Hacker Newsnew | past | comments | ask | show | jobs | submit | tomwas54's commentslogin

It's announced here as also being in beta for public repos: https://github.blog/changelog/2021-06-23-issues-forms-beta-f...


I cannot comprehend why GitHub chose to let people define the form elements in YAML (!) instead of simply allowing <input>, <select> and <textarea> in Markdown. One of the most beautiful aspects of Markdown is that it supports HTML. It's trivial to allow only a minimal set of attributes, like `required`.


It was indeed removed during the submit, corrected it now.


For ~40 minutes, it was also impossible to SSH into any Compute Engine instance that uses OS Login for authentication, but it seems to have been resolved in the last few minutes.


Ubuntu 18.04, the newest LTS, recently backported OpenSSL 1.1.1 to its stable package repository.

Because of this my personal webserver, running nginx on Ubuntu 18.04, started offering TLS 1.3 without any manual action on my part, because the server is configured to auto-apply updates from these repositories.



Let's Encrypt seems to be working on validating from multiple vantage points, by doing or having done this in their staging environment: https://community.letsencrypt.org/t/validating-challenges-fr...


No, it doesn't. As mentioned in the article, the attacker successfully requested a TLS certificate for the hostname, which was possible because he could pass a CA's domain validation.

I'm not entirely sure, but I think HPKP could have prevented this for returning customers, because Fox-IT would have been able to pin the key of their own certificate. Then the new certificate used by the attacker would have been rejected by the customer's browser.


Yes, it more highlights that the simple presence of a valid certificate does NOT guarantee that you are connecting to the service that you think you are.

EV certs would be harder to compromise, but likely not too difficult for a sophisticated attacker. And who really notices if a site that had an EV cert suddenly doesn't? I might for my bank, but likely would not for a software product website.


> he could pass a CA's domain validation

What! That's impossible! /s


FastMail added a Dark Mode this week :)

(Settings → General & Preferences → Theme → Dark)


It was actually added about six months ago, blog post and all, but most people only heard about it once it was mentioned in the newsletter, which was last week.

I’d qualify the inclusion of FastMail because the mobile app doesn’t yet support the dark theme. (It will, it just doesn’t yet. There’s a fair bit of refactoring of the style system to make it work better pending.) Then again, half of the websites listed on this site depend on applying user styles or installing a browser extension…


You should have one now.


Very kind of you, thank you.


Done!


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: