Probably not a good person to piss off. Several months ago I recall a website owner posted a bug to Firefox saying he didn’t need HTTPs and that Firefox shouldn’t tell users it’s insecure. Within hours his database was pwned.
HTTPS on Your Landing Page Is Important
111–120 of 307 posts
Re: HTTPS on Your Landing Page Is Important
#112Earlier quoted context omitted.
That's typosquatting and it's not very ethical. It's also in a grey legal zone, you might get sued for this. So I would advise you not to do it.
Do you have any examples of "You might get sued for this"?
Re: HTTPS on Your Landing Page Is Important
#113That feeling when you're arguing with an idiot, and the idiot isn't listening because he thinks it's YOU who's missing the point.
The important thing for all of us to remember, is that in any given conversation we may be idiot. Until I'm sure the other person doesn't know what they're talking about, I try and assume they're right.
Alternative take, particularly pertinent to this situation:
The person handling twitter is not a technical person, but a customer support person who handles hundreds of dumb questions, day in, day out, from customers who have no clue what they're doing but will often throw technical terms around.
Expecting solid technical answers from a general twitter account for a business is beyond absurd.
Re: HTTPS on Your Landing Page Is Important
#114About 8 years ago Natwest had a policy of having a "browser whitelist" which was rarely updated. Each time a security update for chrome or firefox came out it would be 2 weeks before online banking was accessible, and using any pre-release versions were out of the question. I complained and a member of the dev team phoned me up and after a long discussion about why this was madness he told me that it was better to us…
When I worked for Chase on their main app, the policy for support was the current version of the browser, minus one.
The app is pretty great.
Re: HTTPS on Your Landing Page Is Important
#115Probably not a good person to piss off. Several months ago I recall a website owner posted a bug to Firefox saying he didn’t need HTTPs and that Firefox shouldn’t tell users it’s insecure. Within hours his database was pwned.
Re: HTTPS on Your Landing Page Is Important
#116Probably not a good person to piss off. Several months ago I recall a website owner posted a bug to Firefox saying he didn’t need HTTPs and that Firefox shouldn’t tell users it’s insecure. Within hours his database was pwned.
Besides, if the DB was pwned, it is unlikely that http -> https would have any real bearing anyway. There was probably a XSS exploit or whatever.
Re: HTTPS on Your Landing Page Is Important
#117Earlier quoted context omitted.
Do you have any examples of "You might get sued for this"?
There is the horrible example of the nice computer company that had called itself by a certain name. [1] They registered their domain in good faith and conducted business. Later, a multi-million dollar car company decided they wanted the domain for the name they choose after Datsun and lawyered up on the mom-and-pop computer company. 1: http://nissan.com/
Re: HTTPS on Your Landing Page Is Important
#118It seems that every time Troy interacts with a company on Twitter, they never seem to click on to who he is, until it's probably too late and they look like fools.
It's just so amusing to see companies trying to condescend to Troy, when he's one of the most visible authorities on web security on the planet (not necessarily the most authoritative, but the most well known).
I occasionally get this when people try talking to me about computer science topics, when they don't realise that it's what I do for a living. I've probably done the same myself when talking to Doctors and other domain experts, I'm sure.
Re: HTTPS on Your Landing Page Is Important
#119It's 2017, and my social media account is protected by a tamper-proof phish-resistant embedded-encryption U2F microcontroller dongle, in addition to a password of virtually unlimited length and charset. Meanwhile, my bank has a max password length of 12 and I can only use an alphabet of roughly 64 characters. The future is here folks. And it sucks.
What's worse, because it can be entered on the phone, aAbBcC are all == 1. So it's really just 6 digits.
Re: HTTPS on Your Landing Page Is Important
#120It's 2017, and my social media account is protected by a tamper-proof phish-resistant embedded-encryption U2F microcontroller dongle, in addition to a password of virtually unlimited length and charset. Meanwhile, my bank has a max password length of 12 and I can only use an alphabet of roughly 64 characters. The future is here folks. And it sucks.
So the passwords 'abc' 'ABC' and '222' are treated as equivalent. Try it out for fun!