Live data from Hacker News

Viewing profile — marumari

marumari

HN member
Joined
Thu, Aug 25, 2016, 7:22 PM UTC
HN karma
86
Public activity
16 items

About marumari

Security Engineer.

[ my public key: https://keybase.io/april; my proof: https://keybase.io/april/sigs/kNfkel8VNf5CwWpxGsWj4xZMhGcxTagssfbA0FxUpqw ]

Recent public activity

  1. comment
    Comment #42208752

    Safari is a lot more strict about cookies than Chromium or Firefox, it will straight up drop or ignore (or, occasionally, truncate) cookies that the other two will happily accept. …

  2. comment
    Comment #42207036

    Thanks for pointing that out -- I've updated the article and given you credit down at the bottom. Let me know if you'd prefer something other than "kibwen."

  3. comment
    Comment #35888330

    An unspecified "implementation detail" is essentially another way of saying that it doesn't work. I've ported my account on ActivityPub a couple time, and it's a horrendous experie…

  4. comment
    Comment #33825294

    Platform keys are only required to be v2, as far as my understanding goes.

  5. comment
    Comment #33755751

    this is a terrible time of year for interviewing, most places won’t be adding headcount until january.

  6. comment
    Comment #24579895

    I guess we just have different definitions of what "broken" means, since disconnecting Gecko sounds fairly broken to me. :)

  7. comment
    Comment #24578119

    Because huge chunks of are broken in the new browser engine, and could leave your browser in an unrecoverable state.

  8. comment
    Comment #20331727

    X25519 is the mechanism for using Curve25519. Software that uses OpenSSL all uses “X25519” and so it would be needlessly confusing to use other verbiage despite being more technica…

  9. comment
    Comment #15369475

    Both uBlock Origin and Tree Style Tabs (as well as Tab Center Redux, which I prefer) are already compatible with Firefox 57.

  10. comment
    Comment #15369442

    You can do the same in Firefox. It's under Tools -> Web Developer -> Browser Toolbox.

  11. comment
    Comment #15082212

    Connections to the Mozilla Telemetry server are done over HTTPS, so all an interceptor would know is that you are sending Telemetry and not what that Telemetry is.

  12. comment
    Comment #13081867

    > If AV was so vulnerable, we'd see nothing but exploits in the wild going after AV. Yet we aren't seeing that anywhere. That's because the Linux kernel, Chrome, Firefox, etc. are …

  13. comment
    Comment #12363032

    On the plus side, there are sites doing really well, like GitHub (A+), HackerOne (A+), and Twitter (A). Even Facebook is doing pretty well, with a B. Hopefully sites like the Obser…

  14. comment
    Comment #12362912

    The nice thing is that most of the security measures -- aside from Subresource Integrity -- can be done without changing any of the actual content.

  15. comment
    Comment #12362336

    It also has an invalid website certificate. Kind of a shame that it's so neglected, but it's a pretty good example of what happens to sites when they're allowed to sit for too long…

  16. comment
    Comment #12361893

    I'm the primary developer of the scanner and website, and would be happy to answer anybody's questions, should they have any. :)