LastPass is known to have... "problems".
HN user
rahrahrah
For me:
HTTPS Everywhere: https://chrome.google.com/webstore/detail/https-everywhere/g...
uMatrix: https://chrome.google.com/webstore/detail/umatrix/ogfcmafjal...
If you have hundreds of tabs open, unused tabs etc, I would suspect that you'd have more to gain by fixing whatever is wrong with your work methodology than by downloading extensions. Food for thought.
Thanks for the reference.
France as usual leading in workers' rights.
The results of getting into "Podesta's gmail for some days" is you take the elections. But no, you think it's smarter getting into some nobody sysadmin's social media accounts. Got it.
Sorry, my intention wasn't to move the goalposts, I actually misspoke the second time. Obviously I don't care where the evidence comes from. I did mean "no public evidence" and then the parent made it political, somehow.
I did read the RPT-APT28 report by FireEye on APT28 (all fifty-something pages, surprise!). It did convince me that APT28 has political motivations. What's the connection between that and DNC/Podesta? I don't know, because there's no public evidence on that (that I know of).
No idea why you're bringing politics into this. All I said was no evidence has been made public by the government.
That's right, I was one of those confused people. I assumed this would be the WH presenting what evidence they have.
Sooo... still no public evidence that Russia leaked the DNC and Podesta's e-mails?
Ok, so I just want to be absolutely clear:
They are signed by the same process as all other APK's on the store; using the play store developer keys that OWS received. Google can backdoor it because they control the distribution source and verification scheme.
If I verify the signature, I can determine whether or not the APK has been tampered with by Google, yes or no?
It would be too easy to say "don't try to teach moxie how to do crypto" but this won't be interesting to either of us, I'm really curious what is your threat model that you would like additional signature specifically by OWS and what do you want them to sign.
Well, obviously I'm not trying to teach anyone crypto as I don't know enough myself to begin with. My threat model is don't trust anyone that has a bad track record. In my book Google has a bad track record but not moxie.
Because it depends on how you want to use email. eg I have emails which are sent to my address+subs@gmail.com being put to a label "subscriptions", but obviously not everyone wants to use it like this, in which case why make it default?
Most people have similar needs, and most people's job is to actually do their job, not mess with their email config
This is such an obvious excuse. You get the config right once and you've solved a problem forever. It is, how do you say, very "scalable" in time.
If the "something malicious" is run by a user that only has permissions to read/write to his home, it's perfectly contained.
You said that the play sore APK is signed. Signed by whom? By OWS, right? So Google can't backdoor it. Again, what am I missing? Help me out. I might be making a reasoning mistake due to not thoroughly understading how these things work (I mean APK distribution)
Got it, just saw this comment
Nah - brokenness is intentional
Well played sir.
EDIT: are you actually in the UK?
Guys.... This is obviously NOT an attempt to SQL inject. This is a full fledged company incorporation. A marketing move if you will.
Although a risky one. If that had worked that guy would end up in court.
I probably don't know enough to be talking about these things, but it seems to me that the Qubes OS approach is more complex and less battle tested. User permissions in Linux have been around forever.
Ok, but it's STILL false that if google wants to backdoor you a signature check is irrelevant.
Also, no need to get triggered mate, we're just having a conversation.
No one cares.
If Apple/Google want to backdoor Signal they can do so, they can also backdoor your device in this case the signature check is irrelevant if you consider them an adversary.
What? No...
Assuming you trust OWS you can check the APK signature.
A) Nuke everything
B) Install ASOP or other OS that you prefer.
C) Download and manually checked Signal's signature.
D) Transfer it to your device.
No need to trust Google. Am I missing something?
Listen, you always need to trust SOMETHING. If you don't trust Google or OWS you can read their code yourself, but then you're trusting the compiler, the OS, the hardware, etc. But I submit that of the above some are inherently more trustworthy than others, given their track record.
Hi Alex, thanks for sharing.
I was wondering, what you pay your affiliates is missing from the break down of costs. Why is that?
Something related happened to me. Some of the photos on my google photos are just completely black. It's not exactly the same because this guy's photos are "corrupted". Mine are just literally black. Not all of them, just around 20, all in the same day, all in sequence.
Curating IS their business. When you type in "public key pinning", for example, google understands that you want to learn about public key pinning and so it curates OUT results about kim kardashian for example and instead shows you factual truths about public key pinning. Why should the holocaust be different?
AGAIN, google's goal is to organise all knowledge and that's exactly what it's doing. That holocaust denial is a thing is also knowledge, and so you can find it by typing "holocaust denial".
Interesting. But what's the set of public keys that it uses to decide whether or not an APK can be executed?
I don't understand what the outrage around this is. Google's goal has always been to organise all knowledge around a query box, and that's exactly what it's doing. If it understands that the holocaust did happen, why should it display that it didn't?
Ok so you're giving me an answer about something that I don't care about, the "overall" state of security. I just care about mine, really. Thanks.
When you say "doesn't meaningfully improve security", does "meaningfully" mean "for the majority of users"? Because I can assure you that for a single user who does things properly it does improve security.
What about the case where I want to know if a piece of software being pushed into my phone has been approved by a specific person?
he is generally in favour of ephemerality over verifiability
That's not an absolute law in a vacuum. What does "ephemerality" even mean in the context of the question "how can I verify that the software that's being pushed to my phone comes from where it says it comes?"
Are you suggesting that signing doesn't meaningfully improve security?