I'm excited to share a project that I've been working on: a brand-new version of @Mozilla's SSL Configuration Generator:
ssl-config.mozilla.org/
Configuring TLS is perhaps the most complicated and error-prone of all IT tasks, and this tries to make it as easy as possible.
therapist: itβs normal for painful memories to soften over time
me: but what if they donβt? what if they only hurt more as i age?
therapist: do you have any memories in particular youβre thinking of?
me: yes, itβsβ¦ *sobs* the end of google reader
Handling Cookies is a Minefield:
Inconsistencies in the HTTP cookie specification have caused a situation where countless websites (including Facebook, Netflix, Okta, WhatsApp, Apple, etc.) are one small mistake away from locking their users out.
grayduck.mn/2024/11/21/handlβ¦
Instead of spinning off Chrome, the Department of Justice should have split Google into:
β’ Google Chat
β’ Google Talk
β’ Google Wave
β’Β Google Huddle
β’ Google Spaces
β’ Google Meet (original)
β’ Google Meet
β’ Google Buzz
β’Β Google Allo
β’Β Google Hangouts
one thing i love about being in a long tech career is seeing how far things have come over the years.
when i started it was all βugh clippy is so obnoxiousβ and decades of progress have gotten us all the way to βugh this ai assistant is so obnoxious.β
got laid off in the big @dropbox layoffs today.
if anybody is looking for a staff-level engineer who loves mentoring and who is an expert in web security, email security, TLS/PKI, keys and secrets management, and general defense security stuff, please feel free to hit me up.
thanks to everyone who reached out today. sorry if you contacted me and i havenβt responded yet.
itβs been a bit overwhelming (in a good way) and i am so thankful for all of you for helping to turn a miserable day into a much better one.
as a minnesotan, is there anything more delightful than that time of the year when we get to transition from lightweight flannel to heavyweight flannel?
macOS designers speedrunning ways to cause security warning fatigue while failing to provide any actual security benefits.
begging them to talk to anyone who has done security UX research.
i see we are doomed to repeat the same bad decision made in 2013, one that users overwhelmingly hated, except this time the loser at the helm doesnβt care about user safety or experience
techcrunch.com/2013/12/12/twβ¦
dad: what is it you do again?
me: i built a ton of features into firefox
dad: okay i guess
me: and now i secure systems with an almost incalculable amount of data
dad: ???
me: also today i got quoted by consumer reports
dad: *EYES BUG OUT OF HEAD*
consumerreports.org/electronβ¦
people who are gay: i'm gay
people who are straight: i'm straight
people who are bisexual: i'm bisexual
people who are trans: i'm trans
people who are from chanhassen: i'm from minneapolis
when the @cityofsaintpaul was drafting their laws for new drive-throughs, I suggested that they tweak the language so that those outside of vehicles were entitled to the same level of service as those inside.
and it looks like it might happen π
ALT Products and services provided via a drive-through window must during the same hours also be provided to customers not in motor vehicles via the building interior, a walk-up kiosk, or a walk-up service window. Serving such customers via the drive-through window does not satisfy this standard.