Hacker Newsnew | past | comments | ask | show | jobs | submit | justhere4beer's commentslogin

Loved reading his columns back in print magazine days. Found him again changing Leo Laporte's phones language to something other than English. Loved that. Found No Agenda from there. Was quite surprised to hear this news last week. Hope he heals up quickly. I wouldn't be surprised if he back in front of the mic in 3-4 weeks.


Alternate title, "Mutually Assisted Suicide."

Google drastically underestimates the harm this will cause and grossly overestimates the state of automation.


F-16's make sense, they are combat effective.

Patriot missiles make less sense. They are crap. The only redeeming value to provide Patriots is to deplete inventory.


Patriots draw fire. If the Russians are focused on nullifying the patriots, then chances of Russian missiles hitting something further back are lower.


They have no training or experience flying F-16s. They wouldn't be able to maintain and repair the jets either without training and parts from the US.


I remember first watching back when he was on cable via hacked DirecTV cards. Fascinating back in the day. When it went to the podcast/vid, I started losing interest when it became a smart phone centric, then came the two inadvertent D pics live on air. Never watched a segment since. Great run though, congrats.


I spent 15 years helping to build something great, only to be subjected to abusive gaslighting the last 3-5 years. When I quit, I was called irrational and emotional. Same year, 15 people followed my exodus.

I should have left years earlier, but money was good, and change was hard to think about. Fluffy handcuffs.

2 years later, Org still survives. Best guess is they are in rebuilding stage. No love lost.

Take your time to recharge the batteries.


I applaud the Let's Encrypt founders, past and current team for solving the automation problem that's plagued the SSL/TLS industry.

The yang to that ying is a lack trust. I have zero trust in a site owner using LE certs. Domain vetting only means control of the domain ... everything inside that beautifully encrypted traffic can be insightful, helpful or script kiddies scamming the vulnerable. If one finds the scam, LE shrugs, "not our problem bruh. We just issue certs to those who control the domain."

They single handedly reduced the price of entry for douchebag asshats ability to pretend someone they are not and harm a non-technical populace.

Two steps forward, one step backward.


What you're expressing was the mistake of overloading the meaning of a certificate and incorrectly teaching people that the lock meant trusted.

None of this was the fault of Let's Encrypt. They just exposed the mistakes that were OV and EV certificates and incorrect education.


I think history proved fairly convincingly that people would still get scammed with the old system. Given that, I'll take encrypted traffic almost universally across the internet and scams still being a thing over mostly unencrypted traffic any day.


I wish this statement to be true "... scams still being a thing over mostly unencrypted traffic any day." Sadly this falls in a similar category of domain validation.

I guess, take comfort where you can?


TLS or SSL never meant that kind of safety in the first place. Even before LE, there was no guarantee that HTTPS means it's not a scam, and the PKI system has never been meant to guarantee that anyway! Let's Encrypt didn't change anything here, and they're doing exactly what they or any other CA is supposed to do.


Hard to take your article seriously with statements such as "...Levels 1 and 2 of the FIPS140-2 certification are just a marketing gimmick". Even harder to believe Jakob took the time to respond.


Hexview provided their reason for believing that. Care to explain why you think otherwise?


Original quote:

>That is not a big deal, considering that Levels 1 and 2 of the FIPS140-2 certification are just a marketing gimmick for most electronic devices.

They have a point here: technically, the iPhone is FIPS140-1/2 compliant. By itself, that doesn't mean that the device is secure. It does show two important requirements for security.


FIPS isn't trivial. There is a lot of shit crypto on the market, establishing FIPS is not banal. Regardless of FIPS, if not utilized properly, it protects nothing. If utilized correctly, it protects what it needs to. Discounting it show lack of understanding.


A little education goes a long way: http://csrc.nist.gov/groups/STM/cmvp/


They state they believe the device fulfils these requirements, it just isn't certified. And for many customers, it doesn't matter if it actually has the piece of paper to prove it or not.


The moment they mention left/right brain, lost credibility. How long does this myth have to be debunked before it catches up with the mainstream?


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: