HNHacker News
TopNewBestAskShowJobs

brainfire

387 karma · joined September 23, 2015

[ my public key: https://keybase.io/brainfire; my proof: https://keybase.io/brainfire/sigs/GVAetvr0F7CALXPskxRhI45WV4hQVqXSMYRDBg2UL7A ]
submissionscomments
brainfire··on LastPass release fix for DOM manipulation vulnerability
How else would it sync automatically?
brainfire··on Ansible playbooks for installing OpenVPN, IPsec, Tor, etc. on popular clouds
I think you'd typically want to use tags [0] for controlling which portions of an ansible playbook run, for a one-off set of tasks like this. This one in particular isn't set up to work that way though.

[0] http://docs.ansible.com/ansible/playbooks_tags.html

brainfire··on UK Home Secretary says encryption on messaging services is unacceptable
It's perfectly legal to use a fork, if you choose to take that risk. We absolutely haven't banned forks, we just urge special precautions due to the clear and obvious terrorism risks. If you want to use a fork or fork-like object (various devices that can be used for stabbing crimes like pencils or pens), just put your name on this watchlist...
brainfire··on No, I Don’t Want to Subscribe to Your Newsletter
Two step process here:

1) Subscribe "abuse@(sitedomain)" to the newsletter. I don't know if anyone still uses that convention but it reduces my frustration.

2) Add the site to my ad blocker blacklist so I don't waste my time by visiting again.

brainfire··on Wikileaks is offering tech firms CIA files first
They've always seen support and revulsion on both sides of the aisle. Your partisan retcon is dishonest and shameful.
brainfire··on USCIS Will Temporarily Suspend Premium Processing for All H-1B Petitions
That seems incorrect, given both their actual actions (including immediate and without warning discontinuation of existing visas) and rhetoric ("[T]hey're not sending their best.")
brainfire··on The Rise of the Professional Airbnb Investor
Why are you so confident there hasn't been any harm?
brainfire··on In Just 5 Moves, Grandmaster Loses and Leaves Chess World Aghast
Talking over a woman who is speaking for herself, and discussing whether she is competent without her input, is a classically sexist way to be rude.
brainfire··on Black market Blackphones get sent a kill message that bricks them
I'm saying it doesn't matter if they avoid a brand if the alternative is that they will buy a knock-off. Neither option represents any value to the actual manufacturer- avoiding negative PR from people with knock-offs might actually be preferable.
brainfire··on Black market Blackphones get sent a kill message that bricks them
So you expect them in the future to seek out the higher priced legitimate product?
brainfire··on Black market Blackphones get sent a kill message that bricks them
Why would they care about driving away the one set of people who have already demonstrated they aren't interested in buying the phone from them?
brainfire··on Automatic HTTPS Enforcement for New Executive Branch .gov Domains
Sorry, I'm not going to continue arguing with you. It's clear you don't understand the scope of what you're proposing is happening.
brainfire··on Automatic HTTPS Enforcement for New Executive Branch .gov Domains
> A more-robust system would require multiple malicious agents in various organizational silos (security, compliance, management) to fail.

Yes, and at that point the name for it is "policy". These are our own keys after all- nobody would blink an eye if they were supposed to be collected.

They're not.

brainfire··on Automatic HTTPS Enforcement for New Executive Branch .gov Domains
It would have to be one of the four people with root.

Multiply this by the number of groups that operate a .gov website (it's a lot) compounded by turnover (even more.) And account for the cat-herders needed to organize it and do it every time the private key rotates (no less than yearly for our internet-facing sites.)

There are a lot of ways you could do this on a small scale, but you really can't scale up this particular mechanism and keep it secret.

brainfire··on Automatic HTTPS Enforcement for New Executive Branch .gov Domains
I think it's safe to assume that would be impossible to keep secret. The number of people that would need to be "in on it" is huge.

I can vouch personally that at least one civilian department doesn't do this.

brainfire··on Obama Commutes Bulk of Chelsea Manning’s Sentence
It's interesting that your example is someone working for the Washington Post- that's enough for certain people to dismiss it out of hand as "fake news."
brainfire··on The Problem with AMP
It does, since 2010.

https://webmasters.googleblog.com/2010/04/using-site-speed-i...

brainfire··on Easy XMPP: What are we doing here?
So Conversations has implemented a feature that isn't in the protocol, but important enough that when the feature doesn't work, users are turned off?

Or it's part of the protocol, but design decisions lead to client interoperability problems?

Maybe there's a third answer, but both of these are problems with XMPP.

brainfire··on Easy XMPP: What are we doing here?
How is that not an XMPP problem?
brainfire··on There is no WhatsApp 'backdoor'
"The WhatsApp clients have been carefully designed so that they will not re-encrypt messages that have already been delivered. Once the sending client displays a "double check mark," it can no longer be asked to re-send that message. This prevents anyone who compromises the server from being able to selectively target previously delivered messages for re-encryption."
brainfire··on Google AMP Cache, AMP Lite, and the Need for Speed
Site operators are mad that they can't ruin our experience as thoroughly any more.
brainfire··on NeverSSL
You must be able to MitM something to get this to work.

If you can MitM connections on your network just by connecting a client to it, with no particular participation from the router, your network sucks.

Your linked site notes that they provide the router hardware.

brainfire··on I've removed all ad network code from my blog
His sponsorship banners are blocked by ad blockers, to the point of being manually added by someone to EasyList. [0]

[0] https://www.troyhunt.com/ad-blockers-are-part-of-the-problem...

brainfire··on The Real Name Fallacy
> So what else are people going to do with my home address?

Send the police to save your (non-existent) hostages: http://krebsonsecurity.com/2013/03/the-world-has-no-room-for...

Or to arrest you for the drugs you ordered (or were sent to you): http://krebsonsecurity.com/2013/07/mail-from-the-velvet-cybe...

brainfire··on Tesla footage of braking before crash ahead [video]
This is something that kills tens of thousands of people per year in the US alone- already greatly reduced by technological advances, and still falling. Excuse me if I don't shed a tear for the feelings that might be hurt among human drivers who consistently and measurably overestimate their abilities.
brainfire··on FreeDOS 1.2
Or not so old devices...
brainfire··on Excessive load on NTP servers
Well, I didn't say it was a good way ;)
brainfire··on Excessive load on NTP servers
I've never used Snapchat but I believe one of its features is time-expiring photos. If they do the expiration in the client then this may be a way to check if a user is getting around it by setting the system clock backwards.
brainfire··on CoreOS Linux Is Now Container Linux by CoreOS
That's grey on a white background. This is what it would look like if it was black (I removed the "color: rgba(0,0,0,75)" tag via chrome's inspector): http://i.imgur.com/v491foi.png

It looks like your rendering (resolution, dpi, hinting? no idea) mitigates the effects of the reduced contrast in a way that mine do not. I'm guessing that's true on their developers' systems as well.

brainfire··on My Priorities for the Next Four Years
Meh. It quibbles over points that have no impact on the actual message of the blog post regarding security.
← PreviousPage 3 of 6Next →