Live data from Hacker News

Viewing profile — johannh

johannh

HN member
Joined
Tue, Nov 13, 2012, 1:16 PM UTC
HN karma
593
Public activity
31 items

About johannh

No profile information was provided.

Recent public activity

  1. comment
    Comment #26243522

    Both the more technical blog post as well as the MDN page are linked shortly after that paragraph.

  2. comment
    Comment #26238175

    No, there’s no allow-list, you get the same heuristics as described on that MDN page.

  3. comment
    Comment #26238167

    Yes, it’s essentially that, FPI with workarounds for common breakage. You should switch from FPI, this is essentially another take on FPI by some of its original developers, so it …

  4. comment
    Comment #26238123

    (I’m one of the developers of this feature and co-author of the blog posts) This is a great question and I’m glad you found the answer, you probably understand that for many blog p…

  5. comment
    Comment #21981423

    If your users are clicking a button then it should actually show the permission prompt, unless you're losing the user interaction somewhere in the callback (by doing something asyn…

  6. story
  7. comment
    Comment #12014195

    Congrats! Please note that Servo is a work in progress that is still lacking some modern browser security features, so enjoy responsibly. See also https://github.com/servo/servo/la…

  8. story
  9. story
  10. comment
    Comment #9277712

    https://en.wikipedia.org/wiki/Egg_of_Columbus

  11. comment
    Comment #8661804

    I find it ironic if banks and post offices are using combination locks as advertised security measures but the people selling those install steel doors on their storefront.

  12. comment
    Comment #8660825

    True, I'm not surprised at all. HTTPS Everywhere-like functionality should be integrated into browsers and not a downloadable extra, tricking people into feeling fully secured.

  13. comment
    Comment #8660805

    > AMO doesn't do any code signing for extensions, so they're only protected by HTTPS. As we saw with Heartbleed, SSL private keys can be compromised. I find it quite ironic that HT…

  14. story
  15. story
  16. story
  17. story
  18. story
  19. story
  20. story
  21. comment
    Comment #8432469

    This was originally published a year ago in this blog post: http://berzniz.com/post/68001735765/javascript-hacks-for-hip... Makes for a nicer read than slideshare imo.

  22. comment
    Comment #8425948

    True, but it still feels like the right thing to do. I'd like people do be responsible when they discover a serious flaw in my programs, so I'll try to be responsible when discover…

  23. comment
    Comment #8425878

    This is something that could definitely have been reported to Slack before disclosing it publicly. Maybe he did that, but it's not mentioned in the blog post so I assume he didn't.…

  24. story
  25. story