Skip to content
  • Home Home Home, current page.
  • Moments Moments Moments, current page.

Saved searches

  • Remove
  • In this conversation
    Verified accountProtected Tweets @
Suggested users
  • Verified accountProtected Tweets @
  • Verified accountProtected Tweets @
  • Language: English
    • Bahasa Indonesia
    • Bahasa Melayu
    • Català
    • Čeština
    • Dansk
    • Deutsch
    • English UK
    • Español
    • Filipino
    • Français
    • Hrvatski
    • Italiano
    • Magyar
    • Nederlands
    • Norsk
    • Polski
    • Português
    • Română
    • Slovenčina
    • Suomi
    • Svenska
    • Tiếng Việt
    • Türkçe
    • Ελληνικά
    • Български език
    • Русский
    • Српски
    • Українська мова
    • עִבְרִית
    • العربية
    • فارسی
    • मराठी
    • हिन्दी
    • বাংলা
    • ગુજરાતી
    • தமிழ்
    • ಕನ್ನಡ
    • ภาษาไทย
    • 한국어
    • 日本語
    • 简体中文
    • 繁體中文
  • Have an account? Log in
    Have an account?
    · Forgot password?

    New to Twitter?
    Sign up
RichFelker's profile
Rich Felker
Rich Felker
Rich Felker
@RichFelker

Tweets

Rich Felker

@RichFelker

Yeah, I do @musllibc, FOSS & infosec stuff. But now is not the time for a mostly-/only-tech Twitter feed.

musl-libc.org
Joined March 2014

Tweets

  • © 2018 Twitter
  • About
  • Help Center
  • Terms
  • Privacy policy
  • Cookies
  • Ads info
Dismiss
Previous
Next

Go to a person's profile

Saved searches

  • Remove
  • In this conversation
    Verified accountProtected Tweets @
Suggested users
  • Verified accountProtected Tweets @
  • Verified accountProtected Tweets @

Promote this Tweet

Block

  • Tweet with a location

    You can add location information to your Tweets, such as your city or precise location, from the web and via third-party applications. You always have the option to delete your Tweet location history. Learn more

    Your lists

    Create a new list


    Under 100 characters, optional

    Privacy

    Copy link to Tweet

    Embed this Tweet

    Embed this Video

    Add this Tweet to your website by copying the code below. Learn more

    Add this video to your website by copying the code below. Learn more

    Hmm, there was a problem reaching the server.

    By embedding Twitter content in your website or app, you are agreeing to the Twitter Developer Agreement and Developer Policy.

    Preview

    Why you're seeing this ad

    Log in to Twitter

    · Forgot password?
    Don't have an account? Sign up »

    Sign up for Twitter

    Not on Twitter? Sign up, tune into the things you care about, and get updates as they happen.

    Sign up
    Have an account? Log in »

    Two-way (sending and receiving) short codes:

    Country Code For customers of
    United States 40404 (any)
    Canada 21212 (any)
    United Kingdom 86444 Vodafone, Orange, 3, O2
    Brazil 40404 Nextel, TIM
    Haiti 40404 Digicel, Voila
    Ireland 51210 Vodafone, O2
    India 53000 Bharti Airtel, Videocon, Reliance
    Indonesia 89887 AXIS, 3, Telkomsel, Indosat, XL Axiata
    Italy 4880804 Wind
    3424486444 Vodafone
    » See SMS short codes for other countries

    Confirmation

     

    Welcome home!

    This timeline is where you’ll spend most of your time, getting instant updates about what matters to you.

    Tweets not working for you?

    Hover over the profile pic and click the Following button to unfollow any account.

    Say a lot with a little

    When you see a Tweet you love, tap the heart — it lets the person who wrote it know you shared the love.

    Spread the word

    The fastest way to share someone else’s Tweet with your followers is with a Retweet. Tap the icon to send it instantly.

    Join the conversation

    Add your thoughts about any Tweet with a Reply. Find a topic you’re passionate about, and jump right in.

    Learn the latest

    Get instant insight into what people are talking about now.

    Get more of what you love

    Follow more accounts to get instant updates about topics you care about.

    Find what's happening

    See the latest conversations about any topic instantly.

    Never miss a Moment

    Catch up instantly on the best stories happening as they unfold.

    1. Hector Martin‏ @marcan42 Jun 4

      Hector Martin Retweeted Robᵉʳᵗ Graham X🅂 Max

      First good argument I see about why the GitHub acquisition is bad.https://twitter.com/ErrataRob/status/1003396869052141568 …

      Hector Martin added,

      Robᵉʳᵗ Graham X🅂 Max @ErrataRob
      So here's a more serious discussion of what 'GitHub' is, and why Microsoft's acquisition of it is so important: China can't block GitHub's pages about the Tiananmen Square massacre.
      Show this thread
      6 replies 30 retweets 78 likes
    2. Andrew Miller (安藤龍)‏ @ikari7789 Jun 4
      Replying to @marcan42

      China’s great firewall isn’t MITM the SSL certs? That seems surprising to me.

      1 reply 0 retweets 0 likes
    3. Rich Felker‏ @RichFelker Jun 4
      Replying to @ikari7789 @marcan42

      That's not how TLS ("SSL") works.

      1 reply 0 retweets 0 likes
    4. Andrew Miller (安藤龍)‏ @ikari7789 Jun 4
      Replying to @RichFelker @marcan42

      It’s certainly possible to intercept SSL traffic if you’re controlling the middle layer. Many companies do it, some countries as well. I don’t see how China cannot.

      2 replies 0 retweets 1 like
    5. Hector Martin‏ @marcan42 Jun 4
      Replying to @ikari7789 @RichFelker

      No, it isn't. That's the whole *point* of TLS. To intercept it you need to control *an endpoint*. Companies control the local endpoint. China tries, but cannot control all endpoints (people's devices).

      1 reply 0 retweets 2 likes
    6. modrobert‏ @modrobert Jun 4
      Replying to @marcan42 @ikari7789 @RichFelker

      MITM was made possible after adding SNI extension to TLS (OpenSSL) for cert handling to accommodate for companies like CloudFlare. This is just one of many HTTPS flaws.

      1 reply 0 retweets 0 likes
    7. Rich Felker‏ @RichFelker Jun 4
      Replying to @modrobert @marcan42 @ikari7789

      You have no idea what you're talking about. MITM is never possible without a compromised endpoint.

      1 reply 0 retweets 1 like
      Rich Felker‏ @RichFelker Jun 4
      Replying to @RichFelker @modrobert and

      Perhaps you're confusing that, to use a service like Cloudflare, you (the server endpoint) are voluntarily appointing Cloudflare as a MITM. Then in some sense you compromised your own endpoint. This only affects your site, not anyone else's.

      6:36 PM - 4 Jun 2018
      1 reply 0 retweets 0 likes
        1. New conversation
        2. modrobert‏ @modrobert Jun 4
          Replying to @RichFelker @marcan42 @ikari7789

          My point is that the if the website admin is using CloudFlare (or being forced to use similar service in an oppressive country) and accepted them as a MITM, the user browsing the web will have no warning there is a MITM in the browser.

          1 reply 0 retweets 1 like
        3. Rich Felker‏ @RichFelker Jun 4
          Replying to @modrobert @marcan42 @ikari7789

          They had to authorize the certificate to be issued to Cloudflare or a similar service, or had to have provided a private key for a certificate already issued. If not, the CA that issued the cert is in violation of CA policy and can/should be removed from trusted CA set.

          1 reply 0 retweets 0 likes
        4. Rich Felker‏ @RichFelker Jun 4
          Replying to @RichFelker @modrobert and

          Especially now with CT logs, wrongfully issued certs WILL be caught, and someone will be held accountable.

          0 replies 0 retweets 0 likes
        5. End of conversation

      Loading seems to be taking a while.

      Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.

        Promoted Tweet

        false

        • © 2018 Twitter
        • About
        • Help Center
        • Terms
        • Privacy policy
        • Cookies
        • Ads info