Conversation
Notices
-
Danyl Strype (strypey)'s status on Monday, 16-Apr-2018 06:06:05 CEST
Danyl Strype
https://www.howsmyssl.com/ -
Danyl Strype (strypey)'s status on Monday, 16-Apr-2018 14:31:05 CEST
Danyl Strype
@budkin #1 it's Lunduke, and his sponsored #clickbat is best taken with a grain of salt ... -
Danyl Strype (strypey)'s status on Monday, 16-Apr-2018 14:35:28 CEST
Danyl Strype
@budkin ... Problem #1: solution is #certbot. Problem #2: solution is cert authorities like Let's Encrypt ... -
Danyl Strype (strypey)'s status on Monday, 16-Apr-2018 14:38:00 CEST
Danyl Strype
@budkin #SHA Lunduke doesn't know the difference between an algorithm and a program. SHA implemented by free code isn't subject to #NSA -
Danyl Strype (strypey)'s status on Monday, 16-Apr-2018 14:39:00 CEST
Danyl Strype
@budkin here's someone who knows their shit writing about #HTTPS
https://blog.codinghorror.com/lets-encrypt-everything/ -
Danyl Strype (strypey)'s status on Monday, 16-Apr-2018 14:43:25 CEST
Danyl Strype
@budkin plus the crypto HTTPS uses isn't baked in. SSL was replaced with TLS, HTTPS didn't break. If SHA was compromised it can be swapped -
Danyl Strype (strypey)'s status on Monday, 16-Apr-2018 14:43:52 CEST
Danyl Strype
@budkin sure, which is why we're now up to SHA-3. See my last point -
Danyl Strype (strypey)'s status on Monday, 16-Apr-2018 15:16:05 CEST
Danyl Strype
@budkin ok. Have you been in touch with #LetsEncrypt about this? If so, what do they say? -
Danyl Strype (strypey)'s status on Monday, 16-Apr-2018 15:17:50 CEST
Danyl Strype
@budkin Lunduke is, like me, an opinionated user. Jeff Atwood co-created both #StackExchange and #Discourse ... -
Danyl Strype (strypey)'s status on Monday, 16-Apr-2018 15:18:49 CEST
Danyl Strype
@budkin ... Brian would have to raise some pretty strong and well-referenced arguments before I take his opinion over Jeff's ... -
Danyl Strype (strypey)'s status on Monday, 16-Apr-2018 15:20:01 CEST
Danyl Strype
@budkin ... let alone over *everyone* at #Mozilla and the #InternetSociety . It doesn't prove he's wrong, but Brian's HTTPS views are fringe -
Danyl Strype (strypey)'s status on Monday, 16-Apr-2018 18:56:20 CEST
Danyl Strype
@budkin "involved" doesn't always mean *useful*. Brian is know to get stuff totally wrong, then instead of self-correcting, he doubles down -
Danyl Strype (strypey)'s status on Monday, 16-Apr-2018 18:57:49 CEST
Danyl Strype
@budkin I really don't want to watch his self-promotional FUD in full, but I'm happy to discuss HTTPS issue with you here. Shoot! -
Danyl Strype (strypey)'s status on Monday, 16-Apr-2018 19:08:29 CEST
Danyl Strype
@budkin BTW did you read the older post linked at the top of that one?
https://blog.codinghorror.com/should-all-web-traffic-be-encrypted/
-