• Home
  • About

Saved searches

  • Remove
  • Verified account @
Suggested users
  • Verified account @
  • Verified account @
  • Language: English
    • Bahasa Indonesia
    • Bahasa Melayu
    • Català
    • Čeština
    • Dansk
    • Deutsch
    • English UK
    • Español
    • Filipino
    • Français
    • Hrvatski
    • Italiano
    • Magyar
    • Nederlands
    • Norsk
    • Polski
    • Português
    • Română
    • Slovenčina
    • Suomi
    • Svenska
    • Tiếng Việt
    • Türkçe
    • Ελληνικά
    • Български език
    • Русский
    • Српски
    • Українська мова
    • עִבְרִית
    • العربية
    • فارسی
    • मराठी
    • हिन्दी
    • বাংলা
    • ગુજરાતી
    • தமிழ்
    • ಕನ್ನಡ
    • ภาษาไทย
    • 한국어
    • 日本語
    • 简体中文
    • 繁體中文
  • Have an account? Log in
    Have an account?
    · Forgot password?

    New to Twitter?
    Sign up
By using Twitter’s services you agree to our Cookie Use and Data Transfer outside the EU. We and our partners operate globally and use cookies, including for analytics, personalisation, and ads.
mjtsai's profile
Michael Tsai
Michael Tsai
Michael Tsai
Verified account
@mjtsai

Michael TsaiVerified account

@mjtsai

Mac Software Developer

Joined August 2007
  • © 2016 Twitter
  • About
  • Help
  • Terms
  • Privacy
  • Cookies
  • Ads info
Dismiss
Previous
Next

Go to a person's profile

Saved searches

  • Remove
  • Verified account @
Suggested users
  • Verified account @
  • Verified account @

Retweet this to your followers?

Optional comment for Retweet
 
 

Saved searches

  • Remove
  • Verified account @
Suggested users
  • Verified account @
  • Verified account @
140

Are you sure you want to delete this Tweet?

Promote this Tweet

Block

  • Add a location to your Tweets

    When you tweet with a location, Twitter stores that location. You can switch location on/off before each Tweet and always have the option to delete your location history. Learn more

    Profile summary

    Your lists

    Create a new list


    Under 100 characters, optional

    Privacy

    Copy link to Tweet

    Embed this Tweet

    Embed this Video

    Add this Tweet to your website by copying the code below. Learn more

    Add this video to your website by copying the code below. Learn more

    Hmm, there was a problem reaching the server.

    Preview

    Log in to Twitter

    · Forgot password?
    Don't have an account? Sign up »

    Sign up for Twitter

    Not on Twitter? Sign up, tune into the things you care about, and get updates as they happen.

    Sign up
    Have an account? Log in »

    Two-way (sending and receiving) short codes:

    Country Code For customers of
    United States 40404 (any)
    Canada 21212 (any)
    United Kingdom 86444 Vodafone, Orange, 3, O2
    Brazil 40404 Nextel, TIM
    Haiti 40404 Digicel, Voila
    Ireland 51210 Vodafone, O2
    India 53000 Bharti Airtel, Videocon, Reliance
    Indonesia 89887 AXIS, 3, Telkomsel, Indosat, XL Axiata
    Italy 4880804 Wind
    3424486444 Vodafone
    » See SMS short codes for other countries

    Confirmation

     

    Buy Now

    Hmm... Something went wrong. Please try again.

    Welcome home!

    This timeline is where you’ll spend most of your time, getting instant updates about what matters to you.

    Tweets not working for you?

    Hover over the profile pic and click the Following button to unfollow any account.

    Say a lot with a little

    When you see a Tweet you love, tap the heart — it lets the person who wrote it know you shared the love.

    Spread the word

    The fastest way to share someone else’s Tweet with your followers is with a Retweet. Tap the icon to send it instantly.

    Join the conversation

    Add your thoughts about any Tweet with a Reply. Find a topic you’re passionate about, and jump right in.

    Learn the latest

    Get instant insight into what people are talking about now.

    Get more of what you love

    Follow more accounts to get instant updates about topics you care about.

    Find what's happening

    See the latest conversations about any topic instantly.

    Never miss a Moment

    Catch up instantly on the best stories happening as they unfold.

    Previous Tweet Next Tweet
    1. Michael Tsai ‏@mjtsai Mar 2

      1Password’s Cleartext IPC: http://mjtsai.com/blog/2016/03/02/1passwords-cleartext-ipc/ … #mjtsaiblog

      0 replies 1 retweet 2 likes
    2. Landon Fuller ‏@landonfuller Mar 2

      @mjtsai I'm just surprised they're using TCP, since local IPC mechanisms provide access to peer user/process credentials.

      0 replies 0 retweets 0 likes
    3. Gwynne Raskind ‏@ameaijou Mar 2

      @landonfuller @mjtsai If I had to wager an uneducated guess, possibly browser plugins can’t use all the good APIs (for security, ironically)

      0 replies 0 retweets 2 likes
      Michael Tsai Verified account ‏@mjtsai Mar 2

      @ameaijou @landonfuller That is my understanding as well.

      3:49 PM - 2 Mar 2016
      0 replies 0 retweets 0 likes
        1. Landon Fuller ‏@landonfuller Mar 2

          @mjtsai @ameaijou Looks like there are options: https://developer.chrome.com/extensions/nativeMessaging … && https://developer.apple.com/library/safari/documentation/Tools/Conceptual/SafariExtensionGuide/CommunicatingwithyourOSXApplication/CommunicatingwithyourOSXApplication.html#//apple_ref/doc/uid/TP40009977-CH23-SW4 … &&https://developer.mozilla.org/en-US/docs/Mozilla/js-ctypes/js-ctypes_reference …

          0 replies 0 retweets 1 like
        2. Gwynne Raskind ‏@ameaijou Mar 2

          @landonfuller @mjtsai But now you’ve wiped out _any_ hope of using common code across browsers, much less platforms.

          0 replies 0 retweets 1 like
        3. View other replies
        4. Landon Fuller ‏@landonfuller Mar 2

          @ameaijou @mjtsai When it comes to security, portability at the raw IPC level doesn't seem like an overriding concern.

          0 replies 0 retweets 0 likes
        5. Gwynne Raskind ‏@ameaijou Mar 2

          @landonfuller @mjtsai In theory, agreed. In practice, 1Password has to security-check all of their code heavily. More platform support (1/N)

          0 replies 0 retweets 0 likes
        6. Gwynne Raskind ‏@ameaijou Mar 2

          @landonfuller @mjtsai means more code to review and more chance for mistakes. Given that you can’t eavesdrop on loopback without root (2/N)

          0 replies 0 retweets 1 like
        7. View other replies
        8. Gwynne Raskind ‏@ameaijou Mar 2

          @landonfuller @mjtsai anyway, I think it’s a reasonable compromise for the sake of less code to maintain (and the solutions you linked (3/N)

          0 replies 0 retweets 0 likes
        9. Gwynne Raskind ‏@ameaijou Mar 2

          @landonfuller @mjtsai , while correct, involve a good bit of complexity of deployment. Might well be something they’re planning to do (4/5)

          0 replies 0 retweets 0 likes
        10. Gwynne Raskind ‏@ameaijou Mar 2

          @landonfuller @mjtsai in the future - I rather hope it is; I have every reason to believe they’ve thought of this stuff.) (5/5)

          0 replies 0 retweets 0 likes

      Loading seems to be taking a while.

      Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.

        Promoted Tweet

        false

        • © 2016 Twitter
        • About
        • Help
        • Terms
        • Privacy
        • Cookies
        • Ads info