Should you use Let's Encrypt for internal hostnames?

by @edent | , , | 25 comments | 450 words | Read ~28,447 times.

A padlock engraved into a circuit board.

Julien Savoie has written a brilliant post explaining how you can enable https on your intranet. This is useful for several reasons. It means your employees aren't constantly fighting browser warnings when trying to submit stuff internally. All your http traffic is encrypted. You don't need to install a self-generated root certificate on devices. Lovely!…

Path - Privacy & Security Problems

by @edent | , , , , , , | 2 comments | 250 words | Read ~270 times.

I'm trying out the new Android app for Path - the new social networking service. I've discovered something rather troubling... Most of the app's communication with the Path servers is over SSL. This means that no-one can see the data you're sending and receiving. If there are snoops on your network, they will only be…

A (Minor) Twitter Privacy Bug?

by @edent | , , , , , | 1 comment | 500 words | Read ~180 times.

Quick Summary Twitter's secure API hides the contents of the tweets you are reading. But it doesn't hide the images of those you converse with. Raised as Issue 2175. A Bit More Detail Twitter has a secure (HTTPS) and insecure (HTTP) API. When calling the secure API, all the content of the returned message (tweets)…