Live data from Hacker News

Show HN: Hacker News' “most unique support email of 2014”

news.ycombinator.com

61–70 of 120 posts

Re: Show HN: Hacker News' “most unique support email of 2014”

#61
post #13
post #10

Earlier quoted context omitted.

So I should take it that you're OK with every country's intelligence agency modifying links on HN for their citizens, redirecting crypto downloads to trojaned pages for specific users, suppressing links that are overly critical of the government, right?

Protection against changes should be done with subresource integrity hashes ( http://www.w3.org/TR/SRI/ ). With HTTPS, an observer still knows who you're talking to, and since they can see how big the request and reply are, they can probably guess what you're looking at.

See also: https://news.ycombinator.com/item?id=8910637.

Subresource integrity can protect against changes done on the server, while TLS can protect against changes done by a man-in-the-middle. They protect against different things, and do not significantly overlap.

Re: Show HN: Hacker News' “most unique support email of 2014”

#62
post #56

Earlier quoted context omitted.

I would urge you to, like I realised I had to a few years ago, get over it. Language is not defined by a dictionary or by history; roots and origins are truly meaningless. A word is defined by its usage; it’s one of the delightful things in the world for which it can be said that if enough people say something is true, it becomes true. Uniqueness may once have been a boolean property (I cannot say for certain one way…

Should we accept incorrect usage of language that is more confusing than the correct usage? For instance, using "begs the question" instead of "raises the question". It causes a lot of confusion because people cannot even agree what the misusage of "begs the question" means and it is never a better choice of words than "raises the question" if that is what someone means.

Rarely are we in a position to "accept" or "deny" changes in language. They just happen, with or without our consent. All we can do is try to keep up and make some sense of the current state.

Re: Show HN: Hacker News' “most unique support email of 2014”

#63
post #13
post #10

Earlier quoted context omitted.

So I should take it that you're OK with every country's intelligence agency modifying links on HN for their citizens, redirecting crypto downloads to trojaned pages for specific users, suppressing links that are overly critical of the government, right?

Protection against changes should be done with subresource integrity hashes ( http://www.w3.org/TR/SRI/ ). With HTTPS, an observer still knows who you're talking to, and since they can see how big the request and reply are, they can probably guess what you're looking at.

No. Subresource Integrity Hashing allows an HTTPS site to use the trusted channel that TLS provides to verify the content of external resources it includes, even if those external resources are delivered over HTTP. There still has to be an HTTPS site to provide a root of trust.

For example, example.com (delivered over HTTPS) could use jquery, and include in the page it delivers to you both the URL and a hash of the jquery scripts; you could then fetch those scripts over untrusted channels or from untrusted servers, and be sure that they are the ones that the administrators of example.com intended to reference. If example.com were not using HTTPS at all, then they could just be the resources that the Man In The Middle of your channel to example.com intended you to see.

Re: Show HN: Hacker News' “most unique support email of 2014”

#64

My gut says that they've disabled SSL v2/v3, and that the device does not support TLS.

Same happened to me trying to use Safari Books Online on my Kindle browser (as the only official way yo access their content on an eInk display). They dropped SSLv3, and in doing so the old 'experimental' Kindle browser can no longer access it.

Re: Show HN: Hacker News' “most unique support email of 2014”

#65

I used a Palm treo up until about 3 years ago, and used to browse HN quite often. My treo was modified and upgraded I should say :) beleive it or not, some poor soul actually stole it, probably not knowing it would be worth more on ebay as an obscure item than at a pawn shop.

Yeah, fellow former Treo user here. I loved that thing.

When people talk about how Steve Jobs invented the smartphone, I used to say, "but but but..." Now, though, I just sigh and nod like I'm still listening to them.

Re: Show HN: Hacker News' “most unique support email of 2014”

#66
post #28

Earlier quoted context omitted.

"unique" comes directly from the Latin "unus", one. The modernist, American wishy-washy uses of the word to mean "unusual" are a sad travesty of thinking. One should simply use the word "unusual" if that's what one means to say.

If you think words gaining new and changing meanings is "a sad travesty", then I think you are a nice person -- and I don't mean in the modern sense of the word.

The problem isn't gaining meanings; it's losing them. If unique becomes a synonym for unusual, then we no longer have a word that means unique.

I think these battles are worth fighting. As does Weird Al: https://www.youtube.com/watch?v=RGWiTvYZR_w

Re: Show HN: Hacker News' “most unique support email of 2014”

#67
post #47
post #26

Earlier quoted context omitted.

I totally agree (although you need more than SRI, since you also need some way of signing the original content, but I'd love to see a full spec for this sort of thing). However, SSL is what we have right now that works. And I think, of the browsers that do support SRI (possibly in prerelease versions or behind feature flags), they require the page to be delivered over SSL anyway.

HTTPS is broken by content delivery networks who terminate SSL connections. HTTPS Everywhere makes the problem worse, by increasing load for static pages and breaking caches, forcing sites to use a content delivery network. Take a look at that HTTPS certificate that you think means you're talking to the site of your choice. If it says "cloudflare.com", "incapsula.com", "edgecastcdn.com", "palmwebservices.com", "cdnet…

You seem to be extremely confused about how HTTPS works. If the site I'm visiting chooses to give a certificate to cloudflare for their service, that is their choice. What they choose to do server side is completely out of a customer's hands no matter how secure the protocol.

Even with CDN terminating SSL, it protects you from injected malware and ADs between you and the CDN by your ISP.

Re: Show HN: Hacker News' “most unique support email of 2014”

#68
post #19
post #15

Uniqueness is absolute, so the support email is either unique or not. There are no degrees of uniqueness for something to be more unique than another thing. Sorry, but this grammar mistake is a big pet peeve.

Now if we ever issue this award again we will be obliged to repeat the mistake forever. :) Had I thought about it I probably would have written "most unusual". Still, I'm not sure the pedant's case holds up on this one. Two things may differ from everything else to varying degrees; both are unique, but the one that stands apart more is arguably more so. Even among the unique support requests of 2014, Rob's email stoo…

Take the following definition of unique - being the only one of its kind; unlike anything else.

So if something is 'more unique' than something else, it doesn't really fit the first part of the definition because they are both only one of a kind, but it fits with the second in that it is more unlike anything else than the other thing.

Re: Show HN: Hacker News' “most unique support email of 2014”

#69
post #66

Earlier quoted context omitted.

If you think words gaining new and changing meanings is "a sad travesty", then I think you are a nice person -- and I don't mean in the modern sense of the word.

The problem isn't gaining meanings; it's losing them. If unique becomes a synonym for unusual, then we no longer have a word that means unique. I think these battles are worth fighting. As does Weird Al: https://www.youtube.com/watch?v=RGWiTvYZR_w

I don't know why Weird Al thought that was necessary, but this supposed less vs fewer "rule" does not describe actual modern or historical usage. Self-appointed grammarians can choose to stick to whatever usage they like, but going around with stickers and marker pens only makes them look like pedantic bores.

Re: Show HN: Hacker News' “most unique support email of 2014”

#70
post #47

Earlier quoted context omitted.

HTTPS is broken by content delivery networks who terminate SSL connections. HTTPS Everywhere makes the problem worse, by increasing load for static pages and breaking caches, forcing sites to use a content delivery network. Take a look at that HTTPS certificate that you think means you're talking to the site of your choice. If it says "cloudflare.com", "incapsula.com", "edgecastcdn.com", "palmwebservices.com", "cdnet…

HTTPS does not break caches; that's FUD. Browsers can cache HTTPS pages just fine, and do by default unless told not to. Nothing forces sites to use a CDN. HTTPS, by itself, does not massively increase load. If the limiting factor of your web server is how fast you can do cryptographic operations for HTTPS, you're doing rather well; most of the time that won't be your limiting factor. Using a CDN is not wildly less s…

  HTTPS does not break caches; that's FUD. Browsers can cache 
  HTTPS pages just fine
Yes, but caching by intermediaries is a very important part of HTTP caching, and HTTPS effectively breaks that, does it not?
Post reply on HN