Conversation
Notices
-
Danyl Strype (strypey@quitter.se)'s status on Monday, 16-Apr-2018 04:06:05 UTC
Danyl Strype
https://www.howsmyssl.com/ -
Danyl Strype (strypey@quitter.se)'s status on Monday, 16-Apr-2018 12:31:05 UTC
Danyl Strype
@budkin #1 it's Lunduke, and his sponsored #clickbat is best taken with a grain of salt ... -
Danyl Strype (strypey@quitter.se)'s status on Monday, 16-Apr-2018 12:35:28 UTC
Danyl Strype
@budkin ... Problem #1: solution is #certbot. Problem #2: solution is cert authorities like Let's Encrypt ... -
Danyl Strype (strypey@quitter.se)'s status on Monday, 16-Apr-2018 12:38:00 UTC
Danyl Strype
@budkin #SHA Lunduke doesn't know the difference between an algorithm and a program. SHA implemented by free code isn't subject to #NSA -
Danyl Strype (strypey@quitter.se)'s status on Monday, 16-Apr-2018 12:39:00 UTC
Danyl Strype
@budkin here's someone who knows their shit writing about #HTTPS
https://blog.codinghorror.com/lets-encrypt-everything/ -
Danyl Strype (strypey@quitter.se)'s status on Monday, 16-Apr-2018 12:43:25 UTC
Danyl Strype
@budkin plus the crypto HTTPS uses isn't baked in. SSL was replaced with TLS, HTTPS didn't break. If SHA was compromised it can be swapped -
Danyl Strype (strypey@quitter.se)'s status on Monday, 16-Apr-2018 12:43:52 UTC
Danyl Strype
@budkin sure, which is why we're now up to SHA-3. See my last point -
Danyl Strype (strypey@quitter.se)'s status on Monday, 16-Apr-2018 13:16:05 UTC
Danyl Strype
@budkin ok. Have you been in touch with #LetsEncrypt about this? If so, what do they say? -
Danyl Strype (strypey@quitter.se)'s status on Monday, 16-Apr-2018 13:17:50 UTC
Danyl Strype
@budkin Lunduke is, like me, an opinionated user. Jeff Atwood co-created both #StackExchange and #Discourse ... -
Danyl Strype (strypey@quitter.se)'s status on Monday, 16-Apr-2018 13:18:49 UTC
Danyl Strype
@budkin ... Brian would have to raise some pretty strong and well-referenced arguments before I take his opinion over Jeff's ... -
Danyl Strype (strypey@quitter.se)'s status on Monday, 16-Apr-2018 13:20:01 UTC
Danyl Strype
@budkin ... let alone over *everyone* at #Mozilla and the #InternetSociety . It doesn't prove he's wrong, but Brian's HTTPS views are fringe -
Danyl Strype (strypey@quitter.se)'s status on Monday, 16-Apr-2018 16:56:20 UTC
Danyl Strype
@budkin "involved" doesn't always mean *useful*. Brian is know to get stuff totally wrong, then instead of self-correcting, he doubles down -
Danyl Strype (strypey@quitter.se)'s status on Monday, 16-Apr-2018 16:57:49 UTC
Danyl Strype
@budkin I really don't want to watch his self-promotional FUD in full, but I'm happy to discuss HTTPS issue with you here. Shoot! -
Danyl Strype (strypey@quitter.se)'s status on Monday, 16-Apr-2018 17:08:29 UTC
Danyl Strype
@budkin BTW did you read the older post linked at the top of that one?
https://blog.codinghorror.com/should-all-web-traffic-be-encrypted/
-