1,039 karma · joined May 24, 2011
Today, with Chrome being dominant the situation is different because Google is still innovating Chrome at light speed. The one and only Achilles heel to beat this giant is by attacking their business model, which is to enable ad blocking by default. I expect this is something people want, just like pop-up blockers back in the days. Google will never be able to lead, or even follow in this direction without changing their business model.
Unfortunately, Mozilla’s own business model also heavily relies on selling ads, albeit indirectly. According to this statement from an independent audit report[1]:
"Note 10 - Concentrations of Risk:
Mozilla has entered into contracts with search engine providers for royalties which expire through November 2020. Approximately 93% and 94% of Mozilla’s royalty revenues were derived from these contracts for 2017 and 2016, respectively, with receivables from these contracts representing approximately 75% and 79% of the December 31, 2017 and 2016 outstanding receivables."
In other words, $539 Million, which is 93% of their total revenue, comes from companies that have selling ads as their business model (Baidu, Google, Yahoo and Yandex [2]).
I really hope Mozilla will be able to change this revenue stream to better align with their mission[3]. They have been trying to diversify their revenue since 2014 [4] and although they might not be as dependent on Google as they once were, they're still almost fully dependent on ads.
Oh, and yeah, of course simply making a better browser than Chrome would also help ;)
Background:
* https://www.mozilla.org/en-US/foundation/annualreport/2017/
* https://assets.mozilla.net/annualreport/2017/mozilla-2017-fo...
[1] https://assets.mozilla.net/annualreport/2017/mozilla-fdn-201...
[2] https://wiki.mozilla.org/Global_Search_Strategy_Status
[3] https://www.mozilla.org/en-US/mission/ "An Internet that truly puts people first, where individuals can shape their own experience and are empowered, safe and independent."
[4] https://blog.mozilla.org/advancingcontent/2014/02/11/publish...
As a programmer you have the right (or maybe even obligation?) to write secure software and I would argue software that's hard or impossible to use insecurely. It should live up to the standards of the time of release, not the time of the release of the first version (in case of OpenSSH that would be more than seventeen years ago).
As a sysadmin you can always decide to stick with an old version if that is what the environment you operate in demands.
I think this proactive mentality of OpenSSH is an important part of their success and why it has such a good track record from a security point of view.
Too late to edit my own post but please s/voting booth/polling station/ in the parent. Of course every voter should have absolute privacy in the voting booth in order to rule out coercion, but the ballot storage in the polling station should be publicly verifiable.
(as mentioned in a comparable thread five days ago: "Intel and ME, and why we should get rid of ME" (fsf.org) https://news.ycombinator.com/item?id=11880935)
OpenSSL announced several issues today that also affect LibreSSL.
- Memory corruption in the ASN.1 encoder (CVE-2016-2108)
- Padding oracle in AES-NI CBC MAC check (CVE-2016-2107)
- EVP_EncodeUpdate overflow (CVE-2016-2105)
- EVP_EncryptUpdate overflow (CVE-2016-2106)
- ASN.1 BIO excessive memory allocation (CVE-2016-2109)
Thanks to OpenSSL for providing information and patches.
http://marc.info/?l=openbsd-announce&m=146228598930416&w=2The nice thing about using the onion address (transport layer) is that you have mandatory e2e authentication with only one id that solves multiple real world problems with bgp/dns/tls.
How would you propose to go further from current state-of-the-art WhatsApp to stop leaking meta-data? I know Ricochet is open to use a stronger encryption layer on top of Tor †.
Maybe in the future when prop224†† is implemented the encryption will be more solid.
† https://media.ccc.de/v/32c3-7322-tor_onion_services_more_use...
†† https://gitweb.torproject.org/user/asn/torspec.git/tree/prop...
Host *
Ciphers chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr
MACs hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256
KexAlgorithms curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256
HostKeyAlgorithms ssh-ed25519,ssh-rsa
ChallengeResponseAuthentication no
UseRoaming no
If you only connect to newer servers you can further restrict ciphers to only use AEADs (only list the chacha20-poly1305 and aes-gcm ciphers). I assume using AEADs-only makes the MACs keyword obsolete, is this correct?Config is based on tips from https://stribika.github.io/2015/01/04/secure-secure-shell.ht...
> Anyone with the onion address can still estimate availability by watching descriptors
Maybe cheaper, but I'm not sure if having to trust my computer with an important vote like that is better than having to trust a voting booth, ballot box and my eyes when the votes are being tallied. I think the slowness of manual tallying is a security property since anyone can inspect the computation while it's being run. All other technologies like Civitas, Scantegrity etc. are not cheaper but more expensive than this manual process and open up great possibilities for state level adversaries.
I think your system (using peoples computers) might be trusted when the stakes are lower though. Interesting project :)
Recently the CEO of Fox-IT reported a delay to our minister in the Netherlands[2] with researching the specs for a usable and secure vote printer and vote counter[3]. It's not as easy as people think, especially the elder seem to have trouble with it.
[1] https://www.usenix.org/conference/evtwote14/workshop-program...
[2] https://zoek.officielebekendmakingen.nl/blg-604665 (Dutch)
[3] Unofficial translated summary of the report on large scale voting; proposes using a vote printer and vote counter with human readable ballots in between: https://www.kiesraad.nl/sites/default/files/every-vote-count... (English)
According to Halderman* it might take us 10 years, if ever, to get machines the public can trust and verify on the scale that is needed for nation-wide elections.
Given the sorry state of current phone and laptop security, the problem of having a massive TCB is not solved, not with building on Ethereum either.