Terence Eden. He has a beard and is smiling.

Terence Eden’s Blog

Theme Switcher:

Should you use Let's Encrypt for internal hostnames?

· 29 comments · 500 words · Viewed ~35,240 times


A padlock engraved into a circuit board.

Julien Savoie has written a brilliant post explaining how you can enable https on your intranet. This is useful for several reasons. It means your employees aren't constantly fighting browser warnings when trying to submit stuff internally. All your http traffic is encrypted. You don't need to install a self-generated root certificate on devices. Lovely! But there's a downside. Every TLS…

Minor Reddit Security Bug Fixed

· 2 comments · 350 words


I'm the sort of hip cat who frequents Internet Bulletin Boards. Recently I found myself needing to verify the email address associated with my Reddit account. The email I received from Reddit was charmingly lo-fi and eschewed those bourgeois capital letters. Notice the (teensy tiny) flaw? Yup, it's using vanilla "http" rather than the super secure "https". Earlier this year, Reddit switched …

WebDAV, SSL Handshake, OwnCloud, CloudFlare, and Ubuntu 12.04

· 250 words · Viewed ~1,576 times


Right, that's enough keyword stuffing! I've been trying to mount an OwnCloud instance via WebDAV. I kept receiving the error Mounting failed. SSL handshake failed: SSL error: sslv3 alert handshake failure Or SSL handshake failed: SSL alert received: Handshake failed The route of this problem seems to be that the version of libneon (the WebDAVS connector library) shipped with Ubuntu 12.04…

Path - Privacy & Security Problems

· 2 comments · 250 words · Viewed ~297 times


I'm trying out the new Android app for Path - the new social networking service. I've discovered something rather troubling... Most of the app's communication with the Path servers is over SSL. This means that no-one can see the data you're sending and receiving. If there are snoops on your network, they will only be able to see the encrypted data flowing back and forth. In general, this is…

A (Minor) Twitter Privacy Bug?

· 1 comment · 500 words · Viewed ~204 times


The Twitter logo.

Quick Summary Twitter's secure API hides the contents of the tweets you are reading. But it doesn't hide the images of those you converse with. Raised as Issue 2175. A Bit More Detail Twitter has a secure (HTTPS) and insecure (HTTP) API. When calling the secure API, all the content of the returned message (tweets) are encrypted. Eavesdroppers only see the cipher-text - essentially garbage. …