Live data from Hacker News

Elementary OS Freya Released

elementary.io

41–50 of 95 posts

Re: Elementary OS Freya Released

#41
post #37

Earlier quoted context omitted.

It doesn't matter who it's handled by, the fact is that credit card numbers are being transferred over regular, non-encrypted HTTP.

Actually, it does matter. The webpage might be http, but the Stripe Javascript library connects to Stripe's servers over https . The website never sees your card number and your card number and info is never transmitted over a non-encrypted connection.

In that case the process is merely broken from a usability standpoint (a user can't click on the browser padlock to verify certificate information).

Which is ironic.

Re: Elementary OS Freya Released

#42
post #37

Earlier quoted context omitted.

It doesn't matter who it's handled by, the fact is that credit card numbers are being transferred over regular, non-encrypted HTTP.

Actually, it does matter. The webpage might be http, but the Stripe Javascript library connects to Stripe's servers over https . The website never sees your card number and your card number and info is never transmitted over a non-encrypted connection.

I had to look around for a minute to find the "powered by stripe" message in the bottom left corner of the overlay. Simply seeing that message shouldn't be synonymous with security. I'm trained to look for the secure lock in the address bar of the browser.

Re: Elementary OS Freya Released

#43
post #37

Earlier quoted context omitted.

It doesn't matter who it's handled by, the fact is that credit card numbers are being transferred over regular, non-encrypted HTTP.

Actually, it does matter. The webpage might be http, but the Stripe Javascript library connects to Stripe's servers over https . The website never sees your card number and your card number and info is never transmitted over a non-encrypted connection.

Since the page is loaded over plaintext, there's no easy way for a normal user to know that the credit card isn't being intercepted by a malicious script. It's not safe to serve a payment page over plaintext HTTP, even if it POSTs to a HTTPS endpoint as it could be modified in transit.

Stripe explains that TLS is required in their docs: https://stripe.com/help/ssl

Re: Elementary OS Freya Released

#46
post #25

Only negativity in this thread. You're being offered a desktop environment for free, and all you can do is point out its problems. I think it looks pretty slick, and will give it a try, why are people so nitpicky here?

It's things like [1] that really irk me. Yes, they're working 'hard', yes they deserve compensation, no, there isn't any license conflicts (that I'm aware of) that would make selling eOS illegal, it's the fact that they wrote this justification to make you feel like a thief. Really, it's just an ubuntu clone with a pretty osx-like gui. This isn't really anything amazing or new, and it makes it seem like they're tryin…

> This isn't really anything amazing or new

One counterexample: Contractor, an Android Intents-like system for sharing data between apps.

https://web.archive.org/web/20130314024115/http://elementary...

(archive.org link because this info doesn't seem to be on their new site, for whatever reason...)

There are other technologies like Switchboard and Granite that are unique to Elementary OS, and many of the user-facing apps were written from scratch.

Re: Elementary OS Freya Released

#48

There is no upgrade path from OS Luna (previous release) to Freya. Their own web site states, "elementary OS Luna users should back up their data and perform a clean install". Given that the operating system is built on Ubuntu I should be able to upgrade from Luna to Freya without too many issues. Disappointed? Yes. I wrote this post on my Cr-48 running Elementary OS Luna. Instead of running Apt to update my laptop n…

Ah yes, because you're unhappy with a build-everything-new OS, so you're going to DW to look for even newer distros? Well, good luck.

Re: Elementary OS Freya Released

#50
It really saddens me how much people underestimate the effort it takes to create a good UI by saying eOS is just a "pretty Ubuntu clone".

I don't think their blog post[1] is offensive at all. Ubuntu does this too. [2]

People consider Sublime's popup and "unregistered user" acceptable. How often do you install/download eOS? Once in a year? And you use it every-day, not only when you do text-editing. And there is no difference between paid or free user.

[1]: http://blog.elementary.io/post/110645528530/payments [2]: http://www.ubuntu.com/download/desktop/contribute/?version=1...

Post reply on HN