HNHacker News
TopNewBestAskShowJobs

bwblabs

345 karma · joined July 28, 2011

Mail me@: bw AT broersma DOT com

https://twitter.com/bwbroersma https://github.com/bwbroersma

[ my public key: https://keybase.io/bwbroersma; my proof: https://keybase.io/bwbroersma/sigs/AVR1zyAY5CAHxvzuZt6pxxsgv3FcWUgJ04r_Nd5Gex0 ]

submissionscomments
bwblabs··on Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited
Microsoft never had this issue: "For security reasons, data URIs are restricted to downloaded resources. Data URIs cannot be used for navigation, for scripting, or to populate frame or iframe elements." - https://msdn.microsoft.com/en-us/library/cc848897(v=vs.85).a... (also a note of http://caniuse.com/#search=datauri)

It's a bit weird from a security point of view that self-XSS is protected in Firefox & Chrome (https://bugzilla.mozilla.org/show_bug.cgi?id=994134 & https://bugs.chromium.org/p/chromium/issues/detail?id=345205), but navigation data-uris are not.

bwblabs··on Caddy – a modern web server (vs. Nginx)
The code is mainly written in C (https://github.com/h2o/h2o) with some Perl testing. The Mruby for small (header/push) logic isn't that bad, and not bad in terms of performance either (https://h2o.examp1e.net/configure/mruby.html), although I'm also not a Ruby fan.
bwblabs··on Caddy – a modern web server (vs. Nginx)
Any experiences with running h2o on production sites? The documentation is a bit lacking sometimes, luckily the code is well written.
bwblabs··on RustgreSQL
A port to a way more strict type and memory safe language would be great, but as Craig Ringer from 2ndquadrant replies: the postgres project is pretty conservative & this could only happen in an incremental way.
bwblabs··on Show HN: Rocket – Web Framework for Rust
Indeed way cleaner than Iron in terms of parsing query (int) arguments and JSON post data (BodyParser).
bwblabs··on Software Engineering Internship Amazon Interview Experience
And lots of contradicting privacy claims:

"Secure Exam Proctor Exam Environment: You can generally utilize the Secure Exam Proctor for taking a proctored examination without revealing any Personally Identifiable Information about yourself. The types of information collected depend on the exam settings and can include video, audio, desktop recording, and websites visited. The aforementioned data is encrypted and will not be used by Proctorio in anyway. This information may be used by "Authorized School Officials" to review the actions of Students during exam administration. Proctorio may collect additional information set forth below in the "Aggregate Information" and anonymous information. Aggregate and anonymous information will be used to improve the quality of the Secure Exam Service. Note: Proctorio utilizes zero-knowledge encryption to keep your information safe."

bwblabs··on Encrypted libraries leak lots of information in Seafile
I actually use SeaFile for some clients (since OwnCloud doesn't do client side encryption at all), after Wuala shut down last year. I actually was disappointed by the security and features too (https://forum.seafile-server.org/t/encryption-the-pro-added-...), you cannot securely share sub trees/dirs like in Wuala (with their Cryptree).

Is there a better FOS alternative?

The Wuala service did had a lot's of deadlocks, either on server or the client side, and customer service was not done secure: please send over the log files (included file names) or the client storage block, etc...

bwblabs··on UltraDNS Server Problem Pulls Down Websites, Including Netflix, for 90 Minutes
And that's even without 'DNSSEC and IPv6 support', 'Regional Routing' and 'DNS Load Balancing (where available)', that's only available for 'UltraDNS Enterprise'... (I'm running my own (Power)DNS, after EveryDNS was bought by DYN and they didn't grandfathered old plans, charging per domain, which made it extremely pricey)
bwblabs··on UltraDNS Server Problem Pulls Down Websites, Including Netflix, for 90 Minutes
Running my own DNS servers. But having issues with clients using Rackspace Apps - hosted email (still down due to UltraDNS).

Would there be anything against using multiple large anycast DNS providers?

bwblabs··on Show HN: Private Forms: PGP-Encrypted Webforms for Privacy-Conscious Receipients
That's called lean right? ;)

It's only something worth solving if it hits the log files.

bwblabs··on Show HN: Private Forms: PGP-Encrypted Webforms for Privacy-Conscious Receipients
I cannot try anything before entering my CC number (and paying, no free month or anything), nor finding any detailed information about the setup (apart from 'public/private key client side JS'). But the site/server/data center security probably does matter if the JS is hosted at their site / servers.

Edit: See link below: https://privateforms.net/embed/rNKlzL

So you get jquery, moment, bootstrap + datatimepicker, kbpgp and a few lines of glue to use kbpgp to send and XMLHttpRequest, basically:

    kbpgp.KeyManager.import_from_armored_pgp({
        armored: '-----BEGIN PGP PUBLIC KEY BLOCK-----\n' +
                 /* key */
                 '-----END PGP PUBLIC KEY BLOCK-----'},
        function(err, keyManager) {
            kbpgp.box({msg: '**form=data**', encrypt_for: keyManager},
            function(err, encryptedString, encryptedBuffer) {
                //send result;
            }
        );
    });
bwblabs··on PostgreSQL 9.5 New Features with Examples [pdf]
Can't wait to use the new JSONB operators of 9.5, e.g.:

    SELECT '{"k1":"v1"}'::JSONB || '{"k1":"v2","k2":true}'::JSONB
=> {"k1": "v2", "k2": true}

In 9.4 this is the 'best way' I know:

    SELECT
        ('{' || STRING_AGG(
	    '"' || COALESCE(j2.key, j1.key) ||
	    '": ' || TO_JSON(COALESCE(j2.value, j1.value)
        ), ',') || '}')::JSONB
    FROM JSONB_EACH('{"k1":"v1"}') j1
    FULL OUTER JOIN
    (SELECT * FROM JSONB_EACH('{"k1":"v2","k2":true}')) j2 ON j1.key = j2.key
bwblabs··on Postgres CLI with autocompletion and syntax highlighting
Also autocomplete doesn't seem to work with an alias of a quoted table, in case of using keywords as table names or having casing in names, e.g.:

    SELECT * FROM "access" a WHERE a.
But it's a nice tool! (:
bwblabs··on Self-control improves your prospects, but it may harm your health
Article is based on Self-control forecasts better psychosocial outcomes but faster epigenetic aging in low-SES youth (http://www.pnas.org/content/early/2015/07/08/1505063112.full...), someone with access who can check N and the significance of change of the groups?
bwblabs··on The Vegetable Detective
I stopped reading after this sentence:

"One kale sample reported thallium at 1.14 ppm, nickel at 20 ppm, and aluminum at 120 ppm. (As has been widely reported, aluminum is often suspected as a cause of both autism and Alzheimer’s disease.)"

It's pretty controversial claim that aluminum is related to Alzheimer's disease http://www.webmd.com/alzheimers/guide/controversial-claims-r...

bwblabs··on Ask HN: SSL certificates
Use 2048 bits, not 4096. I'm kind of paranoid and always try to use the highest recommendations, HSTS, all-SSL, etc. But in terms of SSL connection setups / second, your CPU will be the bottleneck, and having 4096 bits will limit you to about 1/4 of the connection setups / second that 2048 could have handled. So if the site has low traffic and a enough CPU resources, it could be ok, but if you ever need to handle a lot of connections: use 2048 bits! (I learned the hard way ;)
bwblabs··on What Happens When You Try to Photoshop Money
Would be funny to include http://en.wikipedia.org/wiki/EURion_constellation on websites, so you cannot make screenshots with Photoshop ;)
bwblabs··on What Happens When You Try to Photoshop Money
Another trick is to invert the colors and then import it to Photoshop & invert it back.
bwblabs··on Ask HN: How to report/revoke malicious Comodo code signing certificate?
Ok, just got a (signed) message back from Robin Alden (CTO): "This certificate has been revoked.", in the CC was: signedmalwarealert@comodo.com , so that seems to be the (internal) email address.
bwblabs··on Ask HN: How to report/revoke malicious Comodo code signing certificate?
Yes, by email: abuse@comodo.com (the only non sales address I could find), no response yet.

I looked at the Twitter & Facebook but they looked pretty dead. No replies @comododesktop (https://twitter.com/comododesktop/with_replies), idem for FB account (https://www.facebook.com/ComodoHome), no replies on the comments I see on FB.

Also both FB & Twitter are about non CA-products, so I was hoping for a security contact form, email address, chat or phone line..

bwblabs··on Know How To Roll Your SSL Certificates
Ever heard of StartSSL Free?

https://www.startssl.com/?app=39

bwblabs··on Know How To Roll Your SSL Certificates
1) monitor the complete certificate chain

2) indeed have a backup certificate ready (might be non EV), this is especially a must if you use HSTS [1] (which you should use BTW) it is actually a (low priority) government recommendation (B5-6) in The Netherlands [2], but that might have something to do with the government heavily using DigiNotar which got compromised and had it root certificates revoked by Microsoft which caused some communication issues..

[1] https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security

[2] https://www.ncsc.nl/binaries/nl/dienstverlening/expertise-ad... (in Dutch)

bwblabs··on Know How To Roll Your SSL Certificates

  Process
  - Know where your key is
  - Know how to generate a new CSR from that key
It's adviced to use a NEW private key, in case there was a private key compromise you didn't know about.

Also see https://www.ssllabs.com/downloads/SSL_TLS_Deployment_Best_Pr... (point 1.2).

BTW there is NO reason to regenerate the CSR if you reuse the private key.

bwblabs··on Guacamole – HTML5 Clientless Remote Desktop
https://github.com/glyptodon/guacamole-client/search?q=video... By looking in the code I think they use Canvas, streaming video would be interesting. Looking at guacamole-common-js/src/main/webapp/modules/Tunnel.js I think they use WebSockets with a XMLHttpRequest fallback?
bwblabs··on Google Domains
It was one of the few lists I found. Although the url redirects to an url containing 'deployment-2012-02-25-en' the page actually states 'Last updated: 27 May 2014', so it's not so out of date.

    If your registrar currently accepts DS records, please 
    send an email with subject "DNSSEC REGISTRAR UPDATE" 
    and body containing company name, country location, URL,
    what TLDs you accept DS records for, whether your Web
    interface supports DS records, whether you provide 
    DNSSEC signing services to dnssec@icann.org and the 
    Security team will add your registrar to this DNSSEC
    page.
bwblabs··on Google Domains
Correct, no .io support.
bwblabs··on Google Domains
Domain name registrar like Hover, NameCheap, NameBright and NameSilo still do not yet support DNSSEC (nor have an ETA for it!). Here is a list of DNSSEC supporting registrars: https://www.icann.org/en/news/in-focus/dnssec/deployment

Based on pricing ($9.99/.com) and a growing irritation with GoDaddy, I finally moved my domains to Dynadot:

https://www.dynadot.com/

They have a (custom) 2FA app and 2FA SMS. BTW this friend referral https://www.dynadot.com/?s9N6j7d9G8B07i73 gives you & me $5 after purchase.

bwblabs··on $1.99 SSL certificates offered by Namecheap
Cheap providers like NameCheap, NameBright and NameSilo do not support DNSSEC. Here is a list of DNSSEC supporting registrars: https://www.icann.org/en/news/in-focus/dnssec/deployment

Based on pricing ($9.99/.com) and a growing irritation with GoDaddy, I finally moved my domains to Dynadot:

https://www.dynadot.com/

They have a (custom) 2FA app and 2FA SMS. BTW this friend referral https://www.dynadot.com/?s9N6j7d9G8B07i73 gives you & me $5 after purchase.

bwblabs··on Lenovo ThinkPad and Edge battery recall
What's always wrong with LiPo batteries: under some condition the LiPo pack is damaged and it will start a fire or 'explode'.
bwblabs··on Lenovo ThinkPad and Edge battery recall
For some reason I just got the email about the recall today, I guess they imported some email addresses since the footer notes 'You were added to the system April 21, 2014.'.

If you have multiple batteries you can deinstall the program and run it again, since it caches the battery serial number (also after reboot).

-----

From the FAQ:

Q4. Do I have to return my defective battery?

Answer: No. However, by accepting a replacement battery you are committing to recycling your battery in an approved manner.

Q5. If my battery is recalled, how long will I have to wait for it?

Answer: Orders will typically be processed and shipped within 3 business days. Delivery times will vary based on country.

← PreviousPage 3 of 4Next →