Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mmd45
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
1.
▲
by
mmd45
5mo ago
shouldn't compaction be interactive with the user as to what context will continue to be the most relevant in the future??? what if the harness allowed for a turn to clarify the user's expected future direction of the conversation
2.
▲
by
mmd45
2y ago
you are assuming i have users and this is a mail server not a website which has a very different access pattern more analogous to ssh where TOFU works beautifully.
3.
▲
by
mmd45
2y ago
for the use case of a single user IMAP server this is all way, way, too complicated and buys you nothing in terms of security. it's completely analogous to why we dont use CAs to validate openssh host certificates.
4.
▲
by
mmd45
2y ago
bad summary. it prompted you to accept the certificate upon first use and then pinned it which is far different than what you are describing in terms of security implications.
5.
▲
by
mmd45
2y ago
i saw a video on youtube where a guy intercepted https app traffic from an android app for a smart scale where the app used certificate pinning. there was some very automated tool for defeating the cert pinning. unfortunately i can't
6.
▲
by
mmd45
2y ago
how are you renewing the LE certificate if the domain is resolving to an internal ip? this seems like a big hoop to jump through.
7.
▲
by
mmd45
2y ago
per apple dev forums it seems like they have a history of breaking this and then fixing it. additionally, while IMAP is broken, calendars and notes seem to work just fine so hopefully it's not deliberate.
8.
▲
by
mmd45
2y ago
explain how a pinned self signed cert is insecure. i don't see it. it would seem to be more secure than one signed by a public CA that's not pinned.
9.
▲
by
mmd45
2y ago
unfortunately none of that applies to my setup. my imap server lives in a dmz and doesn't have all that other jazz.
10.
▲
by
mmd45
2y ago
i'm just using a hardcoded private ip to connect to the imap server. are you saying i can get a certificate with a hostname of "*" that will match ANY ip address?
11.
▲
by
mmd45
2y ago
https://developer.apple.com/forums/thread/732409 (fixed url) seems like the issue is specifically with IMAP- I can confirm that calendar syncing works fine with the self signed cert. this is really disappointing.
12.
▲
by
mmd45
2y ago
I'm using a private ip over a vpn so I don't think that workaround will work for me. I don't really want a public dns record.
13.
▲
iOS 18 breaks IMAPS self-signed certs
(forums.developer.apple.com)
118 points
by
mmd45
2y ago
|
148 comments
14.
▲
by
mmd45
2y ago
:-( hey lurking apple devs- can someone please escalate this?
15.
▲
by
mmd45
2y ago
There is an interesting argument to be made that pre-JT xz code is probably pretty secure due to the fact that the threat actors would have already audited the code for existing exploits prior to exerting effort to subvert it.
16.
▲
Ask HN: Voice ID adoption at financial institutions
2 points
by
mmd45
2y ago
|
5 comments
17.
▲
by
mmd45
2y ago
thanks, that seems promising. i will look into it.
18.
▲
by
mmd45
2y ago
https://github.com/trusteddomainproject/OpenARC/issues/163 https://github.com/trusteddomainproject/OpenDKIM/issues/186 OpenARC/OpenDKIM don't parse email headers to s
19.
▲
by
mmd45
3y ago
maybe its an nfc hack. pretty scary how wide open it is/was: https://www.youtube.com/watch?v=eV76vObO2IM
20.
▲
by
mmd45
3y ago
anyone have any thoughts or experience with this?
21.
▲
Jiko Money Storage
(jiko.io)
2 points
by
mmd45
3y ago
|
1 comments
22.
▲
by
mmd45
3y ago
i've never heard the term narrow banking, but after looking it up isn't that effectively what this company is attempting: https://jiko.io/
23.
▲
by
mmd45
5y ago
interersting. does mercury support bill pay? can you get a cashier's check? how long do deposited checks take to become available for withdrawal?
24.
▲
by
mmd45
5y ago
The killer is the "The bill also prevents investing in an entity in which the IRA owner is an officer." which is generally how the checkbook IRA is structured (IRA owner is the Manager of the single member LLC that is wholly owned
25.
▲
by
mmd45
5y ago
No, the LLC is the same as the plan in terms of rules against prohibited transactions. Apple thought experiment works, but if you are personally generating revenue that moves the needle on a IRA investment that would be a no-no.
26.
▲
by
mmd45
5y ago
They can easily stop the next Pete Thiel by capping the appreciated IRA balance which they have in fact added a provision for. I don't comprehend the scare tactic of killing the self-directed IRA.
27.
▲
by
mmd45
5y ago
some additional information (see page 10, part 3 for Retirement Account provisions) https://waysandmeans.house.gov/sites/democrats.waysandmeans.... https://www.irafinancialgroup.com/learn-more/podc
28.
▲
by
mmd45
5y ago
That may be the case but they are casting a very wide net. The numbers I've seen say there are on the order of 100k-1MM self directed IRA accounts that exist. Approximately 0% of which are lucky enough to be Peter Thiel and invest in
29.
▲
by
mmd45
5y ago
No it doesn't as that would fall under the rules for prohibited transactions of which there are strict rules and penalties. See https://www.irs.gov/retirement-plans/plan-participant-employ... .
30.
▲
by
mmd45
5y ago
Self directed IRAs are commonly used with a wholly owned single member LLC to invest IRA funds into real estate related investments such as rental properties or many other types of private investments. The new proposed tax bill seems to re
More ›