HNHacker News
TopNewBestAskShowJobs

gellerb

61 karma · joined April 24, 2014

submissionscomments
gellerb··on Security alerts on GitHub
One can use sourceclear.com for Composer.
gellerb··on Security alerts on GitHub
One can use sourceclear.com for Python support.
gellerb··on Subresource Integrity
Login and inspect the home page afterwards. http://imgur.com/bwUHgcT
gellerb··on Subresource Integrity
SRI allows one to specify multiple hashes. In other words, to prevent this particular mismatch, one could include the hash of the new resource as well as the previous valid hash.
gellerb··on OpenSSL Security Advisory
Use Chrome Canary
gellerb··on Soylent 1.5 Has Arrived
It unfortunately includes carrageenan.
gellerb··on Is Your Site HSTS Enabled?
ssl:endpoint add-on
gellerb··on Is Your Site HSTS Enabled?
The HTTP 2.0 spec[1] mentions "Implementations of HTTP/2 MUST support TLS 1.2 and it appears Chrome will implement HTTP/2 via TLS only (http://volgarev.me/blog/75094931827).
gellerb··on Is Your Site HSTS Enabled?
Elastic Loading Balancing for AWS customers & Heroku allow for perfect forward secrecy and Akamai customers can expect ECDHE in Q3 of this year.
gellerb··on Is Your Site HSTS Enabled?
ds9, yes, "site certs the browser doesn't trust a CA for" is more accurate. You can find the exact details of HSTS and self-signed certs in the draft in section 11.3[1]. I've updated the post to hopefully be more clear.

[1] http://tools.ietf.org/html/draft-ietf-websec-strict-transpor...

gellerb··on Is Your Site HSTS Enabled?
In Safari one can delete ~/Library/Cookies/HSTS.plist
gellerb··on Is Your Site HSTS Enabled?
Yeah. I noticed that paypal.com has a max-age of 4 hours.