HN user

danyork

2,534 karma

Me: http://www.danyork.com My writing: http://danyork.me/ Me on Twitter: http://twitter.com/danyork Me on Github: http://github.com/danyork

Where I write: http://www.danyork.com/blogs.html Developer-focused: http://code.danyork.com/

Where I work: http://www.internetsociety.org/

Posts535
Comments250
View on HN
pulse.internetsociety.org 10mo ago

Insights from the UN Open Source Conf: Reclaiming the Internet's Foundations

danyork
1pts0
www.vice.com 3y ago

UK Proposes Making the Sale and Possession of Encrypted Phones Illegal

danyork
7pts0
techcrunch.com 3y ago

Messenger ramps up testing of default end-to-end encryption

danyork
1pts0
blog.caida.org 3y ago

Studying Conformance of MANRS Members (routing security)

danyork
2pts0
www.manrs.org 3y ago

For 12 Hours, Was Part of Apple’s Network Hijacked by Russia’s Rostelecom?

danyork
56pts6
pulse.internetsociety.org 4y ago

An Eye on the Numbers: IPv6 Deployment

danyork
3pts0
pulse.internetsociety.org 4y ago

IPv6 Deployment Passes Another Milestone

danyork
15pts0
pulse.internetsociety.org 4y ago

Majority of Announced IPv6 Address Space Now Secured

danyork
4pts0
www.computerweekly.com 4y ago

Encryption Myths versus Realities of UK Online Safety Bill

danyork
1pts0
blog.apnic.net 4y ago

Authenticated Bootstrapping of DNSSEC Delegations

danyork
1pts0
www.axios.com 4y ago

U.S. vs. Russia for the Future of the Internet

danyork
1pts1
www.manrs.org 4y ago

BGP Security in 2021

danyork
2pts0
techmonitor.ai 4y ago

Why government action may be needed to push IPv6 adoption

danyork
3pts0
www.vice.com 4y ago

UK Revives Dangerous Attempt to Verify Age of People Who Watch Porn

danyork
2pts0
pulse.internetsociety.org 4y ago

Where Are the Internet Networks?

danyork
2pts0
www.rollingstone.com 4y ago

UK government plans publicity blitz against encrypted communications

danyork
310pts136
www.techdirt.com 4y ago

UK Government Apparently Hoping It Can Regulate E2E Encryption Out of Existence

danyork
24pts0
www.w3.org 4y ago

W3C Privacy Interest Group (PING) 2021 year in review and thank yous

danyork
34pts0
encryptindia.org 4y ago

Encrypt India – A Research Repository on Encryption

danyork
2pts0
www.manrs.org 4y ago

Facebook Has Good Manrs. Mistakes Still Happen

danyork
1pts0
www.innovationaus.com 5y ago

Encryption laws puts billions at risk: Report

danyork
1pts0
www.independent.co.uk 5y ago

The encryption debate is about all of our personal messages

danyork
3pts0
www.internetsociety.org 5y ago

Don’t Make Parents Raise Kids in a World Without Encryption

danyork
1pts0
www.bbc.com 5y ago

Encrypted messaging puts children at risk, commissioner warns

danyork
2pts1
www.internetsociety.org 5y ago

Internet Society: U.S. ban of TikTok and WeChat is direct attack on the Internet

danyork
2pts1
www.internetsociety.org 6y ago

In Times of Crisis, All Communities Need to Be Connected

danyork
1pts0
www.internetsociety.org 6y ago

A Backdoor Is a Backdoor Is a Backdoor

danyork
10pts0
www.internetsociety.org 6y ago

Is the Internet Resilient Enough to Withstand Coronavirus?

danyork
3pts0
www.worldipv6launch.org 6y ago

New Year, New IPv6 Deployments

danyork
3pts0
ipv4.global 6y ago

Federal CIOs Asking about IPv6-Only

danyork
1pts0
[dead] 2 months ago

If you live in Canada, this site provides a way to communicate with your MP about why Bill C-22 threatens the safety, livelihoods, and national security of all Canadians.

@ruthvik947 - Thanks... but now I have the option to either "Create account" or "Sign in". How do I know that I even want to create an account and check it out? It would be great if there was a way to see at least some of the information so that I could decide whether I want to do that step of creating an account.

Correct, but the ActivityPub plugin has been available for a long time for open source WordPress. This news today now makes it available to the millions of people who host their sites on WordPress.com - and without them having to install a plugin or anything else. It's just now part of the WP.com hosted platform. And that's rather awesome!

My understanding from reading a number of articles about this "helpful content" update from Google is that they want to get rid of pages like what you describe and instead prioritize pages that get right to the point. So perhaps you'll get what you are asking for.

I like how this is a very simple way to explain to NON-technical people how much encryption plays a role in their daily lives.

Agreed! I find many of the recommendations useful. (I also use Pocket personally for bookmarking sites.)

DNSCrypt and other solutions typically involve changes to the DNS resolver in the underlying operating system. That's a lot harder to get changed and deployment can take a long time.

DOH can be implemented directly inside of the web browser application, since those browsers are obviously already doing everything over HTTPS. So the browser developers just have to build in a DNS client. From their perspective, I would see that being much simpler. And deployment is as easy as the next browser application update.

Yes, it works quite well to get a sense of the room. The advantage of humming is that people can change the volume to match their level of agreement with the question being asked. If they strongly agree with the question, they can hum very loudly. If they only weakly support it, they can hum quietly. The chairs of thesession can then get an audible sense of the level of agreement (or not).

Often in the sessions I've been in, there may be two hums taken - one for those in support of a question, and one for those opposed. Often there can be a clear distinction - but sometimes the results can be inconclusive if both sides seem to have equal volume. (But that, too, is helpful to the chairs as they can get a sense that the people in the room are divided.)

What a fun - and educational - post about the full and complete journey from the moment someone starts typing “I love you” on a phone to when it gets read on the other end. That was great!

This post captures so many of the thoughts I've had about how it is NOT a simple answer of "going back to self-publishing on our own websites", because the nature of running websites is no where near as simple as it was. I have continued to write on my own blogs since 2005 ... but with all the ever-present security issues - and the need to do constant updates to my servers/vms, it's hard to keep up. The siren call of simple, centralized systems that take care of all of that for you is indeed a strong call!

I use three tools:

1) Things app on my iPhone/iPad/Mac ( https://culturedcode.com/things/ ) - it's a quick place to jot down quick thoughts or notes when I'm in the middle of doing other things. (I use it for my "to-do" lists - and it syncs beautifully across my other Apple devices.)

2) MindNode ( https://mindnode.com/ ) - if I have a group of thoughts, or if I have a few minutes, I'll often create a quick mind map with MindNode and collect my thoughts there. (It also syncs beautifully across all Apple devices.) I also have a couple of specific mind maps for tracking projects or article ideas, etc. So if my creative thought falls into one of those, I'll open up the mind map and add it there.

3) Evernote - For longer lists or ideas, I'll typically create a note inside of Evernote. I've been using it for years... although with many of the UI changes and general uncertainty about the company's future direction, I'm considering migrating my collection of notes/notebooks to something else (so I've been reading this HN discussion).

I'll note that I'll use these three tools together. Often I'll jot a note into Things... and then later expand upon that into a MindNode mind map or an Evernote entry. So one is more "short term" capture of thoughts, while the other two are for longer term - and longer form - capture.

The challenge of using 3 tools is, of course, that there's no easy way to search across all of them.

P.S. And many times when I'm going to events, speeches, conferences, etc., I'll bring a pen and a notebook as that can be the fastest way to capture ideas.

The challenge with any server-side solution is the huge amount of caching that takes place within the web infrastructure. Many sites sit behind CDNs, but even without CDNs, many ISPs and enterprises run their own caching proxy servers on the edge of their networks. Browsers also have their own caching of recent pages. The result of all the caching is that it is possible that very few of the visitors actually connect to the origin server.

For that reason, most analytics systems use come kind of client-side tracking code that runs within the client web browser. That way it works regardless of whatever caching happens.

Very good analysis. I found myself thinking about this phrase:

The mobile revolution is and has been by far the most powerful driver of centralization in the last 10-15 years.

Many of us who were active users of Skype in its earlier days (mid-2000s) might remember Skype's first attempt at a mobile client. They took all the distributed P2P goodness of the desktop client and tried to have that run on the mobile environment.

The result was sadly a smartphone app that was slow and rapidly drained your battery. For those of us with many Skype group chats open, the mobile client was basically unusable.

So Microsoft/Skype had to go back and rethink the mobile client. To your points in your reply... they made it a "thin client" with all the power in the centralized servers.

As they did that, it seemed from the outside that they determined over time that maintaining a desktop P2P source code and a mobile thin-client/server source code didn't make sense. And so ultimately the desktop P2P was abandoned and everything became client/server. (Which is the case now - Skype on your desktop is basically a wrapper for a web client.)

And so... the quest for a good mobile user experience wound up being one of the drivers for centralizing one of the original decentralized P2P apps. [1]

Good analysis!

[1] Yes, there were, I'm sure, many other contributing factors, including the issues around the supernodes that led to one of the major outages. And yes, I do realize that Skype, even its earliest form was NOT a completely-decentralized communications app. They did have a centralized mechanism for logins / authentication and also for PSTN gateways and other services.

Certifications 9 years ago

If she's just looking for something to show that she has some level of technical skill, I'd second the suggestion others have made for CompTIA certifications. They are a good base level cert - https://certification.comptia.org/

Depending upon what type of law she is planning to go into:

- A+ is targeted at basic devices and operating systems (think: very basic tech support)

- Network+ is basic networking

- Security+ is basic security

etc.

Probably the best way to start.

Correct. And if the local resolver is sufficiently close to your client that there is very low risk of an attacker getting into your local network, then you can have a higher degree of trust in those validated answers from your resolver.