Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
gellerb
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
by
gellerb
9y ago
One can use sourceclear.com for Composer.
2.
▲
by
gellerb
9y ago
One can use sourceclear.com for Python support.
3.
▲
Adopting and Reducing Challenges of Content Security Policy (CSP) with Sentry.io
(medium.com)
1 points
by
gellerb
9y ago
|
0 comments
4.
▲
by
gellerb
11y ago
Login and inspect the home page afterwards. http://imgur.com/bwUHgcT
5.
▲
by
gellerb
11y ago
SRI allows one to specify multiple hashes. In other words, to prevent this particular mismatch, one could include the hash of the new resource as well as the previous valid hash.
6.
▲
by
gellerb
11y ago
Use Chrome Canary
7.
▲
Vault – A tool for managing secrets
(vaultproject.io)
14 points
by
gellerb
11y ago
|
1 comments
8.
▲
by
gellerb
11y ago
It unfortunately includes carrageenan.
9.
▲
MongoDB and ReDoS
(twitter.com)
2 points
by
gellerb
11y ago
|
1 comments
10.
▲
WebRTC Requires Perfect Forward Secrecy (PFS) Starting in Firefox 38
(hacks.mozilla.org)
2 points
by
gellerb
12y ago
|
0 comments
11.
▲
by
gellerb
12y ago
ssl:endpoint add-on
12.
▲
by
gellerb
12y ago
The HTTP 2.0 spec[1] mentions "Implementations of HTTP/2 MUST support TLS 1.2 and it appears Chrome will implement HTTP/2 via TLS only ( http://volgarev.me/blog/75094931827 ).
13.
▲
by
gellerb
12y ago
Elastic Loading Balancing for AWS customers & Heroku allow for perfect forward secrecy and Akamai customers can expect ECDHE in Q3 of this year.
14.
▲
by
gellerb
12y ago
ds9, yes, "site certs the browser doesn't trust a CA for" is more accurate. You can find the exact details of HSTS and self-signed certs in the draft in section 11.3[1]. I've updated the post to hopefully be more clear.
15.
▲
by
gellerb
12y ago
In Safari one can delete ~/Library/Cookies/HSTS.plist
16.
▲
by
gellerb
12y ago
Yeah. I noticed that paypal.com has a max-age of 4 hours.
17.
▲
Is Your Site HSTS Enabled?
(blog.nvisium.com)
49 points
by
gellerb
12y ago
|
30 comments