HN user

cwb71

336 karma

http://cwb.us/

[ my public key: https://keybase.io/cwb; my proof: https://keybase.io/cwb/sigs/rSKneyz8d9PYyKntQfbcdp2jQ5_ER4_CDNBISGGhSk8 ]

Posts13
Comments64
View on HN

From https://support.cloud.google.com/portal/system-status:

Status: Fully Resolved

Product group: Google Workspace

Products affected: Admin Console, Chrome Browser, Endpoint Management

Start time: Tuesday, June 16, 2026, 10:28:15 PM GMT-07:00

End time: Tuesday, June 16, 2026, 10:28:24 PM GMT-07:00

Description: A subset of users within the EU and Americas regions may have encountered a TLS certificate pop-up while using Workspace Apps.

Steps to reproduce: Impacted users may have encountered a popup where "lh3.googleusercontent.com" is asking for a TLS certificate when using any Workspace Apps.

This issue does not impact any critical functions on the corresponding Apps, as an option to bypass the prompt is available to users.

Workaround: The issue is mitigated now.

Updates: Tuesday, June 16, 2026, 5:31:51 PM GMT-07:00:

We are investigating a potential issue with Chrome Browser.

We will provide more information by Tuesday, 2026-06-16 18:00 PDT.

Tuesday, June 16, 2026, 5:40:40 PM GMT-07:00:

We are investigating the authentication prompt issue on Chrome browser beginning on Tuesday, 2026-06-16 05:30 PDT.

Our engineering team continues to investigate the issue.

We will provide an update by Tuesday, 2026-06-16 19:00 PDT with current details.

We apologize to all who are affected by the disruption.

Tuesday, June 16, 2026, 7:05:40 PM GMT-07:00:

We are investigating the authentication prompt issue while using Workspace Apps beginning on Tuesday, 2026-06-16 05:30 PDT.

Our engineering team has identified the root cause and mitigation is currently underway. We do not have ETA for mitigation at the moment.

We will provide an update by Tuesday, 2026-06-16 20:30 PDT with current details.

Tuesday, June 16, 2026, 8:16:33 PM GMT-07:00:

We are investigating the authentication prompt issue while using Workspace Apps beginning on Tuesday, 2026-06-16 05:30 PDT.

Our engineering team has identified the root cause and mitigation is currently underway. We do not have ETA for mitigation at the moment.

We will provide an update by Wednesday, 2026-06-17 00:00 PDT with current details.

Tuesday, June 16, 2026, 10:28:15 PM GMT-07:00:

The issue with Workspace Apps has been resolved for all affected users within the EU and Americas regions as of Tuesday, 2026-06-16 19:41 PDT

From a preliminary analysis, the issue was due to a configuration error that inadvertently requested client certificates. Our engineers have mitigated the issue by fully rolling back the affected configurations to a previous working state.

We thank you for your patience while we worked on resolving the issue.

Demystifying Secret 12 years ago

"First, your data is stored on Google servers — essentially the same servers as Gmail. This means your secrets are as safe as your email."

Well, if David says so…

Except that qwerty_asdf wasn't referring to a /24 subnet, (s)he was talking about one of the three address spaces defined in RFC 1918 and described thusly:

"Note that (in pre-CIDR notation) the first block is nothing but a single class A network number, while the second block is a set of 16 contiguous class B network numbers, and third block is a set of 256 contiguous class C network numbers."

So it is common for crusty old network engineers and sysadmins to refer to 192.168/16 as "the class C" private block, even when they understand that you can subnet it however you'd like.

This. I imagine that an agency with the resources of the NSA could probably work out a couple of ways to obtain almost any private key they want.

Interesting that this would bubble to the top today in light of the Verizon FISA story.

The White House and others defending the practice keep repeating “it’s just metadata.”

Knowing exactly who you talk to, when, where, and for how long can expose a lot about you and be pretty incriminating!

I continue to be confused by the use of the term “Cougar Night” to describe Thursday nights at the Rosewood.

Isn’t a cougar an established older woman looking for casual sex with a “boy toy?”

Seems like a better name for this would be “Gold Digger Night” or just “Rich Old People Trying to Hook Up.”

It is chilling—but is it true?

My immediate reaction when reading that paragraph was that someone as security-minded as Aaron would probably not leave his password saved in a Skype client.

Just noticed this response from Braff’s AMA:

“You can’t really raise enough money on Kickstarter yet. There are some new sites starting that will eventually allow anyone and everyone to own a piece of a movie; invest in it like a stock. But you can imagine the amount of legal issues this raises. So look for it sometime around 3012.”

http://www.reddit.com/r/IAmA/comments/19uwm9/i_am_zach_braff...

What a difference a month (and a $5.7 million Veronica Mars Kickstarter) makes!

Your goals and Zach’s just don’t align on this one—so don’t back it. His feelings will probably not be hurt and he will still be glad to sell you a DVD when the time comes.

This is a Kickstarter project, not an Amazon pre-order.

And also those same fans are now less motivated to go see the film in theaters because their DVD is already pre-ordered, potentially hurting box office revenue.

It is actually brilliant, now he can go to the distributors and say "these thousands of people were so excited about this project that they paid to make it... so of course they will pay us to see it!"

The Kickstarter supporters are likely to be his biggest, most loyal fans.

I can understand a reluctance to offer a reward that will disincentivize those same people from paying to see the movie on opening weekend.

I am not sure that "gospel truth" is a fair characterization.

Anonymous IRC person has provided verifiable details that strongly suggest he or she had access to Linode administrative systems. Fyodor's post to nmap-dev supports the notion that customer nodes were accessed as well.

Linode has provided no details or evidence of anything.

I don't think one has to take that IRC log as gospel truth to be reasonably concerned about the security of their data stored by Linode.

“The photos during take-off and landing are all computer models and totally rendered because I would never use an electronic device during times when the FAA prohibits them.”

Lulz.

Google does intentionally make it a little more difficult to do what you are doing by refusing to ever show you the password again once it has been generated. You have to store that "unmemorizable" sixteen letter password somewhere.

The workflow they seem to encourage is that an "application" asks for your password, you open a browser and generate a new ASP, then save it in that app and forget it forever.

By "application" they mean "something that asks for your password." Thunderbird or iChat, not IMAP or XMPP.

Google already requires that you name each ASP and provides a table listing the name, the date it was created, the date it was last used to log in, and a link to revoke it.

They'd just need to add an option to modify those. The OAuth entries on the same page list each's entitlements, though you don't have the option to modify them.

Introducing Boxen 13 years ago

Understood, but the original blog post begins “Boxen started nearly a year ago as a project called “The Setup” — a pipe dream to let anyone at GitHub run GitHub.com on their development machine with a single command.”

It was this line specifically which implied that Boxen is used to emulate the production environment in OS X and spurred my comment.

Introducing Boxen 13 years ago

This surprised me too, I would not have expected that Githubbers develop on OS X and deploy to Linux.

I would be interested to hear more about why they made that choice.

A note from Keith 13 years ago

Everyone seems to agree that not disclosing this to HR was a huge mistake, but I am not sure I understand how that would have helped.

You still have a sexual relationship between two people in the same organization with a big power differential between them.

Shouldn't the proper HR response just be "you need to absolutely not do that?" What can HR do beyond "keeping an eye on things?"

> So, after each blind date, you ask the participants, "would you go on a date with this person again?"

Does anyone know if Crazy Blind Date actually does this?

One of the great mysteries of OkCupid to me is that they do not attempt to collect this information. There is no "I met this person" button which then asks how it went and whether the match represented themselves accurately.

It seems like this would be an extremely valuable data point. There must be some reason that the feature doesn't exist, but I don't see what it is...

I know this is true, and it has always hurt my feelings a little bit.

I tend to find the women OkC matches me with plain, average, or unattractive. So if their algorithms are correct, what does this say about me?