back
user profile

josephcsible

28,561karma·8,511submissions·May 26, 2020
recent activity (8,511 total)
comment
Isn't the only reason that it didn't take off because it was so incomplete?
5y ago·view thread
comment
They don't even need to fake the URL bar. A malicious app can steal your password from the real login page if it's in its embedded browser.
5y ago·view thread
comment
> Operating systems can and should implement DoH, not every single individual application I agree that it would be better for DoH to be done in the operating system than in applications, but the re…
5y ago·view thread
comment
> You can't be distinguished from an attacker, from the computer's perspective. Then what's the point of things like passwords and fingerprint scanners? > Having the computer be a…
5y ago·view thread
comment
So SIP isn't about keeping me secure. It's about keeping my computer secure from me .
5y ago·view thread
comment
Are Windows and Linux insecure? They don't have anything like SIP. Also, the whole idea of SIP has a strong https://xkcd.com/1200/ vibe.…
5y ago·view thread
comment
Disabling SIP doesn't cripple macOS.
5y ago·view thread
comment
> It’s not just about hosting, they also provide basically the entire software stack you’re using. Pricing that is difficult but I don’t think it should be disregarded. You paid for that already wh…
5y ago·view thread
comment
> It's only through politics that we can make sure that the gains from trade are evenly split. False. Competition from other employers can do this too.
5y ago·view thread
comment
The point is that it has a C interface despite being written in assembly. Your original post said the only reason it had a C interface was that it was written in C.
5y ago·view thread
comment
> Operating systems are currently written in C, and therefore have a C interface. Not true. Operating systems are written in C with some assembly, and the interface to userspace is universally writ…
5y ago·view thread
comment
This is an understatement. The only relevant platform that supports Annex K is MSVC, and this is unlikely to change any time soon.
5y ago·view thread
comment
> I should have the right to monitor my network and my traffic. The key is that if it's really your traffic, then you can easily reconfigure Firefox so that you can monitor it. The benefit of …
5y ago·view thread
comment
This is a fair point, but the reality today is that basically every OS uses the network-provided DNS servers by default, so Firefox is completely right today to ignore the OS by default. If this ever …
5y ago·view thread
comment
Your Pi-hole working on other people's devices is a bad thing. After all, there's nothing stopping you from configuring your Pi-hole to filter political content you disagree with instead of …
5y ago·view thread
comment
Untrusted devices should be on a separate network where they don't have access to any data worth exfiltrating.
5y ago·view thread
comment
> you may trust the local DNS to respect your privacy more than you do Cloudflare For most people, their local DNS is someone like Comcast or Verizon, way less trustworthy than CloudFlare. We shoul…
5y ago·view thread
comment
That's not an issue with overriding the system DNS. It's the point of overriding the system DNS. Content blocking by anyone but the user is a bad thing, and if you the user want it, then ins…
5y ago·view thread
comment
Which governments and which software?
5y ago·view thread
comment
How is this further centralising the Web? You can still use whatever DoH provider you want (and there's plenty of them); the choice just shouldn't be tied to the network you're on.
5y ago·view thread
comment
In the United States, it's considered a social duty but isn't mandatory.
5y ago·view thread
comment
What you want would make censorship and surveillance easier against the vast majority of people. Networks I'm on shouldn't be able to tell which CloudFlare-hosted site I'm visiting, or …
5y ago·view thread
comment
> if your DNS resolver is malicious and points all domains to a malicious IP then https is completely useless. 100% false. HTTPS absolutely protects against that.
5y ago·view thread
comment
We can't say that a true statement is true just because there's a chance that at some point it becomes false?
5y ago·view thread
comment
Supporting TLS is a cakewalk compared to handling modern HTML/JS/etc. This has nothing to do with the browser monoculture.
5y ago·view thread
comment
Image decoders occasionally have RCE vulnerabilities.
5y ago·view thread
comment
The difference is what happens if you type http manually.
5y ago·view thread
comment
There's a ton of trusted roots across multiple countries. I think the odds are virtually nil that none of them would let you have a certificate.
5y ago·view thread
comment
Nobody's saying you should be required by law to use HTTPS. Voting is a social duty too and it's not mandatory.
5y ago·view thread
comment
> That's higher than 5 of the shown previous 10 years So in other words, it's basically exactly the median of the last 10 years? That seems to reinforce the title's claim.
5y ago·view thread