HNHacker News
TopNewBestAskShowJobs

lemonade

56 karma · joined June 15, 2012

submissionscomments
lemonade··on Please stop serving .git to the outside world
Very useful list. None of these have anything running as a service you can try out easily, I guess that would be a Bad Idea anyway as this kind of tools might either accidentally cause stuff to happen to a server, or be used as part of an attack. I guess script youngsters will not be very much deterred by having to install e.g. a python or ruby library - but any lazy bum that drops the idea to scan some elses site is a win.
lemonade··on Ask HN: what about email is broken?
These days mail clients like Thunderbird warn you for large attachments, and prompt you to use some other solution. Even better: using the built in XMPP-client they could easily send you infinitely sized files at you@yourdomain.com - if only you would run an XMPP server on your domain
lemonade··on Ask HN: what about email is broken?
You could safely mail me, though. We use the same stack you do, plus DANE for advertising the fingerprint of the certificate to make sure the connection to the mail server is not MitM-ed. And (open)DMARC for giving feedback to mail origins about what (malicious) traffic tried to send from their domain.

Well, the technology is there and works as advertised. It is just getting people to adopt, and since people depend on hosting companies hosting companies need to upgrade. That hasn't happened. Ever. But it is not the failure of email, I would say, but a failure of the internet ecosystem that is incapable of upgrading itself because of its fragmentation.

lemonade··on Certificate Authority change at HN from Comodo to Entrust. No warning?
I think it is a best practise.

Surely, moving to another service provider is fully legit. However, a hijack with a rogue certificate (say from an undiscovered Diginotar) would not be visible to users - thereby exposing their credentials. So people use TOFU (trust on first use) mechanisms like Certificate Patrol:

http://staff.science.uva.nl/~delaat/rp/2012-2013/p56/present...

The future is of course DANE with DNSSEC, where you put information about the certificate and/or the CA in the DNS.

http://tools.ietf.org/html/rfc6698

lemonade··on Certificate Authority change at HN from Comodo to Entrust. No warning?
https://www.eff.org/observatory

"Browsers trust a very large number of these CAs, and unfortunately, the security of HTTPS is only as strong as the practices of the least trustworthy/competent CA. Before publishing this data, we attempted to notify administrators of all sites observed vulnerable to the Debian weak key bug; please let us know if your analysis reveals other classes of vulnerabilities so that we can notify affected parties."

lemonade··on Gmail now refusing to fetch using self-signed certs
Also if the certificate is published in the DNS, and available through DANE (using DNSSEC)? That would be very disappointing.
lemonade··on Ask HN: What VoIP solution do you use for remote pair-programming?
If you want a command line client, try the sip example client that is part of the SIP SIMPLE client SDK at http://sipsimpleclient.com. If you want a GUI you can try Blink (http://icanblink.com). Both work great with Sylk server (http://sylkserver.com/) on the server side.
← PreviousPage 2 of 2