back
user profile
josephcsible
28,561karma·8,511submissions·May 26, 2020
recent activity (8,511 total)
comment
Isn't the only reason that it didn't take off because it was so incomplete?
comment
They don't even need to fake the URL bar. A malicious app can steal your password from the real login page if it's in its embedded browser.
comment
> Operating systems can and should implement DoH, not every single individual application I agree that it would be better for DoH to be done in the operating system than in applications, but the re…
comment
> You can't be distinguished from an attacker, from the computer's perspective. Then what's the point of things like passwords and fingerprint scanners? > Having the computer be a…
comment
So SIP isn't about keeping me secure. It's about keeping my computer secure from me .
comment
Are Windows and Linux insecure? They don't have anything like SIP. Also, the whole idea of SIP has a strong https://xkcd.com/1200/ vibe.…
comment
Disabling SIP doesn't cripple macOS.
comment
> It’s not just about hosting, they also provide basically the entire software stack you’re using. Pricing that is difficult but I don’t think it should be disregarded. You paid for that already wh…
comment
> It's only through politics that we can make sure that the gains from trade are evenly split. False. Competition from other employers can do this too.
comment
The point is that it has a C interface despite being written in assembly. Your original post said the only reason it had a C interface was that it was written in C.
comment
> Operating systems are currently written in C, and therefore have a C interface. Not true. Operating systems are written in C with some assembly, and the interface to userspace is universally writ…
comment
This is an understatement. The only relevant platform that supports Annex K is MSVC, and this is unlikely to change any time soon.
comment
> I should have the right to monitor my network and my traffic. The key is that if it's really your traffic, then you can easily reconfigure Firefox so that you can monitor it. The benefit of …
comment
This is a fair point, but the reality today is that basically every OS uses the network-provided DNS servers by default, so Firefox is completely right today to ignore the OS by default. If this ever …
comment
Your Pi-hole working on other people's devices is a bad thing. After all, there's nothing stopping you from configuring your Pi-hole to filter political content you disagree with instead of …
comment
Untrusted devices should be on a separate network where they don't have access to any data worth exfiltrating.
comment
> you may trust the local DNS to respect your privacy more than you do Cloudflare For most people, their local DNS is someone like Comcast or Verizon, way less trustworthy than CloudFlare. We shoul…
comment
That's not an issue with overriding the system DNS. It's the point of overriding the system DNS. Content blocking by anyone but the user is a bad thing, and if you the user want it, then ins…
comment
Which governments and which software?
comment
How is this further centralising the Web? You can still use whatever DoH provider you want (and there's plenty of them); the choice just shouldn't be tied to the network you're on.
comment
In the United States, it's considered a social duty but isn't mandatory.
comment
What you want would make censorship and surveillance easier against the vast majority of people. Networks I'm on shouldn't be able to tell which CloudFlare-hosted site I'm visiting, or …
comment
> if your DNS resolver is malicious and points all domains to a malicious IP then https is completely useless. 100% false. HTTPS absolutely protects against that.
comment
We can't say that a true statement is true just because there's a chance that at some point it becomes false?
comment
Supporting TLS is a cakewalk compared to handling modern HTML/JS/etc. This has nothing to do with the browser monoculture.
comment
Image decoders occasionally have RCE vulnerabilities.
comment
The difference is what happens if you type http manually.
comment
There's a ton of trusted roots across multiple countries. I think the odds are virtually nil that none of them would let you have a certificate.
comment
Nobody's saying you should be required by law to use HTTPS. Voting is a social duty too and it's not mandatory.
comment
> That's higher than 5 of the shown previous 10 years So in other words, it's basically exactly the median of the last 10 years? That seems to reinforce the title's claim.