Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
temprature
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
temprature
10y ago
This is wrong. The domain name is revealed through SNI but the path of the URL is sent as part of the encrypted HTTP request.
32.
▲
by
temprature
10y ago
The email that's being sent out: https://marc.info/?l=openbsd-tech&m=149028593819547&w=2 An article where Rich Salz cites "expert legal counsel" in response to de Raadt questing whether that's le
33.
▲
by
temprature
10y ago
> For our secure group chat, file sharing and collaboration tool Semaphor, it means you can even review the source code. Has anyone ever tried to "review the source code"? "review the source code" links to https:&#
34.
▲
by
temprature
10y ago
Are you saying you not only know of some website that does password hashing client-side but that you also inspect the javascript that site serves you every time you login?
35.
▲
by
temprature
10y ago
You're saying no one is doing password hashing right, from Google to Facebook to Apple to Microsoft to this very website we're posting on.
36.
▲
by
temprature
10y ago
BlackBerry's android phones (Priv and the DTEK series) get monthly security updates. They do lag behind in the major version updates though.
37.
▲
by
temprature
10y ago
The Signal server software has federation support. It's not enabled (anymore) on the official server but anyone could set up a server and federate with other federation enabled Signal servers.
38.
▲
by
temprature
10y ago
Select the old entry and click the "Show" button at the bottom, it takes you to the entry tab but with the old data in place so you can copy the old password.
39.
▲
by
temprature
10y ago
`pass` stores the name of the entry in plain-text (as the filename of the encrypted file), so you have to either obfuscate the names of the entries or it leaks the name of the site that the entry is for.
40.
▲
by
temprature
10y ago
> This means it's unlikely that Signal is ever going to have any support for federation. Signal had support for federation. Their server was federated with Cyanogen's for a while[0]. That being the disaster it was is why th
41.
▲
by
temprature
10y ago
> but since Signal's server code isn't federated The Signal server code has supported federation since the first commit in the git history. Whisper Systems' instance of the server doesn't federate with any other ser
42.
▲
by
temprature
10y ago
> it has to send it from it's own address @ it's own domain, to avoid SPF failure. To avoid SPF failure it uses its own domain in the MAIL FROM envelope address. There are very few lists that change the From header, I can
43.
▲
by
temprature
10y ago
> That will not affect DKIM. It will affect DKIM and it does. > The DKIM signing occurs after the listserv creates the email message and hands it off to the SMTP server. The DKIM signing occurs before the listserv even receives th
44.
▲
by
temprature
10y ago
I don't understand what you mean. If you're saying the mailing list SMTP server could sign the message with their own DKIM key, that doesn't work because the DKIM result only gets used if the signing domain is aligned with th
45.
▲
by
temprature
10y ago
> As the mailing list software should use its own domain for the bounce addresses, the mailing list operator can set up SPF to authorize the mailing list server as an outbound server for that domain just fine This will make SPF pass bu
46.
▲
by
temprature
10y ago
> Eich wasn't fired, but he resigned because his own employees were calling for him to be fired. There was also the issue of at least one major website soft-blocking Firefox users in protest.
47.
▲
by
temprature
10y ago
Scroll through Mozilla's security announcements, pick ones at random, find the patch that fixed it and see if it ever got applied to Pale Moon. In many cases they haven't. I have pointed out many of these and argued with Pale Moon
48.
▲
by
temprature
10y ago
This can already happen with existing TLDs, for example: https://3g2upl4pq6kufc4m.onion.link DDG themselves used to link to that URL in thee instant answer box if you searched for "duckduckgo onion", and I don't t
49.
▲
by
temprature
10y ago
> And I lose half of the functionality, as RedPhone is also proprietary. The source code for the Redphone client is here: https://github.com/WhisperSystems/Signal-Android/tree/master... The source code the
50.
▲
by
temprature
10y ago
https://whispersystems.org/blog/reproducible-android/
51.
▲
by
temprature
10y ago
Signal used to use the camera intent, it was changed to use direct capture so the camera opens faster and so captured photos aren't stored in the camera roll.
52.
▲
by
temprature
10y ago
The Signal server software _does_ federate. It has had federation support since the first commit in the git history. Whisper Systems' server federated with Cyanogen's server for a while. Moxie has said it was a disaster and that i
53.
▲
by
temprature
10y ago
No, anyone can set up a server on appspot and do this with Google. The only cooperation needed from the host is apathy. They could take direct action to stop it working (Cloudflare did this a few years back by requiring that SNI matches the
54.
▲
by
temprature
10y ago
A very recent commit[0] added +968 as well, but that was made after this update was tagged. [0] https://github.com/WhisperSystems/Signal-Android/commit/7488...
55.
▲
by
temprature
10y ago
The server returns the certificate of the name given in the SNI, which is the fronted domain, not the real one.