282 karma · joined December 29, 2015
Holding off on the purchase after that event is the least they could've done.
Yes, anything that (re)terminates TLS will be able to - including this - and there is no way around it short of hosting it on-prem.
Marketing it as end-to-end security the way the author is doing is ... wrong.
It cannot be secure end-to-end, as your edge location is quite literally performing a MITM. That aside:
How are you validating the TLS cert that the origin presents?
Going by the info on your website, the possibilities are as follows:
Scenario 1: The SAAS provider presents a TLS cert not valid for customer-domain.com when accessed as customer-domain.com
Scenario 2: The SAAS provider presents a TLS cert valid for customer.saasprovider.com when accessed as customer.saasprovider.com
Assuming scenario 1, you would need to validate the certificate out-of-band as the traditional trust chain does not validate for the given domain. Assuming scenario 2, you would need to rewrite the URLs from customer.saasprovider.com to customer-domain.com to prevent the users from following generated resource URLs to the origin domain. Or am i missing something?
So this is routing plain text http for most of the connection and at the same time giving the managed edge location direct access to the traffic and a valid tls cert for the domain? Isn't that mostly snake oil then, as the secure connection never originates from the target service?
Aegis' design looks a lot less dense than AndOTP on the screenshots, though it seems to be widely recommended. I'll have to check what that's all about
if anything, this should be a toggle- if only an opt-out toggle.
fwiw, you can install a linux system including an entire graphical stack with web browser and mail client in that space, twice.
<body bgcolor=0>
This is a common technique used for tls-termination and management of 'virtual hosts', among other things.
The mentioned "issues" don't seem to be Sinatra-specific, but rather about the authors shallow understanding of the topic as a whole
> alias www='python -m SimpleHTTPServer 8000'
that'll only work on systems where python is python2
> alias speed='speedtest-cli --server 2406 --simple'
speedtest-cli automatically selects a server, invoking it without any opts at all is perfectly fine
> alias ipi='ipconfig getifaddr en0'
the interface name is not predictable, nor portable - `ip a`
Most if not all of these aliases seem rather pointless after all
'Confirm, with appropriate supporting data, that their bid requests made with QUIC are not anti-competitive, and justify why bid requests are being used by a new and opaque request protocol under conditions where competitors are bound to use TCP with its extra round trip overhead.'
Which just looks like they have no idea what they're talking about.
Things QUIC isn't:
- Limited to Google(rs)
- "Opaque" as-is, it's just that the JS APIs are bad. It's still experimental software after all.
The problem is not QUIC, it's the request API the adblockers use to filter the content. QUIC is a fast, documented protocol used by way more people and organisations that aren't Google.
Chrom(e|ium) will suggest to navigate to http://google if you're opening google.com