Hacker Newsnew | past | comments | ask | show | jobs | submit | Group_B's commentslogin

We are almost full circle with going back to taxis. They want to cap the number of drivers. Maybe there’s some way to cap it with this thing called a license. Well played everyone!


I think Microsoft will add in a daily or monthly commit limit. Gonna have to pay for commits that exceed it. Will stop the commit spam


thats why we have https and certs. VPN is redundant


Redundancy is not detrimental to security and privacy. On the contrary, having more layers would protect you in case one of them fails (zero-day, bugs, etc.)


If there's a zero-day in TLS there would be a huge amount of problems that a VPN wouldn't protect you against. Even if you're using a VPN (or just a trusted ISP from your home), as soon as your data leaves their hands it would be vulnerable.

Like, suppose I want to send a physical letter to my bank. I can either ensure it can't be opened (using TLS), or I can get a trusted mailman to bring it to the mail central (using a VPN or trused ISP), but only one of those measures are going to protect me against a malicious mailman carrying it from the mail central to the bank.


I’d expect the mail carrier who goes from the mail center to the bank to be slightly more trustworthy than the one who visits me off in the middle of nowhere. Or at least, if that carrier is untrustworthy, it is a big problem for a lot of rich people who have the time and money to think about this sort of stuff.


> it is a big problem for a lot of rich people who have the time and money to think about this sort of stuff

Because banks famously love spending time and money on IT security... Anyway, if TLS was broken, that would be a big problem for everybody.

Using a VPN to protect against a zero-day in TLS, is sort of like hoarding gold to prepare for a collapse of society, in that it's a very unlikely scenario, and if it actually were to happen you'd have a bunch of other problems that aren't solved by gold / a VPN.


wow, never thought of root certs being a point of failure


That is a common issue on old hardware. You have to be wary because some like android devices get their truststore updated regularly but it doesn't stay in rom so if you do a complete device reset you get back to the original ones that are now useless to connect to app stores and uodate servers.


Yeah nearly had a heart attack this morning. Thought keys were leaked for a sec.


Technically no. Work and School dictate when we get up and go to bed. It's all relative. We could create a timezone where 12:00PM is in the morning. We are just used to this idea that morning, afternoon, evening, and night need to correspond to specific time values. For example, China uses just one timezone. So local regions just adapt to what logically makes sense. In a perfect world, local regions would adapt to the amount of daylight we have for each season, like it was before timekeeping and timezones. So school and work would shift when they start based off the rising of the sun. This isn't practical though for multiple reasons. It would cause chaos and confusion for work shifts, scheduling etc.


netlify isnt bad


Would love to see a write yo on nginx!


And once again, another prime example that we do not live in a serious country


I'm moving everything to self hosted GitLab CE now. Will just use GitHub as a backup. This is so ridiculous at this point.


GitLab vs Forgejo? Personally run GitLab but looking at moving, due to it's massive size.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: