4 ms·
(As the author of the post) I've written and worked on a few TLS implementations, so it wasn't terribly interesting to me. And I have to go to work tomorrow an
by mcpherrinm 28d ago
(As the author of the post)
I've written and worked on a few TLS implementations, so it wasn't terribly interesting to me. And I have to go to work tomorrow and solve real, modern CA problems :)
But in short, I wanted to use Go, and it doesn't support SSLv3, the SSLv2 Client Hello, or the 40-bit RC4-MD5 export-grade cipher suites which I wanted to support too.
I was more shocked that I managed to get stock OpenSSL to issue a certificate that worked. There's a number of things that didn't work there, too. You can find my scars in mkcert.sh in the repo. Perhaps all of this is worthy of a follow-up post.
I could have tried to get some old server running instead, but I wouldn't have wanted to deploy that on the internet, even on an isolated Fly VM.
- dividuum 27d agoI bet all the certificate metadata shown in the „View a certificate“ popup window is vulnerable to cross-site scripting. Back then you probably wouldn’t get a <script> tag through a CA's review process and I found such a problem in Netscape's image „About page“ popup.
- WatchDog 27d agoIf it were vulnerable to XSS, why would you even want it properly signed by a CA? People almost never inspect the certificates of working websites, the only time they might look at it is when it fails validation.
- Sophira 27d agoI actually do like to view certificates of working sites, because it can be interesting to see what's listed in the Subject Alternative Names field. It can lead to some interesting observations about what sites are linked.
- mcpherrinm 27d agoNetscape of this era predates the Subject Alternative Name :)
- kyleomalley 27d agoStrange seeing how people have such a hard time seeing others using AI and seem to want to complain about it instead of just, well, asking AI why something was likely done a way. It works both ways my dudes, experts don’t need to explain every last detail, prompt a bot with the context until you understand. From my prospective, the outputs of a bot aren’t the interesting bits, it’s the input prompt that should warrant more attention.
- rustyminnow 27d agoI asked my AI for a rebuttal to your argument and it came up with some pretty good points. Since inputs are more interesting than outputs I've included my prompt; you should submit it to your AI to see why you're wrong. > I'm debating with someone online. Can you come up with a counter argument? Here's what they said: <QUOTE>