Conversation

Replying to and
You're misunderstanding what I'm saying. I'm not talking about the server you're connecting to but rather a server (or multiple) for sanity checking the local system time. Essentially, a time server, but with the time fetched via TLS.
1
1
The most common source of HTTPS errors in Chrome was determined to be an out of sync local clock, so when it encounters a certificate with an invalid date (expired or issued in the future), it has support for sanity checking the local system time via TLS to provide a notice.
1
1
Brave might have changed the domain from a Google server to one that didn't offer a strong guarantee of providing a correct TLS handshake time value. The server they used might have ended up having the wrong time, or it might randomize the field, which I think became permitted.
1
1
It's important because instead of training the user to accept invalid certificates, they are informed that their system clock is wrong, which they can check themselves, as you did. So, it seems Brave broke this feature, but the feature itself is a useful and important one.
2
Replying to and
It's also not possible to override those errors via the standard UI when a site using HSTS. There's a secret way to bypass the screen, which might work for you. You need to type a secret string for bypassing it. I don't know the string for current releases off the top of my head.
2
Replying to and
I wonder if better UX would be allowing easy bypass of the error, but: 1. showing site as insecure 2. disabling all cookies/localstorage for the site 3. disabling form entry/submission for the site 4. severe warning or blocking [executable] file download from site
2
Kinda similar to how AOSP has generic support for undo / redo in standard widgets like text fields, but most keyboards don't provide an undo / redo button and the ctrl-z / ctrl-shift-z keybinds aren't exposed via most virtual keyboards in their layout since they don't offer ctrl.
1
1
Replying to and
All the Android keyboards are so bad. I use an abandoned one called multiling. That and hacker's are least-bad. A good one would provide blank keycaps matching compact pc physical layout and let you apply any xkb layout file on top of it.
1
1
Show replies