Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
danimo
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
Videos from All Systems Go User-Space Linux Technologies Conference
(media.ccc.de)
7 points
by
danimo
9y ago
|
0 comments
2.
▲
OwnCloud 9.1 Brings 2FA, Collabora Office
(owncloud.org)
9 points
by
danimo
10y ago
|
0 comments
3.
▲
Qt MOC myths debunked
(woboq.com)
10 points
by
danimo
11y ago
|
0 comments
4.
▲
Distribution packages considered insecure
(statuscode.ch)
6 points
by
danimo
11y ago
|
0 comments
5.
▲
by
danimo
11y ago
Nope.
6.
▲
Videos from systemd.conf 2015
(youtube.com)
9 points
by
danimo
11y ago
|
3 comments
7.
▲
Building a pretty, hand-crafted audio player
(dragotin.wordpress.com)
5 points
by
danimo
11y ago
|
0 comments
8.
▲
by
danimo
11y ago
Note that rich does not claim anything else. However, there is a fundamental difference between "initiate TLS connection from byte 0" (as used in HTTPS, but also IMAPS or SMTPS) and STARTTLS, where the protocol is plain text until
9.
▲
by
danimo
12y ago
Second-to-best solutions with older Distributions (Ubuntu 12.04, Debian 7, RHEL 6).
10.
▲
by
danimo
12y ago
I've essentially answered this in https://news.ycombinator.com/item?id=7620756 . Basically, this cannot be the sole task of Apache, as they rely on OpenSSL via mod_ssl. Some parts are apache specific (OCSP stapling), bu
11.
▲
by
danimo
12y ago
Thanks, added!
12.
▲
by
danimo
12y ago
About the Cargo Cult thing: Fair enough. I'm not a native speaker myself, but thought that it may be a well-enough-known idiom. Anyway, SSL is still what people know it under (plus, according to Wikipedia, TLS support was only added in
13.
▲
by
danimo
12y ago
That's an excellent reference with good explanations. I'll add it to the list to get away from the strong Ivan bias :-). The reason why I had A- only is that my openssl (Debian) doesn't seem provide all the ciphers required.
14.
▲
by
danimo
12y ago
>The author attacks blog posts that state the current best-practices No, I'm attacking the fact that people blingly follow blog posts that have been, at some point, what their author believed were best practices. > But then goes
15.
▲
by
danimo
12y ago
Essentially this comes down to pressuring distros and server vendors do their homework finally ship with good examples/defaults. E.g. Microsoft IIS (!) has OCSP stapling enabled by default since ages. Apache? Most people still run 2.2,
16.
▲
by
danimo
12y ago
Yes, that's the exact problem that made me write this. What's particularly amazing is the amount of magical cipher suite strings shared throughout the web, most of which do not take in account PFS, or still prioritize RC4. All of
17.
▲
Fighting Cargo Cult – An Incomplete SSL/TLS Bookmark Collection
(daniel.molkentin.net)
80 points
by
danimo
12y ago
|
33 comments
18.
▲
by
danimo
13y ago
Or http://media.ccc.de/browse/congress/2013/30C3_-_5499_-_en_-_... (incl download option in mp4 hq and lq and webm).
19.
▲
On Practical Qt Security
(daniel.molkentin.net)
24 points
by
danimo
13y ago
|
5 comments
20.
▲
by
danimo
13y ago
They did not. For unknown reasons, the switch in the Conference hall got manipulated (unplugged). It carried both the Skype call and the stream to the outside world.
21.
▲
by
danimo
13y ago
Just to clear this up: cdn.media.ccc.de is the new name for ftp.ccc.de. It was renamed because it does not actually serve FTP anymore, since HTTP can be load-balanced a lot better.
22.
▲
by
danimo
13y ago
For best experience, please do _not_ use mirrors directly. http://media.ccc.de ( http://cdn.media.ccc.de to be precise) will redirect you to the fastest mirror near you (GeoIP and ASN-based).