19 karma · joined February 10, 2017
I just tried it with this tab and not only did I get full back history but it also had my partially entered comment in this form.
Edit: holding ctrl while using back and refresh also duplicate a tab with predictable behaviour.
With that said, what's the threat model for the first point? Is localhost interception a serious risk?
With that said I'm just parroting some other comments I've seen on this topic in other contexts, so I'm asking the question genuinely.
In languages with exceptions, the program will crash as soon as you try to use that value (rather than when you try to unwrap it), e.g. the infamous null pointer exception. Copying bad sample code in this case might result in code that is difficult to debug because a null value might be handed off several times before something tries to dereference it.
In languages that expect but do not enforce that you check the validity of the value (like C) you'll just get undefined behaviour that will hopefully cause your program to segfault when you try to use the value, but who knows what will actually happen? Copying bad sample code in this case will cause a security vulnerability.
Copying "bad" sample rust code (using unwrap) will cause a safe crash with maximum locality, for simpler debugging.
Terraform does support a number of out of band state management backends that I would prefer to use, but none of those backends support encryption at rest. Hopefully hashicorp will roll out support for vault as a backend at some point...
The technology is available for any CA, existing or new, to copycat.
And if they don't want to use the open source reference implementation, they can cleanroom an ACME server that works with all the existing clients that work with letsencrypt.