Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
twleo
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
The Control Plane Was the Point: Revisiting Autofz in the LLM Era
(yfu.tw)
1 points
by
twleo
3mo ago
|
0 comments
2.
▲
by
twleo
1y ago
I don't need another desktop app... The only thing I miss is the official API for the scheduled sending feature. That's the only thing I would open the webpage app to do.
3.
▲
by
twleo
3y ago
https://github.com/epitron/mitm-adblock or https://github.com/barre/privaxy
4.
▲
by
twleo
3y ago
Looks good. I hate how IOS does, especially with certificate pinning, so I cannot use my ad-block http mitmproxy to block ads in Apps. EDIT: thanks for people clarifying that pinning is done by Apps and not by IOS.
5.
▲
by
twleo
3y ago
Open source does not magically make your software more secure. Community needs to audit the code if they are going to use it instead of trusting blindly.
6.
▲
by
twleo
3y ago
That's why we should isolate Chromium from Google. Chromium should be lead by third-party like W3C.
7.
▲
by
twleo
3y ago
Hard Pass for closed-source browser.
8.
▲
by
twleo
3y ago
Me too. The only con is that Monaco does not have bold variants. Fortunately, someone has created them! https://github.com/vjpr/monaco-bold
9.
▲
by
twleo
3y ago
Code should be self-documented. And editor should have a good mechanism to help you understand the source code. Emacs does better in this angle than Vim by far. You can find the documentation for every variable (describe-variable) and funct
10.
▲
by
twleo
3y ago
mu4e: [0] Because I live in Emacs! [0]: https://www.djcbsoftware.nl/code/mu/mu4e.html
11.
▲
by
twleo
3y ago
That is one of my questions too. Use a low entropy things (I guess user's password would be not larger than 20 characters nowadays even using password managers) to encrypt a high entropy strings (PGP key). Looks pretty weird to me.
12.
▲
by
twleo
3y ago
Hmm. I rely mores on server-side filter rules because I don't use native Mail client.
13.
▲
by
twleo
3y ago
Even if all the decryption resides in the app/web browser side, they can just silently change the code and inject some scripts to hijack the encryption routine. Although they are open-source and can be scrutinized by anybody, it does n
14.
▲
by
twleo
3y ago
For other functionality, I will say nothing because it takes time to implement features and Proton is not as big as Google. But for PGP? You should treat it seriously, considering your target customers.
15.
▲
by
twleo
3y ago
It hurts the trust mostly. If they cannot handle basic things like PGP correctly, how should I trust other part of their software. Especially they are a "Privacy-first" company. "Privacy" becomes a marketing term nowaday
16.
▲
by
twleo
3y ago
iCloud filter rules is so weak...
17.
▲
by
twleo
3y ago
There is also a 2-year old issues: https://github.com/ProtonMail/proton-bridge/issues/180 Proton makes it hard for open-source software developer to send patches and they don't care. https://g
18.
▲
by
twleo
3y ago
Until Intel let me use ECC RAM on Consumer-grade CPU, I will use AMD without second thought.
19.
▲
KeePassXC Responds to ProtonMail's Encryption Claims for Password Manager
(twitter.com)
38 points
by
twleo
3y ago
|
6 comments
20.
▲
by
twleo
4y ago
Proton should be responsible no matter it uses the third-party open-source/propriety components or not. If they decide to use third party libraries, that's their responsibility to review those libraries and include them to their c
21.
▲
by
twleo
4y ago
> Bridge is open source, and as a result relies upon open-source components I don't get it. Bridge is open source does not imply it should relies upon open-source components. > Addressing this issue at the source requires replaci
22.
▲
by
twleo
4y ago
Free-tier ProtonMail does not have the privilege to use this buggy bridge.
23.
▲
by
twleo
4y ago
FastMail takes on PGP is very reasonable. https://fastmail.blog/advanced/why-we-dont-offer-pgp/ I don't believe the encryption/key management from a company.
24.
▲
by
twleo
4y ago
I uses FastMail after I discover this serious issue about Proton. I would say it work flawlessly and their web mail client is super fast; even faster than Gmail. Besides, FastMail exists before Gmail and the people in FastMail are active st
25.
▲
by
twleo
4y ago
I will agree with you if the bridge in a open source project backed by communities. However, bridge is a paid feature used to attract more users. Also, I don't understand your point about e2ee. Bridge to proton server is also e2ee. T
26.
▲
by
twleo
4y ago
How is it a click bait? Don't forget bridge is a paid feature of Protonmail.