Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
tokenizerrr
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
tokenizerrr
9y ago
I've used neo4j before and it likes to consume a lot of memory.
32.
▲
by
tokenizerrr
9y ago
You should have done that ages ago. Essentially any anti-cheat software is malware that spies on you.
33.
▲
by
tokenizerrr
9y ago
I'm generally not worried about HTTP connections. Any random hyperlink I click on can produce those. However Ajedi32 made some very good points that being able to MITM HTTP connections can cause lasting issues, even for pages where the
34.
▲
by
tokenizerrr
9y ago
It doesn't need it. You can always just nmap your network, find its lan ip and connect straight through that over http. But that's not very user friendly, hence the dyndns.
35.
▲
by
tokenizerrr
9y ago
That is a generalization. You certainly do with many networked appliances. And I prefer this, since that means connectivity with the device is not dependent on some cloud service. And that some cloud service can't control my appliance.
36.
▲
by
tokenizerrr
9y ago
User's webbrowser is visiting the appliance which resides on LAN. Webbrowsers require certificates signed by a CA.
37.
▲
by
tokenizerrr
9y ago
Yeah, would be nice if ACME with DNS validation was widespread. But right now it's still not viable due to Let's Encrypt's rate limits.
38.
▲
by
tokenizerrr
9y ago
> under their certificate authority delegation to *.coffeepot.com. Where can I get a certificate with the CA flag set for mydomain.com? I did not know this was an option for mere mortals.
39.
▲
by
tokenizerrr
9y ago
Interesting, and point well made. Thanks!
40.
▲
by
tokenizerrr
9y ago
I define insecure as a machine/user getting compromised. Malware, phishing and the like. Anyway, your example is a good one as to why it's weird for Chrome to label these things as insecure.
41.
▲
by
tokenizerrr
9y ago
Actually, now that I think about it, with the Let's Encrypt DNS challenge this might actually be viable... That's pretty recent, though. And they rate limit harshly. I was thinking about the HTTP validation, which would definitely
42.
▲
by
tokenizerrr
9y ago
Unless I'm misunderstanding they did that by partnering with a CA. Becoming a semi-trusted CA themselves. This is not an option for most organizations.
43.
▲
by
tokenizerrr
9y ago
What app store? Which OS? Do you now suddenly have to write software for all OSes to install the certificate? Something that you didn't even have to think about doing before. The entire reason you went for a webui to begin with.
44.
▲
by
tokenizerrr
9y ago
Please tell me how to painlessly install a CA on a user their computer? Imagine buying a network connected coffeepot. You plug it in and you're done.
45.
▲
by
tokenizerrr
9y ago
All of that is bad, none of it is a security issue. Privacy, sure. But not security. And the article specifically shows that Google is planning to mark example.org as insecure. Which it's not.
46.
▲
by
tokenizerrr
9y ago
> Can you not just create a certificate and push it to the system as a trusted cert? If you were to control the user's machine, yes. But imagine you bought a shiny new internet connected coffee pot. Once you turn it on it does the f
47.
▲
by
tokenizerrr
9y ago
Yeah. You could also just host it literally anywhere and post an URL in the comments here. By that logic clicking on hyperlinks is equally insecure.
48.
▲
by
tokenizerrr
9y ago
So it's a http2 vs http1 benchmark. Not a http vs https benchmark?
49.
▲
by
tokenizerrr
9y ago
That's not a security issue if the site doesn't ask for user input, though.
50.
▲
by
tokenizerrr
9y ago
It's impossible to get a valid SSL certificate for an appliance running within someone their lan, without having to open ports. And opening ports would make the appliance even more vulnerable to attack.
51.
▲
by
tokenizerrr
9y ago
I don't understand what is insecure about http://example.com ? It's a simple static site which does not allow user input.
52.
▲
by
tokenizerrr
9y ago
1. You don't have to monitor your cronjobs. They'll send you an email when they produce output. 2. Let's Encrypt will send you an email if your certificate is going to expire in a month. This will normally never happen, since
53.
▲
by
tokenizerrr
9y ago
Running software against my own IP space is considered mean?
54.
▲
by
tokenizerrr
9y ago
"Stop looking at my house from the public street! It's not authorized!"
55.
▲
by
tokenizerrr
9y ago
As far as I know all you have to do is configure your ~/.ssh/config properly, and then use the hostnames set there. Same as regular old OpenSSH. Just don't opt into the Paramiko control scheme, which isn't used by defaul
56.
▲
by
tokenizerrr
9y ago
If you choose to have your hand cut off because you think it would be awesome, I'd hope your doctor would refuse to do it.
57.
▲
by
tokenizerrr
9y ago
As far as I know it's in the tutorial they insist you do upon first enabling swiping edit: Don't actually see a tutorial in the app. Maybe I'm confused with another app such as Swype, but the same technique seems to apply to
58.
▲
by
tokenizerrr
9y ago
> I frequently swipe "See you soon." It always, always renders as "See you son" This works fine for me with GBoard. Are you drawing a little circle on the o to indicate you want the double letter?
59.
▲
by
tokenizerrr
9y ago
Please explain why you hate it?
60.
▲
by
tokenizerrr
9y ago
It had a trailing >, https://github.com/junegunn/fzf
More ›