Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
phlo
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
12 ms
·
91.
▲
by
phlo
10y ago
> When you switch jobs in the USA, you switch health insurance and other benefits. In Switzerland, you'll switch accident coverage and probably the pension fund. Still some work, but not as tedious as what I imagine the situation in
92.
▲
by
phlo
10y ago
...and password managers are weak to lots of problems [1], the least of which is malware stealing your password container plus the master key [2]. I'm still leaning towards the password manager side of the dilemma, but the situation is
93.
▲
by
phlo
10y ago
Good idea. I wonder why the privacy-protecting Add-Ons (ABP, uBlock Origin) don't mask the UA by default. On the other hand, trackers will probably just switch to detecting the capabilities of the browser using JS and then map each dis
94.
▲
by
phlo
10y ago
Absolutely. Which is why I think we still have a lot of work ahead of us, making users actually check the domain name, and the validated identity (for EV certs).
95.
▲
by
phlo
10y ago
This is great news. Furthering HTTPS adoption is the best way we have to combat pervasive surveillance, and we're making steps in the right direction before HTTP2's opportunistic encryption [1] will improve things on an even wider
96.
▲
by
phlo
10y ago
VAT is already factored into EU prices. Germany and France charge 19% and 20%, respectively -- Ireland charges 23%, which explains a difference of roughly $100. Switzerland has a lower VAT rate of 8%, so the lower price compared to EU count
97.
▲
by
phlo
10y ago
Assuming his investments gained by 10% a year (which is extremely optimistic), he would have had to save $80k per year. Only a small minority of people have the required income to do that; especially at 25.
98.
▲
by
phlo
10y ago
Touch ID is a fun case in security where bad is better. Fingerprint authentication on a fingerprint magnet seems like a foolish idea until you realize the alternative (for the majority of users) is 4-digit PINs[1], not strong passwords. [1]
99.
▲
by
phlo
10y ago
Again, I'm suggesting browsers should continue to display a warning if a site that was previously served over an authenticated connection stops being served over an authenticated connection . In this case, an attacker could only turn
100.
▲
by
phlo
10y ago
It clearly doesn't and probably won't, for the forseeable future. I'm arguing for the browser to have the same behavior for all insecure connections, be they HTTP or HTTPS on a self-signed cert. There clearly shouldn't b
101.
▲
by
phlo
10y ago
A self-signed certificate provides the same (or slightly better) security as an HTTP connection, but browsers treat them differently. They sternly warn against the former and silently ignore the latter. I agree with the parent post: both ca
102.
▲
by
phlo
10y ago
> A CDN is effectively part of the developer's infrastructure. Agree. If the CDN is compromised, all bets are off. In my opinion, CloudFlare Flex/Full are a lot more vulnerable to attack (because the resources can be obtained i
103.
▲
by
phlo
10y ago
On one hand, Troy is right: absolutism can hurt security, and a partially encrypted connection (e.g. CloudFlare's "flexible" version) is better than a wholly unencrypted one. On the other hand, opportunistic encryption as des
104.
▲
by
phlo
10y ago
We can draw some interesting parallels to information security from this. Both thieves snuck in through unused passageways, just like some interesting attacks use legacy functionality that is still carried in software: Heartbleed exploited
105.
▲
by
phlo
10y ago
CRIME works because the compression/encryption algorithms aren't aware of which data is secret and which isn't. They treat the whole HTTP stream as a stream of text and operate on that. To them, text within the page is just t
106.
▲
by
phlo
10y ago
That'll make an attack significantly more time-consuming, but won't prevent it. Instead of instand feedback whether they guessed correctly, an attacker would instead need to send a bunch of requests to determine if the average req
107.
▲
by
phlo
10y ago
Either you employ some sort of malware detection on your login page. Modern trojans mostly inject stuff into web pages, so things like Trusteer Pinpoint will scan the DOM and report back anomalies. Based on those reports you block the user
108.
▲
by
phlo
10y ago
It's a valid defense against hardware keyloggers, ignoring that you're way more likely to encounter a software keylogger. If your account is interesting enough for criminals to break into your computer room and attach dongles to y
109.
▲
by
phlo
10y ago
It doesn't. Today's banking malware will capture the form values on submit, either as text or as a screenshot. And it will do so, silently, every time you log in. All this scheme does is limit an attacker to gathering three letter
110.
▲
by
phlo
10y ago
Because in some cases they are. Many banks (I work for one of them) follow reasonable best practices, allow or require strong passwords, store them safely and require sensible second security factors. Others are decades behind in security,
111.
▲
by
phlo
10y ago
Those seem like very reasonable points. Are you confused by the terminology? If so: - "x" height refers to the height of the mean line of lowercase letters, e.g. the lowercase letter "x". Ascenders (on letters like l, t,
112.
▲
by
phlo
11y ago
Sorry, I don't have a public reference. The first number came from my (unpublished) 2013 bachelor's thesis, where I surveyed the 20 biggest banks (by balance sheet) in each of CH, DE, AT, IT and FR. HSTS was very new back then, so
113.
▲
by
phlo
11y ago
> Hazard sign implies some hazard exists - but in this case the hazard has been averted, so why show a hazard sign still? The way I see it, the browser actively blocked a hazardous action. The site continues to be hazardous, and another
114.
▲
by
phlo
11y ago
> Not that any of this will ever be deployed[2], because they're two of the most invasive defence measures [...] SRI is going to be a tough sell. CSP, not so much. Case in point: within two years, HSTS use by Swiss Banks has gone fr
115.
▲
by
phlo
11y ago
I disagree with their rationale in changing the padlock used to indicate a DV certificate from grey to green (and thus mirroring EV certs) to a point: Yes, the connection is secure, but given the numerous free and automated options to obt
116.
▲
by
phlo
11y ago
The term refers to subverting a reputation system by creating loads of spurious participants. See https://en.wikipedia.org/wiki/Sybil_attack for details. With regards to Bitcoin: The value in a distributed block chain
117.
▲
by
phlo
11y ago
There is a paste of the article text (and comments, as of half an hour ago) on http://pastebin.com/0epgegWH
118.
▲
by
phlo
11y ago
On the very high end, Graf von Faber Castell has been selling their "perfect pencil" [1] for a couple of years now. It's platinum-clad (or something similar) and comes with a built-in sharpener for around $260. Refills are so
119.
▲
by
phlo
11y ago
> After the first hash, it's just hashing a hash The recommended password hashing functions (PBKDF2, bcrypt, scrypt) actually use the provided password in each iterated round of the algorithm. The DoS vector Someon1234 mentioned is
120.
▲
by
phlo
11y ago
You're probably talking about the Swisscom offering, which is roughly comparable to what at&t might offer. Fiber7 sells 1 Gbps lines for around CHF 65.- per month, without the obligation to also get a TV subscription and more nonse
More ›