Hacker Newsnew | past | comments | ask | show | jobs | submit | ouaibe's commentslogin

I'm pretty sure some (of these https://www.shodan.io/search?query=fortigate) do, especially considering SSH is usually trusted for its security. But I might be wrong.


I did split ioerror's duraconf nginx configs in 3 distinct configs with different ciphersuites lists, that specifically list desired ciphers in order, targetting :

- Very high security with low compatibility.

- PFS-only moderate security with high compatibility.

- PFS-centric moderate security with very high compatibility.

All of them give an A on Qualys SSL Labs test.

https://github.com/ouaibe/duraconf/tree/master/configs/nginx


FWIW, I have submitted a somewhat similar configuration as a pull request for ioerror's duraconf project at https://github.com/ioerror/duraconf/pull/52.

This project also hosts secure ciphersuite configurations for postfix, nginx, apache, GPG, etc.


Because phones inherit from an old business model where they were subsidized by mobile network operators and thus manufactured and sold according to their needs, not to the users need.

This meant you'd have many restrictions and the user was constrained to a tightly-controlled environment that forbode anything the operator deemed unnecessary (and could even contain malware/spyware-like pre-loaded software).

That model gradually evolved into J2ME platforms (and the like), where developers (and sometime users) could make small customizations, until someone decided there was a huge market selling phones designed not for the operators but for their customers (i.e. Apple/Google).

They still built the product partly following the same mindset/model and provided VM-centric phones that still are not designed to give you ring-0 access from the get go and maximize the operator's & manufacturer control on your device, hoping to gain revenues from gated developer communities, reselling applications that are mostly yet another graphical layer on top of code that already exists natively on regular computers since a long time ago.

That model is gradually evolving (hopefully in the right direction) and operators are slowling realizing that they're not device vendors but merely ISPs, which means that the phones are to be sold to customers, centered around their needs and giving them the maximum control (letting them chose the OS and giving them ring0 access).

You still need to get rid of the protected baseband cpu, the SIM, the TEE, the protected bootloaders etc. and eventually might have the device that you speak about.


phones inherit from an old business model where they were subsidized by mobile network operators

Only in the US.


Contrary to popular belief, copyright law doesn't exist to ascertain dominion from an author onto it's creation. It exists to regulate exchanges and distribution of such creation, giving a controlled and finite monopoly to the original author with a guarantee that said creation ends up in the public domain. GPL exists to bypass such monopoly and implement a form of public domain (copyleft) that is compatible with copyright law.


And you get a real FIPS-compliant hardened device manufactured by someone that actually knows (and tries) how to handle security/crypto vs Square that doesn't really offer anything as such and that handles your track data in the non-protected memory of the phone...


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: