Posts by owen@mastodon.transneptune.net
(DIR) Post #B4BpTsJHLdbCqJV92e by owen@mastodon.transneptune.net
0 likes, 0 repeats
@mhoye How are the various BSDs doing these days?
(DIR) Post #B5I1WezniWVAcKlCJk by owen@mastodon.transneptune.net
0 likes, 0 repeats
RE: https://infosec.exchange/@douglevin/116398473625428623"Do not connect your organization's information systems to the internet" is an increasingly plausible response to this, as catastrophic (and as _unreasonable_) as it is.Trouble is, that runs contrary to the business current for the collection of educational service providers who service this space, who have been shepherding their customers towards "host everything in the cloud" (for many reasons of varying sensibility) for a decade.RT: https://infosec.exchange/users/douglevin/statuses/116398473625428623
(DIR) Post #B5I1WfDGuRHFI73xJY by owen@mastodon.transneptune.net
0 likes, 1 repeats
To be clear I don't think de-internetization is likely, or anything - just that there almost certainly exists a tipping point where the running costs of constantly managing disclosure hazards and unauthorized service hazards and the rest of the internet's plague ward outweighs the benefit of a global network as a solution to info processing problems.
(DIR) Post #B5JytCJSc9qGlyvloG by owen@mastodon.transneptune.net
0 likes, 0 repeats
Which BSDs are principally maintained by organizations and contributors based outside of the United States?
(DIR) Post #B644C1yWi8KlFu5yr2 by owen@mastodon.transneptune.net
0 likes, 0 repeats
@gnomon I'm straight-up assuming - as I have no information one way or the other - that that blob dump was the other half of the prompting API spec Google is trying to ram through: https://github.com/mozilla/standards-positions/issues/1213#issuecomment-4347988313
(DIR) Post #B644C2ChrPfzxsjIxM by owen@mastodon.transneptune.net
1 likes, 0 repeats
RE: https://mastodon.transneptune.net/@owen/116529543186641483I have since found confirmation that the 4GB blob Google helpfully shat into Chrome users' computers and the standards proposal linked below are two ends of the same project. Someone at Google is in a real hurry to turn their quarterly performance review into a durable internet standard.RT: https://mastodon.transneptune.net/users/owen/statuses/116529543186641483
(DIR) Post #B66QlCP6W2OJ2hcaMS by owen@mastodon.transneptune.net
0 likes, 1 repeats
Do you want to put a web page on a .local address to do something cool for your household or club? Here's the list of browser features that browser vendors have decided you're just not fuckin' allowed to use. https://developer.mozilla.org/en-US/docs/Web/Security/Defenses/Secure_Contexts/features_restricted_to_secure_contextsSome random site halfway around the world, served over https with a robo-verified certificate, is allowed, though, so take some comfort in that.
(DIR) Post #B66QlDCNYpo3VWfwAK by owen@mastodon.transneptune.net
0 likes, 0 repeats
There's a discussion thread about allowing RFC 1918 addresses and their ip6 equivalents to participate in secure contexts at https://github.com/w3c/webappsec-secure-contexts/issues/60 . It is _eight years_ old without resolution.I can't find any discussion at all on allowing the user to designate certain origins as secure contexts. Maybe that's a thing for some browsers.
(DIR) Post #B66QlDcbzIn2oswt3Q by owen@mastodon.transneptune.net
0 likes, 0 repeats
The recommendation in that thread is to run a private CA for your LAN. Anyone who has experience doing that outside of a managed (i.e., corporate) network will tell you how hilariously useless that advice is.