Live data from Hacker News

“Users will only be able to view patents via HTTP. HTTPS will no longer work”

uspto.gov

151–160 of 172 posts

Re: “Users will only be able to view patents via HTTP. HTTPS will no longer work”

#151
post #33

To be picky: >Immediately after the maintenance, users will only be able to access Public PAIR through URLs beginning with HTTP, such as http://portal.uspto.gov/pair/PublicPair . Past URLs using HTTPS to access Public Pair, such as ... A URL beginning with HTTPS ALSO begins with HTTP

I see what you did there.

Re: “Users will only be able to view patents via HTTP. HTTPS will no longer work”

#152
post #83

Earlier quoted context omitted.

Please provide rationale showing that the associated risks outweigh the immense fun of "meatspinning" coworkers. "Don't do this" is probably not very convincing.

https://it.slashdot.org/story/08/06/18/2213232/man-fired-whe... Don't be the person that gets someone fired, arrested, jailed, and in lifetime legal trouble because some asshole thought it would be hilarious to display porn on their computer at work. (Yes, I'm equating "meatspinning" to malware. Argue if you like about that, but the main point stands: If you meatspin someone, you're taking a chance of ruining their e…

> Don't be the person that gets someone fired, arrested, jailed, and in lifetime legal trouble because some asshole thought it would be hilarious to display porn on their computer at work.

Not to defend "meatspinning" (first time I've heard the term), but don't you think the real problem here is that people can be fired/jailed/etc without due process is the problem here? This was just some drive by malware, imagine what you could do to someone's life if you intentionally targeted someone?

Re: “Users will only be able to view patents via HTTP. HTTPS will no longer work”

#153

The USPTO databases have to be one of the most torturous services to their users in the whole of internet. The UI of both the patent and trademark search is archaic, but not in a HN way but in a really bad way. In patent search, there is no "search" box. Instead, the "quick search" forces you to specify two (and exactly two) text queries on the database columns with obligatory boolean operation.[1] Even if you happen…

Has anyone built an open index, legal or otherwise? Doesn't seem like it would be too hard to script the downloads and build a real search tool for it.

Re: “Users will only be able to view patents via HTTP. HTTPS will no longer work”

#154
post #30

Earlier quoted context omitted.

If you look at the url, you notice they are using CGI and Win32 EXEs

You can't know that. It could have been redeveloped in anything, but kept the original url scheme for backwards compatibility.

The URLs in question have no backwards compatibility, by design.

Re: “Users will only be able to view patents via HTTP. HTTPS will no longer work”

#155

Earlier quoted context omitted.

crypto offloading isn't hard, and can be done on the NIC if you want/need: https://www.nextplatform.com/2016/10/03/server-encryption-fp...

Can you show us how to configure that on a typical box?

Of course, but that is chargeable work.

Re: “Users will only be able to view patents via HTTP. HTTPS will no longer work”

#156

Earlier quoted context omitted.

Does F5 do any special secret sauce that can't be replicated with an equally powerful set of hardware and a good HAProxy config? Not unless you think "extract a lot of money from clueless execs" is secret sauce. That, and support contracts - you know, throats to choke when it all goes wrong.

BigIP's iRules (Tcl) are pretty nice. ( https://devcentral.f5.com/irules ). I hear HAproxy has Lua support now, but I don't know how comprehensive it is compared to iRules. Also, F5 load balancers have real hardware failover capability, and can even synchronize TCP session state across instances. That's a pretty nice feature.

I worked with BigIP for a few years, and I believe that the real value is in the support contracts, and the peace of mind that gives to enterprise execs. failover (local or global) as well as state sync is all do-able with linux or bsd, but that will take time and work. BigIP is more or less plug and play. This is the case for many "enterprisey" products. Personally, I prefer to go the linux/bsd route, since it forces you and your team to have a deeper understanding of what you are building, which is really handy for when things break.

Re: “Users will only be able to view patents via HTTP. HTTPS will no longer work”

#157
post #152

Earlier quoted context omitted.

https://it.slashdot.org/story/08/06/18/2213232/man-fired-whe... Don't be the person that gets someone fired, arrested, jailed, and in lifetime legal trouble because some asshole thought it would be hilarious to display porn on their computer at work. (Yes, I'm equating "meatspinning" to malware. Argue if you like about that, but the main point stands: If you meatspin someone, you're taking a chance of ruining their e…

> Don't be the person that gets someone fired, arrested, jailed, and in lifetime legal trouble because some asshole thought it would be hilarious to display porn on their computer at work. Not to defend "meatspinning" (first time I've heard the term), but don't you think the real problem here is that people can be fired/jailed/etc without due process is the problem here? This was just some drive by malware, imagine w…

Also worth adding that it was kiddie pr0n that got the guy fired in parent's story. Quite a lot of people tend to overreact to this for either CYA or moral high horse reasons.

If he was fired for meatspin or lemonparty, he would publicly accuse them of homophobia on twitter and things would be different ;)

Re: “Users will only be able to view patents via HTTP. HTTPS will no longer work”

#160
post #33

To be picky: >Immediately after the maintenance, users will only be able to access Public PAIR through URLs beginning with HTTP, such as http://portal.uspto.gov/pair/PublicPair . Past URLs using HTTPS to access Public Pair, such as ... A URL beginning with HTTPS ALSO begins with HTTP

To be pickier, they never said that all URLs beginning with 'HTTP' would be enabled, merely that URLs beginning with something other than HTTP would be disabled, and also that URLs beginning with 'HTTPS' would be disabled. They never stated that HTTPS was part of the "doesn't begin with HTTP" group.
Post reply on HN