It's even worse than that though, enter 'myintranetsite' and hit return, and you end up on a Google search page. Instead you have to enter 'http://myintranetsite'
If you prefix with "http://", no requests are made to Google (except "h", "ht", "htt", "http", and "http:")
This seems surprising to me. Can you back up this claim?
- https://support.mozilla.org/en-US/kb/search-suggestions-fire...
I guess I just had a different interpretation of "no requests are made to Google". It seems "no requests" was intended to be "no search suggestion requests" and not "no requests that leak this information to google".
What's the point of sending those characters?
- https://support.mozilla.org/en-US/kb/add-search-bar-firefox-...
it would be nice if the input string contains a whitespace, it will perform the search engine query for you automatically, or allow some custom regex expression to determine whether to query search engine.
[1] https://support.mozilla.org/en-US/kb/add-search-bar-firefox-...
It's been nice to use the Firefox setting to have a separate search bar. Your address bar will show more results from your history, which is often what I actually need. Then you can just hit the down arrow to select "Search with x" options.
My only minor quip is that your default search engine will be last in the list.
The only way to legitimately use tools like these from work are if they pass rigorous vendor assessment processes and rock solid contracts in place covered by nine figure E&O policies.
Re: third party libraries, yes absolutely.
Honestly, I find it super annoying when someone is fine with me sending them a link to kibana to which the access details are in slack to see a API key but have an issue with me sending the API key to them via slack. The whole we don't trust slack but we'll send customer data to each other via it, have all of our secret business info on it, but the API key for an internal service that just outputs public info, that's too dangerous.
Oh, and then there are the people who store everything on vault or something and then give out the password willy nilly. Mate, if it's got to be encrypted then we shouldn't be giving it out to everytone. If it's got to be given out to everyone then it's not senstive data, it's just private.
For most businesses, the main thing you need to keep safe is your database.
In a project I'm working on we encrypt our secrets with git secret before sending them to GitHub.
When we want to quickly share unencrypted secrets between us we drop them as files into a server we access over ssh. That should be OK.
The gist of it is that if a secret is in clear on a server outside our organization it's not secret anymore. And yet my customer trust their cloud provider (Google) with their data.
edit: typo