166 karma · joined August 8, 2010
This is why the company I work for created PanicMode (https://chrome.google.com/webstore/detail/panic-mode/lamdafc...).
PanicMode is ridiculously simple extension. Once activated, it will swap HTTP for HTTPS without leaking even a single packet. Not even pre-flight requests are spared.
PanicMode is not good for general purpose browsing mainly because 99% of the site break badly, i.e. they do not support SSL at all. That is very telling and sad reality. The way I use it is with profiles. I have a bunch of chrome profiles that I use for different purpose. One of my profiles is just for social browsing - facebook etc. I have another one for company stuff. Those profile have panic mode installed and activated. Because I care about security in those profiles I don't mind if I click on a facebook link and it doesn't open up because at least I know that I am protected against side-channel attacks.
It is a very simple mechanism but works well when used effectively.
Web technologies is for UI what opengl is for gaming.
And btw, iOS development is easy for as long as you do not want to customize things. Once you start changing the standard controls you are entering the land of no return.
Now compare this with web technologies which are designed to be customizable.
However, looking beyond this challenge, the idea is still cool and having an AI assistant to sort out your inbox will be certainly a breakthrough technology. Besides web, email is perhaps one of the greatest innovations of the 20th century but it needs to be brought in the 21st, i.e Email 2.0.
We just published this tool to test for Shellsheck. https://suite.websecurify.com/market/shellshock
Do a scan over before it is too late.
I would love to see firefox converging with NodeJS but given mozilla's attitude towards developers lately I seriously doubt that it will ever happen.
Firefox has a very rich history and the technology is fantastic but sadly it is not made to be easy to the developer.
I think it is time for iOS developers get their strategy checked up. I know a lot of people want to get their app/game to a lot of people but unless you have evidence that you app is reaching millions of people, it is not going to work.
1. They should not ask for any password first of all 2. They post the password to their server when they could have checked it on the client 3. The password is sent as GET meaning that it is in the URL and it will be recorded in your history and perhaps anything else that keeps log of the URLs you visit
100% fail