HNHacker News
TopNewBestAskShowJobs

tokenizerrr

2,693 karma · joined May 24, 2013

submissionscomments
tokenizerrr··on Show HN: Six Degrees of Wikipedia
I've used neo4j before and it likes to consume a lot of memory.
tokenizerrr··on Flight Sim Company Embeds Malware to Steal Pirates’ Passwords
You should have done that ages ago. Essentially any anti-cheat software is malware that spies on you.
tokenizerrr··on Chrome 68 will mark all HTTP sites as “not secure”
I'm generally not worried about HTTP connections. Any random hyperlink I click on can produce those. However Ajedi32 made some very good points that being able to MITM HTTP connections can cause lasting issues, even for pages where the user is not intending to download anything, nor enter credentials.
tokenizerrr··on Chrome 68 will mark all HTTP sites as “not secure”
It doesn't need it. You can always just nmap your network, find its lan ip and connect straight through that over http. But that's not very user friendly, hence the dyndns.
tokenizerrr··on Chrome 68 will mark all HTTP sites as “not secure”
That is a generalization. You certainly do with many networked appliances. And I prefer this, since that means connectivity with the device is not dependent on some cloud service. And that some cloud service can't control my appliance.
tokenizerrr··on Chrome 68 will mark all HTTP sites as “not secure”
User's webbrowser is visiting the appliance which resides on LAN. Webbrowsers require certificates signed by a CA.
tokenizerrr··on Chrome 68 will mark all HTTP sites as “not secure”
Yeah, would be nice if ACME with DNS validation was widespread. But right now it's still not viable due to Let's Encrypt's rate limits.
tokenizerrr··on Chrome 68 will mark all HTTP sites as “not secure”
> under their certificate authority delegation to *.coffeepot.com.

Where can I get a certificate with the CA flag set for mydomain.com? I did not know this was an option for mere mortals.

tokenizerrr··on Chrome 68 will mark all HTTP sites as “not secure”
Interesting, and point well made. Thanks!
tokenizerrr··on Chrome 68 will mark all HTTP sites as “not secure”
I define insecure as a machine/user getting compromised. Malware, phishing and the like.

Anyway, your example is a good one as to why it's weird for Chrome to label these things as insecure.

tokenizerrr··on Chrome 68 will mark all HTTP sites as “not secure”
Actually, now that I think about it, with the Let's Encrypt DNS challenge this might actually be viable... That's pretty recent, though. And they rate limit harshly. I was thinking about the HTTP validation, which would definitely fail, due to the DNS resolving to a LAN IP. Which a CA would obviously not be able to verify.
tokenizerrr··on Chrome 68 will mark all HTTP sites as “not secure”
Unless I'm misunderstanding they did that by partnering with a CA. Becoming a semi-trusted CA themselves. This is not an option for most organizations.
tokenizerrr··on Chrome 68 will mark all HTTP sites as “not secure”
What app store? Which OS? Do you now suddenly have to write software for all OSes to install the certificate? Something that you didn't even have to think about doing before. The entire reason you went for a webui to begin with.
tokenizerrr··on Chrome 68 will mark all HTTP sites as “not secure”
Please tell me how to painlessly install a CA on a user their computer? Imagine buying a network connected coffeepot. You plug it in and you're done.
tokenizerrr··on Chrome 68 will mark all HTTP sites as “not secure”
All of that is bad, none of it is a security issue. Privacy, sure. But not security. And the article specifically shows that Google is planning to mark example.org as insecure. Which it's not.
tokenizerrr··on Chrome 68 will mark all HTTP sites as “not secure”
> Can you not just create a certificate and push it to the system as a trusted cert?

If you were to control the user's machine, yes. But imagine you bought a shiny new internet connected coffee pot. Once you turn it on it does the following:

1. Coffeepot Determines its LAN IP address (e.g. 192.168.1.100)

2. Coffeepot connects to the coffeepot cloud service to register a dynamic DNS entry (e.g. user1.coffeepot.com) to point to its LAN IP address.

3. User is told they can access their coffeepot WebUI by going to user1.coffeepot.com, which resolves to 192.168.1.100

This is secure since the coffeepot can only be controlled if you are in the same network. Yet, since the coffeepot webui can only be reached if you are in its network, it is nearly impossible to get a valid SSL certificate on the coffeepot appliance.

> Presumably there is already some sort of communication going on if they're receiving Chrome updates.

There is a difference between outgoing network traffic and incoming network traffic. Only the latter requires open ports.

tokenizerrr··on Chrome 68 will mark all HTTP sites as “not secure”
Yeah. You could also just host it literally anywhere and post an URL in the comments here. By that logic clicking on hyperlinks is equally insecure.
tokenizerrr··on Chrome 68 will mark all HTTP sites as “not secure”
So it's a http2 vs http1 benchmark. Not a http vs https benchmark?
tokenizerrr··on Chrome 68 will mark all HTTP sites as “not secure”
That's not a security issue if the site doesn't ask for user input, though.
tokenizerrr··on Chrome 68 will mark all HTTP sites as “not secure”
It's impossible to get a valid SSL certificate for an appliance running within someone their lan, without having to open ports. And opening ports would make the appliance even more vulnerable to attack.
tokenizerrr··on Chrome 68 will mark all HTTP sites as “not secure”
I don't understand what is insecure about http://example.com? It's a simple static site which does not allow user input.
tokenizerrr··on Chrome 68 will mark all HTTP sites as “not secure”
1. You don't have to monitor your cronjobs. They'll send you an email when they produce output.

2. Let's Encrypt will send you an email if your certificate is going to expire in a month. This will normally never happen, since it is continuously renewed.

tokenizerrr··on Find and analyze any reachable server and device on the internet
Running software against my own IP space is considered mean?
tokenizerrr··on Find and analyze any reachable server and device on the internet
"Stop looking at my house from the public street! It's not authorized!"
tokenizerrr··on Show HN: Interactive Ansible Tutorial
As far as I know all you have to do is configure your ~/.ssh/config properly, and then use the hostnames set there. Same as regular old OpenSSH.

Just don't opt into the Paramiko control scheme, which isn't used by default except on RHEL6 anyway.

You can also set ssh_args in the config file to enable ControlMaster, etc. http://docs.ansible.com/ansible/latest/intro_configuration.h...

tokenizerrr··on Do You Have the Right to Plead Not Guilty When Your Lawyer Disagrees?
If you choose to have your hand cut off because you think it would be awesome, I'd hope your doctor would refuse to do it.
tokenizerrr··on Google Memory Loss
As far as I know it's in the tutorial they insist you do upon first enabling swiping

edit: Don't actually see a tutorial in the app. Maybe I'm confused with another app such as Swype, but the same technique seems to apply to all.

tokenizerrr··on Google Memory Loss
> I frequently swipe "See you soon." It always, always renders as "See you son"

This works fine for me with GBoard. Are you drawing a little circle on the o to indicate you want the double letter?

tokenizerrr··on A letter about Google AMP
Please explain why you hate it?
tokenizerrr··on Things I Wish I'd Known About Bash
It had a trailing >, https://github.com/junegunn/fzf
← PreviousPage 2 of 34Next →