109 karma · joined December 27, 2011
http://www.panic.com/blog/coda-2-5-and-the-mac-app-store/
PS-I don't think they will switch to ARM. The new USB-C MacBook is very power efficient.
[1] http://windowsitpro.com/systems-management/making-windows-cl...
A cool realtime clock that shows the offset the GPS satellites work from, which do not include leap seconds.
PS-PCalc was the first notification center app I enabled on iOS 8 and I actually use it.
PS-I have never needed to buy anything back from my old book wish list.
https://www.google.com/maps/@30.1199335,-93.7106707,1513m/da...
Because the url past the domain name is not for the user to be messing with most of the time. We the developers control everything to right of the first single slash. Maybe if it was hidden then it would force us to do a better job showing the users where they are in our sites with breadcrumbs and menus and at the same time keep them from trying to poke around in places where they shouldn't be. I think this is a perfect opportunity to open up our minds and build better UI inside the frame.
I respectfully disagree that it is less secure. Showing only the domain will reduce the clutter to where the user can determine which domain they are typing their password into. I say can because in the phishing example the user would be unable to determine the domain name.
The full url is only a click away. A click that is going to be happening anyway when the user wants to copy the URL.
I welcome the clean look as user. As a developer I will re-enable the full URL on my development machines, but not on my family members machines.
repurposed an old flag
The flag was not OLD since there was still code in the CURRENT code base which COULD use it. # - Apache 2.4 PFS & BEAST attack Safe /etc/apache2/mods-enabled/ssl.conf
SSLProtocol -ALL +SSLv3 +TLSv1 +TLSv1.1 +TLSv1.2
SSLCipherSuite ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES256-SHA:!RC4:HIGH:!MD5:!aNULL:!EDH
SSLHonorCipherOrder on
SSLCompression off
# - HSTS Apache directive to force SSL (.htaccess or per site in control panel)
Header always set Strict-Transport-Security "max-age=15552000"
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule (.*) https://%{HTTP_HOST}%{REQUEST_URI} [NC,R=301,L]