HNHacker News
TopNewBestAskShowJobs

troyjfarrell

107 karma · joined October 5, 2011

submissionscomments
troyjfarrell··on Let's Encrypt now holds 35% of the market
Do you have an opinion on Sandstorm's use of wildcard certificates and randomized hostnames for each application sesssion? [0] They insist that this provides many desirable security features. (Note that the free HTTPS certificates provided by the Sandcats.io service are renewed every week. [1])

[0] https://docs.sandstorm.io/en/latest/administering/wildcard/#...

[1] https://docs.sandstorm.io/en/latest/administering/sandcats/#...

troyjfarrell··on 40% of foreign students in the US have no close American friends on campus
For non-native English speakers:

“I could care less about $THING” and “I couldn't care less about $THING” mean the same thing. Each means that the speaker does not care about $THING.

troyjfarrell··on Passpie: manage login credentials from the terminal
Version control is really cool for this sort of information. Unfortunately, pass leaks information in filenames, which is a pretty big problem for some uses. In my opinion, the version control needs to be built into the application to avoid all the potential side channel information leaks.
troyjfarrell··on Unfortunately, we have renewed our ICANN accreditation
Is there a reason registrars aren't cryptographically signing these messages? That would give everyone a relatively simple way to verify that they aren't forged. I get that not everyone who will receive these messages are technical enough to figure out PGP or S/MIME, but it would be trivial for Gmail, Outlook.com, Yahoo Mail, etc. to put a pretty seal on these signed messages.
troyjfarrell··on Game of Hacks
Fixing the indentation would also make the Python code readable. (For those who aren't aware, whitespace is significant in Python.)
troyjfarrell··on Security Hole in Sendgrid
You should review the work NearlyFreeSpeech.NET recently did on customizable account recovery options. It's easy the best I've every seen. It works like this:

1) You decide how valuable the account is, the probability that you will lose access to the account, and the probability that the account will be attacked. 2) You selected the required number of recovery actions, from one recovery action to completely unrecoverable. Possible recovery actions include (copied from NFSN):

* You provide a scanned copy of a government-issued photo ID. * You provide a scanned copy of a statement showing both the most recent deposit and a name and address matching one of your accounts. * You complete SMS verification. (SMS must be previously configured.) * You complete 2-factor verification. (2-factor auth must be previously configured.) * You correctly answer your security question. (Security question and answer must be previously configured, below.) * You use an ssh key to create a file with a specific name on one of your sites hosted here. (Must be previously configured, won’t work if account is empty.) * We try and fail to contact you via your currently configured email address. (This one may take a long time.)

As far as I'm concerned, this is the way it should be done. The public details are on their blog: https://blog.nearlyfreespeech.net/2014/02/28/price-cuts-more...

troyjfarrell··on Private keys committed to Github repositories
It's actually very handy to keep your private keys in a VCS (along with other dotfiles.) I keep mine in a private repository. I don't worry about it because all my private keys are encrypted with strong passphrases.
troyjfarrell··on Why No One Uses Your Test Framework
Python (the subject of the OP) is a strongly-typed, dynamically-typed language.
troyjfarrell··on Redesigning the country selector
This can be diplomatically difficult.

The linked implementation only lists Taiwan as "Taiwan, Province of China". I could see this being interpreted in many different ways, with either side being insulted. (Maybe that's best.)

← PreviousPage 2 of 2