Earlier quoted context omitted.
> We don't need to send any information to our service to protect you from bad sites because that is handled locally. The browser history already exists so the load on your machine is the same with or without Apozy. We use the headers to make it efficient for a large number of sites - 1M+ Okay so the local version is comparing the user's current page vs. the sites they've gone to prior? And if it seems off based on s…
> Wouldn't work for me though as I have my browser set to nuke everything each time it's closed. If you don't nuke your local storage, it should still work. I do suspect it may be more annoying without any browser history to go on because there's no model built, so you have to 'prime the pump' a little more than a user who has history would have to. -Erhan
Launch HN: Apozy (YC W17) – Use browsing habits to stop phishing and spot breaches
31–36 of 36 posts
Re: Launch HN: Apozy (YC W17) – Use browsing habits to stop phishing and spot breaches
#32Earlier quoted context omitted.
> Wouldn't work for me though as I have my browser set to nuke everything each time it's closed. If you don't nuke your local storage, it should still work. I do suspect it may be more annoying without any browser history to go on because there's no model built, so you have to 'prime the pump' a little more than a user who has history would have to. -Erhan
Are you storing a shadow browser history in localStorage?
Re: Launch HN: Apozy (YC W17) – Use browsing habits to stop phishing and spot breaches
#33Earlier quoted context omitted.
> Wouldn't work for me though as I have my browser set to nuke everything each time it's closed. If you don't nuke your local storage, it should still work. I do suspect it may be more annoying without any browser history to go on because there's no model built, so you have to 'prime the pump' a little more than a user who has history would have to. -Erhan
Are you storing a shadow browser history in localStorage?
Re: Launch HN: Apozy (YC W17) – Use browsing habits to stop phishing and spot breaches
#34Earlier quoted context omitted.
> We don't need to send any information to our service to protect you from bad sites because that is handled locally. The browser history already exists so the load on your machine is the same with or without Apozy. We use the headers to make it efficient for a large number of sites - 1M+ Okay so the local version is comparing the user's current page vs. the sites they've gone to prior? And if it seems off based on s…
> Wouldn't work for me though as I have my browser set to nuke everything each time it's closed. If you don't nuke your local storage, it should still work. I do suspect it may be more annoying without any browser history to go on because there's no model built, so you have to 'prime the pump' a little more than a user who has history would have to. -Erhan
I think opting in to the server side checking (which is a bit like the domain-based blacklists that modern browsers have, I think) is the best thing we've got at the moment, so long as that channel isn't compromised.
Re: Launch HN: Apozy (YC W17) – Use browsing habits to stop phishing and spot breaches
#35Earlier quoted context omitted.
> Wouldn't work for me though as I have my browser set to nuke everything each time it's closed. If you don't nuke your local storage, it should still work. I do suspect it may be more annoying without any browser history to go on because there's no model built, so you have to 'prime the pump' a little more than a user who has history would have to. -Erhan
With TOFU, "priming" equates to blind trust in practice. This is an important point even when you don't nuke on browser-quit. You can have TOFU (e.g., SSH), WoT (e.g., PGP), or PKI (e.g., TLS)... each with it's pros and cons. I can only hope that someday we have something without the "priming" hole of TOFU, the UX hurdles of WoT, and the fact that HTTPS doesn't really stop people from being phished. I think opting in…
Re: Launch HN: Apozy (YC W17) – Use browsing habits to stop phishing and spot breaches
#36Citation needed. I'm sure the number will look like that at companies who open and forward the email, doubt it's that high off the cuff.