Live data from Hacker News

Show HN: Hacker News' “most unique support email of 2014”

news.ycombinator.com

11–20 of 120 posts

Re: Show HN: Hacker News' “most unique support email of 2014”

#11
post #8

My gut says that they've disabled SSL v2/v3, and that the device does not support TLS.

Security Theater Everywhere strikes again. Unless you're logged in and entering data, Hacker News does not need SSL.

> Unless you're logged in and entering data, Hacker News does not need SSL

What about if you're in a country that likes to censor the news?

Re: Show HN: Hacker News' “most unique support email of 2014”

#12
post #8

My gut says that they've disabled SSL v2/v3, and that the device does not support TLS.

Security Theater Everywhere strikes again. Unless you're logged in and entering data, Hacker News does not need SSL.

Instead of continuing the trend of downvoting you:

Without SSL, you can't be sure of the integrity of the data set by the site. It's important even when not exchanging private data.

Re: Show HN: Hacker News' “most unique support email of 2014”

#13
post #10
post #8

Earlier quoted context omitted.

Security Theater Everywhere strikes again. Unless you're logged in and entering data, Hacker News does not need SSL.

So I should take it that you're OK with every country's intelligence agency modifying links on HN for their citizens, redirecting crypto downloads to trojaned pages for specific users, suppressing links that are overly critical of the government, right?

Protection against changes should be done with subresource integrity hashes (http://www.w3.org/TR/SRI/). With HTTPS, an observer still knows who you're talking to, and since they can see how big the request and reply are, they can probably guess what you're looking at.

Re: Show HN: Hacker News' “most unique support email of 2014”

#14
post #13
post #10

Earlier quoted context omitted.

So I should take it that you're OK with every country's intelligence agency modifying links on HN for their citizens, redirecting crypto downloads to trojaned pages for specific users, suppressing links that are overly critical of the government, right?

Protection against changes should be done with subresource integrity hashes ( http://www.w3.org/TR/SRI/ ). With HTTPS, an observer still knows who you're talking to, and since they can see how big the request and reply are, they can probably guess what you're looking at.

[deleted]

Re: Show HN: Hacker News' “most unique support email of 2014”

#16
post #13
post #10

Earlier quoted context omitted.

So I should take it that you're OK with every country's intelligence agency modifying links on HN for their citizens, redirecting crypto downloads to trojaned pages for specific users, suppressing links that are overly critical of the government, right?

Protection against changes should be done with subresource integrity hashes ( http://www.w3.org/TR/SRI/ ). With HTTPS, an observer still knows who you're talking to, and since they can see how big the request and reply are, they can probably guess what you're looking at.

SRI does not replace HTTPS.

You say they can guess what you're looking at with HTTPS.. well if you use SRI without HTTPS, then they don't need to guess.. they absolutely know what you're looking at.

Also, if they can change the page (which they can if it's over http), they can change the hash as well.

Also, SRI is like 9 months old since the first draft... which means it does nothing for the visitor unless they are using the newest version of one of the major browsers.

Re: Show HN: Hacker News' “most unique support email of 2014”

#19
post #15

Uniqueness is absolute, so the support email is either unique or not. There are no degrees of uniqueness for something to be more unique than another thing. Sorry, but this grammar mistake is a big pet peeve.

Now if we ever issue this award again we will be obliged to repeat the mistake forever. :)

Had I thought about it I probably would have written "most unusual". Still, I'm not sure the pedant's case holds up on this one. Two things may differ from everything else to varying degrees; both are unique, but the one that stands apart more is arguably more so. Even among the unique support requests of 2014, Rob's email stood apart the most by a long shot.

Re: Show HN: Hacker News' “most unique support email of 2014”

#20
post #15

Uniqueness is absolute, so the support email is either unique or not. There are no degrees of uniqueness for something to be more unique than another thing. Sorry, but this grammar mistake is a big pet peeve.

My dictionary lists two definitions for "unique." One is "being the only one of its kind" and is thus a binary property as you say, but the other is merely "particularly remarkable, special, or unusual," which is perfectly amenable to modifiers like this.
Post reply on HN