Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
the_zeroth_law
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
the_zeroth_law
8y ago
Yep. This looks like a bug in STARTTLS Everywhere, and we're working on it!
2.
▲
by
the_zeroth_law
8y ago
One of the nice features of the policy list is that you can put your server on it in testing mode. In testing mode, any failure in TLS negotiation is logged and reported, but the message is sent over the insecure communication. So it should
3.
▲
by
the_zeroth_law
8y ago
Thanks for catching that! We definitely still have some bugs to work out.
4.
▲
by
the_zeroth_law
8y ago
I'm an EFF technologist, and we're looking into this!
5.
▲
by
the_zeroth_law
8y ago
We do mention both: see https://www.eff.org/deeplinks/2018/06/technical-deep-dive-st... To sum up from that post, we think STARTTLS Everywhere is a stop-gap measure until DNSSEC is fully deployed, and STARTTL
6.
▲
by
the_zeroth_law
11y ago
One major difference is that Privacy Badger doesn't use a blacklist like the others and really isn't designed for the purpose of ad-blocking. It's designed to prevent non-consensual tracking, so it observes which third-party
7.
▲
by
the_zeroth_law
11y ago
That's correct; Privacy Badger doesn't block anything by default because it doesn't use a blacklist. Instead, it observes the behavior of third-party domains and blocks them based on their behavior. (So it may take a bit of n
8.
▲
by
the_zeroth_law
11y ago
They're both good at different things: NoScript blocks Javascript/Flash/etc. based either on a list you import, or on a case-by-case basis. I use it as a security measure, blocking potentially harmful content by default and e