←back to thread

103 points voxadam | 5 comments | | HN request time: 2.402s | source
Show context
1970-01-01[dead post] ◴[] No.46212198[source]
[flagged]
schmuckonwheels ◴[] No.46212214[source]
Objectively better than serving 12MB of JavaScript slop, trackers, and "analytics" over HTTPS so you can share a recipe for flan.

Greg K-H has more credibility than 99% of posters here.

He's literally the #2 guy in Linuxworld (behind Linus). What have you done?

replies(2): >>46212478 #>>46212559 #
1970-01-01 ◴[] No.46212478[source]
You enumerated the security risks of clear text transmission over the Internet and everything came up green because the blogger works on Linux?
replies(2): >>46212553 #>>46214001 #
1. schmuckonwheels ◴[] No.46212553[source]
If you are too afraid to click a cleartext HTTP link then don't; it's not for you. Just spare the rest of us the melodrama.

While you are at it, better not ever update Debian or any number of other OSes because their updates are served over plain HTTP.

replies(1): >>46212827 #
2. 1970-01-01 ◴[] No.46212827[source]
You almost had a great point here. If he began every blog rant with BEGIN PGP SIGNED MESSAGE and included a digital key somewhere secure, somewhere that I could go and verify, just Debian does with updates, I maybe could tolerate the cleartext. But he clearly didn't (pun alert!)
replies(1): >>46218565 #
3. zahlman ◴[] No.46218565[source]
Pardon; your threat model includes someone MITMing Greg's site to misrepresent what the blog article says?

... But you'll happily go to a forum site such as HN to discuss the post?

replies(1): >>46218912 #
4. 1970-01-01 ◴[] No.46218912{3}[source]
https://apps.lansa.com/LearnLANSAWebMobile/index.html#!Docum...

XSS is real threat that everyone like you missed.

replies(1): >>46225423 #
5. zahlman ◴[] No.46225423{4}[source]
> The content is not shown because JavaScript is disabled.

Two can play the luddite game.