"I’ve been speaking with the owner about SSL before I invest in becoming a member, but she’s been told by the dev of the platform (it’s a franchise system called ShopCity.com) that SSL is more about Google’s monopolizing visibility of content, and less to do with security" This is an interesting observation of how Google's technical crusades often align with its profit interests. The main threat that HTTPS everywhere…
> The main threat that HTTPS everywhere secures against is preventing your ISP from analyzing your traffic in order to build and sell an advertising profile on you. That is not true. The main threat it protects against is MitM (man in the middle attacks) that allow someone to redirect all traffic to a website through their machine and thus see all the data including your password. HTTPS when combined with root certif…
Bypassing Browser Security Warnings with Pseudo Password Fields
91–100 of 127 posts
Re: Bypassing Browser Security Warnings with Pseudo Password Fields
#92Earlier quoted context omitted.
I don't want my ISP to inject JavaScript to random pages or analyze my traffic. That should be downright illegal. They should be like water supply company: provide me damn clean water and get out of my way. Somehow the sewage company doesn't analyze my urine (I hope ) to figure out if I prefer spicy or sour food and get an extra buck from third parties, and somehow they're still in the business .
> I don't want my ISP to inject JavaScript to random pages or analyze my traffic. I haven't seen a single reputable ISP do this anywhere. It would illegal. Is the US really such a third world nation that not even basic regulation like this exist?
Re: Bypassing Browser Security Warnings with Pseudo Password Fields
#93Earlier quoted context omitted.
Giving everyone SIP phones is expensive, and forcing your subscribers to purchase SIP phones will ensure a number of them flee to the competition. Putting the VOIP hardware in the modem makes much more sense, because you have to provide that to your subscribers anyway.
I actually have my own Cisco Phone adapter to connect my old analog phone/answering machine. I'd assume that a true SIP phone would work as well. What's questionable is whether I could authenticate from a different network than my home network. I know, however, that both Vodafone and Telekom in Germany offer products that allow connecting VOIP phones from anywhere to a virtual phone appliance.
Re: Bypassing Browser Security Warnings with Pseudo Password Fields
#94Earlier quoted context omitted.
I've seen PBX people find religion once they wake up Monday morning to a weekend of hacked calls to Africa. Though sometimes that religion is in the form of yelling at upstream providers to please give them refunds. And because of these insecure systems, the more serious issues (all this SIP software is tons of C, and I've found exploits in just 1000 line utilities, let alone protocol level hackery and other fun) get…
SIP... doesn't seem like the greatest protocol. Maybe I'm tainted because I've only really dealt with it in the context of the Microsoft IM/telephony platforms (renamed constantly, but always essentially the same), but it appears to be incredibly brittle complicated. On anything less than a local LAN, messages get dropped or mangled or timed out all the time, and that trashes connections, or puts sessions into unreco…
Re: Bypassing Browser Security Warnings with Pseudo Password Fields
#95Troy Hunt is attempting to claim this is a feature and not a bug, and that their workaround is "being deceptive", when they never claimed it was secure to begin with.
The browser is literally pushing an idealistic philosophy down websites' throats and basically doing damage to businesses and brands without an attempt to help them, and any attempts to simply keep old functionality are being vilified as "anti-vaxers". This is not an honest narrative.
Yes, Oil and Gas International had an insecure site, and yes, their reaction and demand to the browser vendor was inappropriate. But the point of it is still valid: as a vendor, you don't embarrass and damage business reputations in order to force them to comply with the way you would like them to run their sites.
Troy writes in the article that browser vendors are trying to use a "lever" to "force organizations to go secure". I don't care who you are, it's wrong to force anyone to do anything they don't want to do, and on your timeline instead of theirs, and with absolutely no help given to them before this deadline.
Imagine if Microsoft changed their OS to flag every single application as "insecure" if it doesn't implement a new primitive, and they pushed this out today. All of a sudden, you receive a barrage of calls from upset users. You didn't know they were going to push that out (certainly Microsoft never sent you an e-mail), and you now have to hit the ground running trying to figure out how to add those primitives to your code, test them, and release them, none of which could possibly happen immediately, and may take weeks of development. Meanwhile, your reputation with your users is damaged, and users themselves go through emotional stress and fear. And Microsoft's response? "Too bad. You should have been secure already."
This is fucked up. And if Google does this knowing it's going to damage businesses, they could face a class-action lawsuit.
The only way they get away with it is because they have the biggest market share. If Chrome had a smaller user base, businesses would simply shut off access to Chrome browsers and tell them their browsers were faulty and to switch to IE. This is impressively tyrannical behavior for a software vendor, and Google is indeed being a bully.
Re: Bypassing Browser Security Warnings with Pseudo Password Fields
#96Earlier quoted context omitted.
> The main threat that HTTPS everywhere secures against is preventing your ISP from analyzing your traffic in order to build and sell an advertising profile on you. That is not true. The main threat it protects against is MitM (man in the middle attacks) that allow someone to redirect all traffic to a website through their machine and thus see all the data including your password. HTTPS when combined with root certif…
MitM is blown out of proportion. Afaik, only dns poisoning attacks will result in MitM as effective as phishing or botnets, and poisoning can be mostly-solved with better resolvers. No criminal anywhere cares about your password going over the wire in a coffee shop.
The one thing that reduces the likelihood of that happening is to minimize the amount of credentials you could get your hands on using that attack.
Re: Bypassing Browser Security Warnings with Pseudo Password Fields
#97Earlier quoted context omitted.
You could potentially use the validation rules, and set a min length of 1.
You'd need [required] instead of [minlength] for :valid to work. The other option is :placeholder-shown, to style no-input normally, but it's newer and not as supported.
Re: Bypassing Browser Security Warnings with Pseudo Password Fields
#98Earlier quoted context omitted.
I've been supplying information and you've been complaining. I fail to see how I'm at fault for trying to answer questions.
You didn't just talk about the debate. You stated as a fact that many vaccines have improper testing or substances. If you state something as a fact, you should be prepared to back it up.
You're putting words in my mouth. What I said was "...without what many would consider..."
I'm still taking about the debate itself and you're trying to make this a binary debate about vaccination.
Re: Bypassing Browser Security Warnings with Pseudo Password Fields
#99Earlier quoted context omitted.
I'm assuming you're talking about consumer VoIP; in the corporate world, Cisco (and presumably others) do a crapload of VoIP office phones.
I also haven't seen an office phone in ages, it's just all mobiles around here.
You've never noticed the phones at every checkout stand in the grocery store? Or at every customer service desk in every retail store in the nation? Or hotel front desks?
When that new coffee shop opens down the street and isn't on Yelp yet (or is, but the hours are wrong anyway), how do you find out its hours? Do you ask the barista for his Facebook ID? How do you find out information about a place that doesn't have a web site, or that has an obviously outdated web site? Have you never worked in a place with a receptionist?
The only place I've ever worked that didn't have telephones turned out to be a scam operation. I don't think I would trust a company that didn't have phones.
Re: Bypassing Browser Security Warnings with Pseudo Password Fields
#100Earlier quoted context omitted.
I don't want my ISP to inject JavaScript to random pages or analyze my traffic. That should be downright illegal. They should be like water supply company: provide me damn clean water and get out of my way. Somehow the sewage company doesn't analyze my urine (I hope ) to figure out if I prefer spicy or sour food and get an extra buck from third parties, and somehow they're still in the business .
> I don't want my ISP to inject JavaScript to random pages or analyze my traffic. That should be downright illegal. They should be like water supply company: provide me damn clean water and get out of my way. I don't want my search engine to do that either. They should provide me damn accurate results and get out of my way. Unfortunately, whereas I have a choice of several good ISPs here (UK), I have a choice of prec…
What aspect of DDG "sucks" for you?