The USPTO databases have to be one of the most torturous services to their users in the whole of internet. The UI of both the patent and trademark search is archaic, but not in a HN way but in a really bad way. In patent search, there is no "search" box. Instead, the "quick search" forces you to specify two (and exactly two) text queries on the database columns with obligatory boolean operation.[1] Even if you happen…
“Users will only be able to view patents via HTTP. HTTPS will no longer work”
51–60 of 172 posts
Re: “Users will only be able to view patents via HTTP. HTTPS will no longer work”
#52Earlier quoted context omitted.
Does F5 do any special secret sauce that can't be replicated with an equally powerful set of hardware and a good HAProxy config? I know one of our network admins is continually complaining about how shitty their UI is...
F5 has some secret sauce to it but it's mostly performance related. They have a good chunk of hardware offloading, all the way up to the TLS layer. I seem to remember even the entry license includes full TLS offloading so I doubt the poster above is correct that it is a cost issue. As to if HAProxy can do the job, well, that depends. F5s are complex beasts and they can load balance application specific protocols that…
Re: “Users will only be able to view patents via HTTP. HTTPS will no longer work”
#53*https://thestack.com/security/2017/04/12/netflix-found-to-le...
Re: “Users will only be able to view patents via HTTP. HTTPS will no longer work”
#54There has been a XSS vulnerability in the USPTO site since 2008 I reported. It still worked in 2014. Meatspinned quite a few coworkers using it.
Don't do this.
Re: “Users will only be able to view patents via HTTP. HTTPS will no longer work”
#55I wonder if 18f can help at all, it seems agencies must contact 18f themselves.
1: https://www.digitalgov.gov/2017/04/12/dotgov-domain-registra...
Re: “Users will only be able to view patents via HTTP. HTTPS will no longer work”
#56This would be interesting for patent research; you could legitimately say "I looked for a patent that already covers X but since you cannot guarantee the data was not modified in transit, I cannot be certain that I saw what was actually in the patents I reviewed".
Re: “Users will only be able to view patents via HTTP. HTTPS will no longer work”
#57Earlier quoted context omitted.
Does F5 do any special secret sauce that can't be replicated with an equally powerful set of hardware and a good HAProxy config? I know one of our network admins is continually complaining about how shitty their UI is...
F5 has some secret sauce to it but it's mostly performance related. They have a good chunk of hardware offloading, all the way up to the TLS layer. I seem to remember even the entry license includes full TLS offloading so I doubt the poster above is correct that it is a cost issue. As to if HAProxy can do the job, well, that depends. F5s are complex beasts and they can load balance application specific protocols that…
Re: “Users will only be able to view patents via HTTP. HTTPS will no longer work”
#58Also, at the bottom of the page "This page is owned by Service Desk." What does that mean? And it's legal to publish a .GOV site using Drupal?
Re: “Users will only be able to view patents via HTTP. HTTPS will no longer work”
#59Fun fact: HSTS https://securityheaders.io/?q=www.uspto.gov&followRedirects=... HSTS is 1 year at the time this comment is posted. They're in for some pain.
They are basically going to be DOSing a huge segment of users who've previously had that header set on their browsers...they're also violating the OMB mandate that requires TLS for all government sites...it is a rather strange move, I can't imagine there is a good reason for it.
EDIT If it is for portal.uspto.gov then HSTS is a non-issue but still a very bad move.
Re: “Users will only be able to view patents via HTTP. HTTPS will no longer work”
#60Earlier quoted context omitted.
Well if you put on your tinfoil hat - maybe someone wants to track who's viewing which patents, which they can't do when it's encrypted. You're right, it doesn't make any sense to do this, so there must be an ulterior motive.
If that were the case and USPTO were in on the trick, why the need to drop HTTPS? They'd have that data already, so could just share it directly.