separate these two sides of the problem. There are many ways to break SSL, the easiest, cheapest and most in tune with the present progression towards
224.
▲
by
phkamp
12y ago
It's really very simple: Instead of all the servers dumping cookies on you, you send a session-id to them, for instance 127 random bits. In front of those you send a zero bit, if you are fine with the server tracking you, and you save
225.
▲
by
phkamp
12y ago
That's actually a very good question, thank you for asking it. Because I think that we can do much better than the pile of IT-shit we have produced until now. I am actively trying to do that, through my own code, through the articles t
226.
▲
by
phkamp
12y ago
A bad analogy is like a wet screwdriver. Try this one, it's better, but not perfect: Imagine what happened if some cheap invention turned all buildings into inpenetrable fortresses unless you had a key for the lock. Now police can not
227.
▲
by
phkamp
12y ago
Pervasive authenticated encryption will not prevent the NSA from doing their job, as long as lawmakers think they should do their job. Instead you will see key-escrow laws or even bans on encryption. You cannot solve the political problem b
228.
▲
by
phkamp
12y ago
With unencrypted HTTP, NSA can just grab the packets on the fiber and search for any keyword they want. With a self-signed cert they would have to do a Man In The Middle attack on you to see your traffic. They don't have the capacity (
229.
▲
by
phkamp
12y ago
self-signed-certs is about making NSA&friends work for it, rather than giving them a free ride. Today they can grep plaintext as they want. With SSC's they would have to pinpoint what communication they really need to see. That wo
230.
▲
by
phkamp
12y ago
I'm not arguing against SSL. I'm arguing against making SSL mandatory, because that will force NSA to break it so they can do their work, and then we will have nothing to protect our privacy. More encryption is not a solution to a
231.
▲
by
phkamp
12y ago
No, this is actually a very important point for me. If HTTP/2.0 had done this right, there wouldn't be a need for your employer to trojan your CA list so they can check for "inappropriate content" going either way throug
232.
▲
by
phkamp
12y ago
The difference is who makes the decisions: session id is controlled by the client. cookies by the server. FaceBook, Twitter etc. track you all over the internet with their cookies, even if you don't have an account with them, whenever
233.
▲
by
phkamp
12y ago
There is. I have received emails that say so outright.
234.
▲
by
phkamp
12y ago
Show me the mainstream browsers that will use HTTP/2 without SSL/TLS ? The difference between you and me, may be that I have spent a lot of time measuring computers power usage doing all sorts of things. You seem to be mostly gue
235.
▲
by
phkamp
12y ago
Yes, clearly nothing has changed since 1995 at all, obviously nobody has gotten any wiser or anything. My big problem with HTTP/2 is that it's crap that doesn't solve any of the big problems.
236.
▲
by
phkamp
12y ago
SSL does not provide identity assurance (=authentication), the CA-cabal does, SSL just does the necessary math for you. CA's are trojaned, that's documented over and over by bogus certs in the wild, so in practice you have no auth
237.
▲
by
phkamp
12y ago
Actually, getting rid of cookies would fit almost all HTTP requests into a single packet, so there are tangible technical benefits, even without the privacy benefits. You seem confused about cryptography. Against NSA we only need secrecy, p
238.
▲
by
phkamp
12y ago
You obviously havn't spent much time looking either, have you? You could look at section 15 here for instance: http://phk.freebsd.dk/words/httpbis.html With respect to key-exchange, maybe the problem is that I do
239.
▲
by
phkamp
12y ago
SPDY was chosen because nobody got any serious notice or time to come up with any alternatives. If the IETF wanted a fresh look at HTTP, they would not have set such a short deadline for submissions. It was evident from the start that this
240.
▲
by
phkamp
12y ago
I have go go shopping and cook dinner, but if I'll be back in a couple of hours. Poul-Henning
More ›