Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
kniht
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
Beyond the NASCAR
(blog.oshineye.com)
1 points
by
kniht
13y ago
|
0 comments
2.
▲
Say Goodbye to the Password
(online.wsj.com)
3 points
by
kniht
13y ago
|
1 comments
3.
▲
by
kniht
13y ago
It's also possible to make the cookies non-exportable using a similar technique called channel binding[1], where the cookie is linked to the TLS channel it's minted over. This is a lot more powerful than baking in the IP address w
4.
▲
by
kniht
13y ago
It looks like ChannelID has been enabled since Chrome 24[1]. [1] https://code.google.com/p/chromium/issues/detail?id=136462#c...
5.
▲
by
kniht
13y ago
TLS client authentication allows the server to detect when an active MITM attempts to get into the connection[1]. This means that if you hold the theory that the NSA is acting as a MITM with Google's private keys, you also have to ass
6.
▲
by
kniht
13y ago
> provided they don't use cipher modes that provide forward secrecy They use a PFS cipher spec: http://googleonlinesecurity.blogspot.com/2011/11/protecting-...
7.
▲
by
kniht
13y ago
It bears repeating because this argument comes up in every PRISM thread... The basics: HTTPS is TLS/SSL transport level encryption of HTTP traffic (including HTTP headers). The way it works is that client and server go through a handsh
8.
▲
by
kniht
13y ago
AFAIK a strong key passphrase would be effective at protecting the private key while it's at rest (stolen laptop / hard drive). However as soon as the private key is pulled into memory for a signing or encryption operation the pa
9.
▲
by
kniht
13y ago
If you're doing public key crypto on the client side in javascript, then the client side JS must necessarily have access to the private key (unless you have a TPM _and_ browser hooks to use it). This means that suddenly the private ke
10.
▲
by
kniht
13y ago
That proposal is for an ephemeral, per gTLD client key and an example of mutual authentication that aims to defeat _active_ attackers (MITM). Perfect forward secrecy in TLS is a bit different in that the ephemeral diffie-hellman key exchang
11.
▲
by
kniht
13y ago
So you want to transmit potentially sensitive information through the post in plaintext? Just to give the middle finger to the NSA?
12.
▲
by
kniht
13y ago
You should look into how perfect forward secrecy works in TLS before you make these kinds of claims. [1] http://vincent.bernat.im/en/blog/2011-ssl-perfect-forward-se...
13.
▲
by
kniht
13y ago
These are all things you should be doing anyway, even if you're pursuing a degree, and want to land a good software engineering job. So the "without a degree" caveat doesn't really matter.
14.
▲
by
kniht
13y ago
Charles Schwab will issue a two factor device for online banking, but it is not required for withdrawals AFAIK.
15.
▲
by
kniht
13y ago
The old compose _was_ broken (at least for me). I encounter the use case where I need to reference data from another email when composing a new message all the time. This used to mean opening up a new gmail tab, with the new compose I can
16.
▲
Storms and Teacups
(acko.net)
10 points
by
kniht
13y ago
|
1 comments
17.
▲
by
kniht
14y ago
Yes. http://dsandler.org/brdfdr/