TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Torrents Time bundles certificates and private keys

50 pointsby cgtyoderover 9 years ago

3 comments

cheezover 9 years ago
The torrents time server is just to allow your local browser to stream the videos that are being downloaded in a way that makes the browser happy and avoids mixed content issues. Why does it matter if the keys are shipped?<p>They&#x27;re a workaround that don&#x27;t improve or reduce security from what I can tell.<p>Edit: The more egregious parts of the security issues is due to any website being able to access that local server, the server running as root on OSX, etc. THAT is major.
评论 #11093615 未加载
shpxover 9 years ago
Why use proprietary software when there&#x27;s <a href="https:&#x2F;&#x2F;webtorrent.io&#x2F;" rel="nofollow">https:&#x2F;&#x2F;webtorrent.io&#x2F;</a><p>Is piratebay turning into another sourceforge or download.com?
评论 #11094736 未加载
jandover 9 years ago
I strongly dislike the idea of a CA going around revoking certs&#x2F;keys just because the keys were leaked somewhere.<p>This road (as wished for by the author) is very dangerous - it reads to me: &quot;If a software(-bug) or human error allows technically skilled personal to gain access to a private key, all connected keys shall be revoked&quot;.<p>This would apply to (possibly) millions of servers with e.g. vulnerable PHP versions or such stuff.<p>So. Torrents Time made a bad move. Why is that a CA-concern? Honestly, tell me.
评论 #11092519 未加载
评论 #11092513 未加载