HNHacker News
TopNewBestAskShowJobs

johannh

593 karma · joined November 13, 2012

submissionscomments
johannh··on Total Cookie Protection
Both the more technical blog post as well as the MDN page are linked shortly after that paragraph.
johannh··on Total Cookie Protection
No, there’s no allow-list, you get the same heuristics as described on that MDN page.
johannh··on Total Cookie Protection
Yes, it’s essentially that, FPI with workarounds for common breakage. You should switch from FPI, this is essentially another take on FPI by some of its original developers, so it should have fewer issues overall, not just site breakage.
johannh··on Total Cookie Protection
(I’m one of the developers of this feature and co-author of the blog posts)

This is a great question and I’m glad you found the answer, you probably understand that for many blog posts we avoid going into too much technical detail.

To answer your final question, there is no hardcoded allow-list for State Partitioning. The heuristics as described on MDN are accurate.

johannh··on Firefox 72.0
If your users are clicking a button then it should actually show the permission prompt, unless you're losing the user interaction somewhere in the callback (by doing something async first)

https://hacks.mozilla.org/2019/11/upcoming-notification-perm...

This is a frequent "mistake"/issue however, and we're working on a mitigation for it.

johannh··on Servo Nightly Builds Available
Congrats! Please note that Servo is a work in progress that is still lacking some modern browser security features, so enjoy responsibly.

See also https://github.com/servo/servo/labels/A-security

johannh··on Slack was hacked
https://en.wikipedia.org/wiki/Egg_of_Columbus
johannh··on Why HTTPS Everywhere isn't on addons.mozilla.org
I find it ironic if banks and post offices are using combination locks as advertised security measures but the people selling those install steel doors on their storefront.
johannh··on Why HTTPS Everywhere isn't on addons.mozilla.org
True, I'm not surprised at all. HTTPS Everywhere-like functionality should be integrated into browsers and not a downloadable extra, tricking people into feeling fully secured.
johannh··on Why HTTPS Everywhere isn't on addons.mozilla.org
> AMO doesn't do any code signing for extensions, so they're only protected by HTTPS. As we saw with Heartbleed, SSL private keys can be compromised.

I find it quite ironic that HTTPS Everywhere is arguing HTTPS is not safe enough to offer them a reasonable guarantee of integrity.

johannh··on JavaScript Hacks for Hipsters
This was originally published a year ago in this blog post:

http://berzniz.com/post/68001735765/javascript-hacks-for-hip...

Makes for a nicer read than slideshare imo.

johannh··on Wanna know what product your competitor is working on? Try Slack
True, but it still feels like the right thing to do.

I'd like people do be responsible when they discover a serious flaw in my programs, so I'll try to be responsible when discovering one in theirs.

Also Linus basically insults anyone for being alive.

johannh··on Wanna know what product your competitor is working on? Try Slack
This is something that could definitely have been reported to Slack before disclosing it publicly. Maybe he did that, but it's not mentioned in the blog post so I assume he didn't.

It's just a nice thing to do and they might reward you for it. You can still post it on your blog after they released a fix.

johannh··on Intern at a YC Company
What if I'm not from the US and require a work permission? Any chance of applying?
johannh··on Show HN: Google Music for Mac
Looks promising! May I ask why you forked from the original (https://github.com/JamesFator/GoogleMusicMac)? Looking at the commit history it seems to be under active development.
johannh··on MongoDB is to NoSQL like MySQL to SQL - in the most harmful way
So what exactly makes Mongo such a bad implementation (apart from things that were already fixed)?

I don't mean to defend MongoDB, i'm genuinely interested in finding a better NoSQL DB. I just usually get to hear the same "Fisher price" bashing without any real arguments.

johannh··on MongoDB is to NoSQL like MySQL to SQL - in the most harmful way
So he's saying MySQL is bad, and MongoDB (because of a statement on their home page) is kind of like MySQL, so MongoDB is also bad. Also there was some article about scaling it to "only" 100GB which means it damages NoSQL as a whole in the "most harmful way".

Sorry but I don't really get the reasoning.

johannh··on Life in the Universe
Its his choice how he wants his works to be distributed. You can still link to it. And if you want to translate it just ask him.