Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
vtlynch
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
31.
▲
by
vtlynch
10y ago
It can happen. I think right now, we are on path where it will happen. But it is simply the most expensive, inefficient, and environmentally damaging route we could take. In big cities it may indeed help reduce the need for cars, making the
32.
▲
by
vtlynch
10y ago
America's ultimate idiocy is to think the "transportation revolution" is autonomous cars.
33.
▲
by
vtlynch
10y ago
Good find. This is an excellent question. Knowing how much OpenSSL made through this is certainly important.
34.
▲
by
vtlynch
10y ago
This is simply not true. Perhaps its significantly more true for certain industries - especially Saas and similar software. But even then it is no rule.
35.
▲
by
vtlynch
10y ago
The lead feature here seems to be "buy domains with no hassle", but that already exists: Hover.com and Google Domains, to name two major ones. Perhaps your lead should be the unified domain management. Because I will be honest, at
36.
▲
by
vtlynch
10y ago
The first date that Archive.org has that page is August 2015, after heartbleed. Do you know for sure that they offered this service before heartbleed?
37.
▲
by
vtlynch
10y ago
So then why are you worrying about how it could have actually happened.
38.
▲
by
vtlynch
10y ago
>We should stop letting journalists make a big deal of companies that don't have infinite growth Im not sure if thats the main audience pushing the narrative of growth. There is an industry that created the "growth hacker"
39.
▲
by
vtlynch
10y ago
Apple will continue to trust existing certs from WoSign (provided they are CT logged). New certs will not be trusted. mac OS will make this decision by first looking at signatures. It will receive the "end-entity" certificate (a c
40.
▲
by
vtlynch
10y ago
Couple notes for people less familiar with the Internet PKI/CA industry: 1. WoSign (who also owns StartCom) violated all sorts of industry standards. The worst of them was circumventing the SHA-1 deprecation by backdating an SSL certif
41.
▲
by
vtlynch
10y ago
Which is how they have always measured it, as far as I am unaware. While you may not like the measurement, this allows you to make actual comparisons to past years data, instead of comparing two different metrics.
42.
▲
by
vtlynch
10y ago
Can you elaborate? I am not familiar with the specifics of Diebold's problems and how a voluntary audit (which they could choose to keep private and use for internal assessment) would hurt them more than not knowing the risks.
43.
▲
by
vtlynch
10y ago
>In fact if every CA could take a full code security audit and provide complete certificate transparency in the manner proposed Given the risks that screwups have to their business, I would think CAs would VOLUNTARILY do this.
44.
▲
by
vtlynch
10y ago
Can you explain why there would be 100% salary overhead? This seems quite high as a non business owner/operator.
45.
▲
by
vtlynch
10y ago
Its actually 2.06m for 10 employees: https://twitter.com/0xjosh/status/778283999609298944
46.
▲
by
vtlynch
10y ago
So someone doing something is automatically attributed to the free market? Im not sure that is how it works.
47.
▲
by
vtlynch
10y ago
>Most 16 year olds are just using their phones to send silly snaps to their friends and watch porn. Because most 16 year olds dont come from a family with such a wealthy (both in money and opportunities) background.
48.
▲
by
vtlynch
10y ago
EV certificates may improve a user's awareness of a spoofed page, but cannot do anything to make it more technically difficult to execute. Providing an HTTPS login with an otherwise HTTP site is vulnerable to redirection to HTTP or to
49.
▲
by
vtlynch
10y ago
>And yet, nobody can fix these problems because lobbyists are increasing the barrier to entry under the guise of safety. that's a shame. how could we fix this? perhaps... regulation against lobbyists?
50.
▲
by
vtlynch
10y ago
Mixed Content is when your site is serving some of the page's content over HTTP, and some over HTTPS. This is a problem because if any piece of content is served over HTTP, browsers will count the connection as non-secure and will no
51.
▲
by
vtlynch
10y ago
That's great :) Just how it should be.
52.
▲
by
vtlynch
10y ago
It is certainly common practice to not include lunch as work time in the US. But I think that is unfair to the employee. In the US almost all Low-skill jobs that pay by the hour dont count lunch as work time. At those jobs you usually expli
53.
▲
by
vtlynch
10y ago
It should, yes.
54.
▲
by
vtlynch
10y ago
>I think it's mostly supply and demand, timing and where you live. But those are the factors we rarely talk about. I think those are the exact factors constantly mentioned by the HackerNews community.
55.
▲
by
vtlynch
10y ago
Some in the industry, including some CAs (Certificate Authorities), believe that issuing certificates to "malicious" websites should be against the rules of the CA/B Forum, the industry body that sets guidelines for CA behavi
56.
▲
by
vtlynch
10y ago
Washington Post. Buzzfeed. The Guardian. New York Times still dosent have HTTPs.
57.
▲
by
vtlynch
10y ago
Yes, I forgot about Adam Smith's treatise about online review systems.
58.
▲
by
vtlynch
10y ago
Agreed. There is real irresponsibility in choosing this name. Thinking that this wont be used against the encryption community is naive and short-sided.
59.
▲
by
vtlynch
10y ago
This will likely never be the case due to how HTTPS actually works. As someone else stated, HTTPs is HTTP + TLS. The "s" in HTTPS is for "secure", and TLS provides that security. TLS is a evolving standard which is updat
60.
▲
by
vtlynch
10y ago
Suggesting that the volume of accusations and eyewitness accounts that have been made against Appelbaum may be "false accusations" is a shameful thing to do.
More ›