Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
rx4g
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
rx4g
2y ago
Yes, I do, and am almost 50. I feel fortunate. I get to solve puzzles with a lot of my time.
2.
▲
by
rx4g
2y ago
Yes, I do, and am almost 50. I feel fortunate. I get to solve puzzles with most of my time.
3.
▲
by
rx4g
11y ago
I have experience with Angular and Backbone. Backbone will definitely give you more control, but you have to make more choices. Angular is definitely generating more buzz, but Backbone has a sizable community too, and is more mature and bat
4.
▲
by
rx4g
12y ago
Now I kind of want to cross-reference this with the TIBOE index and make a frankenlanguage with the most popular syntax.
5.
▲
by
rx4g
12y ago
Huh, http://www.theverge.com/2014/11/18/7239221/whatsapp-rolls-ou... (found searching Google News for TextSecure) is also 404'ing at the moment.
6.
▲
by
rx4g
12y ago
It also gives you a chance, on subsequent logins, to just login using your FB account. Not that uncommon.
7.
▲
by
rx4g
12y ago
Self-signed certs are much harder to get browsers to accept these days. The "I know what I'm doing" button and process are becoming ever more complex, and I wouldn't be surprised if they just start going away in favor of
8.
▲
by
rx4g
12y ago
I think he's saying that clients could decide beforehand whether they want to go into HTTPS-only mode, for example. But this is something clients can actually do today, without the need for a new protocol or any awareness on the server
9.
▲
by
rx4g
12y ago
I can't speak for anyone else, but I certainly do. Regardless of the form of PKI employed, there's going to be a cost associated with validating the identity of the parties you're communicating with. For the average Joe, cert
10.
▲
by
rx4g
12y ago
It's disappointing to hear that the idea of requiring TLS with HTTP/2 has lost traction. For me, TLS-everywhere was the carrot on the stick. I recognize that getting consensus is hard work, but I don't think creating anothe
11.
▲
by
rx4g
12y ago
No measure taken in isolation will give you "that much security". As you say, validating the identity of the artifact signer is an extremely important and oft-missed measure, but that should not lead one to conclude that transport
12.
▲
by
rx4g
12y ago
Try the proxy in Burp Suite. The free edition lets you do most of what you can do in Fiddler. More powerful in some ways, rougher around the edges in other ways.
13.
▲
by
rx4g
12y ago
inb4 LibreCrypt
14.
▲
by
rx4g
13y ago
I have high hopes for TACK too. The fact that it's not CA dependent is a big deal. I wrote a bit about that, and getting by with ditching the root CAs in Firefox here: https://rx4g.com/2013/09/13/of-flyin
15.
▲
Of Flying Pigs and TOFU
(rx4g.com)
2 points
by
rx4g
13y ago
|
0 comments
16.
▲
by
rx4g
13y ago
Actually, without installing extra software, you can drop all the root CAs and do Trust-on-First-Use (TOFU) with a limited set of browsers. It's possible with Firefox desktop, for example. Painful and error-prone, but doable. As with t
17.
▲
Web Server Authentication Is Still Broken
(rx4g.com)
20 points
by
rx4g
13y ago
|
7 comments
18.
▲
Why Browsers Need Encrypted-Only Mode
(rx4g.wordpress.com)
6 points
by
rx4g
13y ago
|
0 comments
19.
▲
by
rx4g
14y ago
Wow, I can relate. A while back I left a job I had for 11 years to enter a completely different business domain. I still get email from users of the software I used to work on. Back when I was paid to do it, I always directed people to the