Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Scott_Helme_
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
31.
▲
by
Scott_Helme_
8y ago
Which is insanely difficult to do at scale and would take a considerable amount of time and resources. Not to mention being really obvious! I'm happy with making things crazy hard for the bad actors out there.
32.
▲
by
Scott_Helme_
8y ago
Have a look at this post: https://www.troyhunt.com/heres-why-your-static-website-needs...
33.
▲
by
Scott_Helme_
8y ago
Our accuracy rate is currently around 99.6% so we're doing pretty well but of course I don't think it can ever be 100% either. The biggest thing we've come across so far is geo-sensitive handling of requests. Some sites will
34.
▲
by
Scott_Helme_
8y ago
Indeed the HTTP -> HTTPS redirect is only the first step in solving the problem. A 301 redirect will offer some lasting protection as it can be cached but it's not really that great. The goal here is to take the first step to get on
35.
▲
by
Scott_Helme_
8y ago
This really highlights the problem that we need a proper technical solution for and not hacky traffic interception/redirects! I also created http://httpforever.com/ for this purpose until such a time that the problem i
36.
▲
by
Scott_Helme_
8y ago
It was screenshots taken for the purposes of demonstration and wasn't his publicly hosted site. Do you think that he'd take that kind of risk?
37.
▲
by
Scott_Helme_
8y ago
There's a difference between resolving something locally or setting up a demo for the purposes of capturing screenshots and having a website resolve on the public Internet and serve that content.
38.
▲
by
Scott_Helme_
8y ago
Phishing using EV, documented in 2011: https://news.netcraft.com/archives/2011/12/30/phishing-sites...
39.
▲
by
Scott_Helme_
8y ago
I can't find any copies of that in any cache showing it was ever actually online, simply mocked-up photos posted to social media.
40.
▲
by
Scott_Helme_
8y ago
This is kind of the point really isn't it. There was no forgery or abuse here, the certificate was issued in full accordance to the rules set out in the CA/Browser Forum Baseline Requirements and the EV SSL Guidelines. If there we
41.
▲
by
Scott_Helme_
9y ago
More or less, yeah..
42.
▲
by
Scott_Helme_
9y ago
There is/was discussion in the standards body of using the SRI hash for exactly this purpose. It sounds really promising but iirc there was a privacy kink to work out.
43.
▲
by
Scott_Helme_
9y ago
Yeah, the best way to handle this is with a version in the path and then the host can knowingly/willingly upgrade the library version and SRI hash at the same time.
44.
▲
Protecting sites from Cryptojacking with CSP and SRI
(scotthelme.co.uk)
237 points
by
Scott_Helme_
9y ago
|
76 comments
45.
▲
by
Scott_Helme_
9y ago
> As you live in the UK, and you noticed business you thought was local or US based turned out to be from the Philippines or Russia, would you care? It's essential the country be included. If I "thought" it was local or if
46.
▲
by
Scott_Helme_
9y ago
Something that I see a lot in the discussions around EV is "the EV indicator might make users feel" x, y or z. Not to sound too harsh but I don't care about making the user 'feel' anything. I want to make them more
47.
▲
by
Scott_Helme_
9y ago
I totally disagree with #2. What relevance is the country I reside or the country the company was founded matter? Half of the time companies have registered addresses all over the world for tax reasons, not to mention things like franchises
48.
▲
by
Scott_Helme_
9y ago
I think completely the opposite. The sooner we can stop depending on the user to behave a certain way so that we can be secure, the better. We told users for years to look for a padlock and https in the address bar before entering passwords
49.
▲
by
Scott_Helme_
9y ago
I'm not opposed to your proposal but I would have some hesitation about an intersitial like that. The example works well with Amazon and Apple but what about: - some-company.com - Other Company [United Kingdom] - some-company.com-fake.
50.
▲
by
Scott_Helme_
9y ago
How is the user supposed to know what to verify in the EV indicator though? If the user is expected to know that the EV indicator should contain "Apple Inc.", why can't we just expect them to know the address should be apple.
51.
▲
by
Scott_Helme_
9y ago
Agreed, that's exactly the purpose of EV. The problem is that the user has to know to look for EV, check it's present and check that it says "Apple Inc." which is a lot of things to expect of the user! There are also lot
52.
▲
by
Scott_Helme_
9y ago
This is my biggest real concern with EV, we depend 100% on the user for it to have any value. I think we learnt that lesson with 'check for https in the address bar' and now we have HSTS instead.
53.
▲
by
Scott_Helme_
9y ago
Would the certificate really help you here though? If we look back at most of the big data breaches over the last few years then we regularly find out long after it's happened. It's generally a news story or a headline somewhere t
54.
▲
by
Scott_Helme_
9y ago
In April next year we will have the CT requirement for all certificates so EV will lose an edge there. For the pinning in a mobile app, would you still depend on the PKI or not just pin against your own private CA/certificates?
55.
▲
by
Scott_Helme_
9y ago
There is a huge presence of EV on financial sites where it is used considerably more than in any other sector. I never did come across a reasonable explanation for that though, I'd be interested to know why.
56.
▲
by
Scott_Helme_
9y ago
I do touch on that point in the article but the numbers show that larger sites are more likely to use EV and smaller sites are less likely to use it. The figures seem to go against the logical assumption. I grabbed the figures and published
57.
▲
by
Scott_Helme_
9y ago
The only safe way to try and do that would be to make sure that the max-age of your policy was never more than the remaining validity of your longest valid certificate.
58.
▲
by
Scott_Helme_
9y ago
Having multiple backup keys doesn't really provide much benefit beyond having 2 well protected backups. Most of the same risks still exist like the minimum key size changing.
59.
▲
by
Scott_Helme_
9y ago
In many of my articles I discuss the various ways to deploy HPKP including leaf pins, intermediate pins and root pins, or even a combination of different types of pin. They all come with various challenges and considerations that a site nee
60.
▲
by
Scott_Helme_
10y ago
Hopefully this event will be 'market motivation' enough for them and any companies who will follow them. If this stuff is insecure it will be found and brought to light. The only question is will the good guys find it or the bad
More ›