345 karma · joined July 28, 2011
https://twitter.com/bwbroersma https://github.com/bwbroersma
[ my public key: https://keybase.io/bwbroersma; my proof: https://keybase.io/bwbroersma/sigs/AVR1zyAY5CAHxvzuZt6pxxsgv3FcWUgJ04r_Nd5Gex0 ]
Of course 1.6% could be about everything in terms of information that is out there, excluding raw non-meta data like bit torrent, mpeg, etc. One way of 'hiding' data for the NSA would be to embed it in these raw data streams with incorrect metadata.. would definitely harder to find that.
When the browser makes a request for a static image and sends cookies together with the request, the server doesn't have any use for those cookies. So they only create network traffic for no good reason. You should make sure static components are requested with cookie-free requests. Create a subdomain and host all your static components there.
If your domain is www.example.org, you can host your static components on static.example.org. However, if you've already set cookies on the top-level domain example.org as opposed to www.example.org, then all the requests to static.example.org will include those cookies. In this case, you can buy a whole new domain, host your static components there, and keep this domain cookie-free.
http://developer.yahoo.com/performance/rules.html#cookie_fre...
But just working from (non reference) phones is dangerous too, it's so annoying to implement the volume controls with a BroadcastReceiver for the ACTION_MEDIA_BUTTON Intent (works great on Motorola's), but fails on HTC, and you should just override onKeyUp()... all (Android) phones behave differently, and not only in (screen) specs. Samsung Galaxy S (<2.2) is notorious in not following the Android specs, for example it shows the versionCode instead of versionName to the user [http://developer.android.com/guide/publishing/versioning.htm...] and if you do some (proxy) audio stream playback there is the [http://google.com/search?q=PVMFMemoryBufferReadDataStreamImp...] error with no real solutions...
The problem is, in the end, it should work on the popular devices, not the 'perfect' Android reference phones..
If you start with video (or even audio) displaying/capturing then the emulator is pretty fast useless indeed.
Then check that http://migrationsmap.net/#/SHN/departures is still broken.
The implementation is not even great either, see this screenr I made: http://screenr.com/azAs
BTW changing #hashcode based on the country looking at would be great too.
2) Well of course I notices it with my IE9 first, but I thought that BrowserLab was a nicer way to show the results. Can you verify my findings with a IE-browser?
BTW I don't see any BrowserLab non-IE problems with that https+ url: http://i.imgur.com/fOeqZ.png
Check the BrowserLab results: http://i.imgur.com/S6dQP.png
I would say that there are two options:
* They don't test their site in IE9 (nor 8/7/6) or they don't know/care.
* They are actively doing this..
And I cannot believe the first..
Any other good DNS tool that queries from multiple GEO locations?
From what I can see:
- Google Search & Google+ (https://encrypted.google.com/ https://plus.google.com/) are using a *.google.com from GeoTrust/Google Internet Authority
- Google Mail (https://www.google.com/accounts/) is using a www.google.com from VeriSign/Thawte
Ofcourse I'm also afraid that this is indeed a MITM attack against Iranian users.
With SSL certs that costs less than $15 you can expect that things cannot be thoroughly checked, however a Wildcard DigiNotar SSL cert is costing you € 750 a year (in a 4 year contract http://diginotar.nl/OnlinePrijsindicatie/tabid/1417/Default....), you would expect that these things would not be possible.
If they however hacked the root CA, it's even more scary, also Vasco (the mother company) makes virtually every Two-factor authentication used for Dutch Banking..
http://google.com/search?hl=en&q=site%3Anews.ycombinator...
(search phrase with wildcard and range in it, I didn't even knew this combination was possible)