Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
agwa
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
31.
▲
by
agwa
6mo ago
Correct. Even a million rounds of hashing only adds 20 bits of security. No need if your secret is already 128 bits.
32.
▲
by
agwa
6mo ago
But JWTs are usually used as bearer tokens when doing API authentication. Those are definitely secrets that need to be scanned for. Or are you suggesting that the API requests are signed with a private key stored in an HSM, and the JWT cert
33.
▲
by
agwa
6mo ago
Instead of using a CA, why not set the key's PIN policy to "once" and use an agent (e.g. https://github.com/FiloSottile/yubikey-agent/ ) that holds an active session to the yubikey? You start the age
34.
▲
by
agwa
7mo ago
Fun fact - in C++ std::sort has undefined behavior, and can crash[1], if you try to sort a container with NaNs in it. [1] https://stackoverflow.com/questions/18291620/why-will-stdsor...
35.
▲
by
agwa
7mo ago
The blog post is also complaining about the options to create a screenshot, copy a link to a text fragment, copy a link without trackers, debug accessibility issues, auto-fill a form, and even to print the page. Also, Mozilla Corporation&#x
36.
▲
by
agwa
7mo ago
In an alternative timeline, Firefox makes their context menu really short and someone writes a blog post ranting about how it deprives functionality from power users. In fact, I've read several such rants about Firefox removing functio
37.
▲
by
agwa
7mo ago
At the beginning of a TCP connection, which is when the certificate chain is sent, you can't send more data than the initial congestion window without waiting for it to be acknowledged. 160KB is far beyond the initial congestion window
38.
▲
Why IP Address Certificates Are Dangerous and Usually Unnecessary
(agwa.name)
3 points
by
agwa
8mo ago
|
0 comments
39.
▲
by
agwa
8mo ago
> It's also not quite clear how to revoke this challenge, and how domain expiration deal with this CAs can cache the record lookup for no longer than 10 days. After 10 days, they have to check it again. If the record is gone, whic
40.
▲
by
agwa
8mo ago
It doesn't comply with one or more root store policies (which all incorporate the Baseline Requirements by reference, which incorporate various specs, such as RFC5280, by reference). Mozilla root store policy: https://www.mo
41.
▲
by
agwa
8mo ago
This usually indicates that the CA was issuing non-compliant certificates and needed to prevent further non-compliance. Will be interesting to watch Bugzilla for the incident report: https://bugzilla.mozilla.org/buglist.cgi?
42.
▲
by
agwa
8mo ago
If an attacker gets a misissued cert not through BGP or DNS hijacks, but by exploiting a domain validation flaw in a CA (e.g. https://bugzilla.mozilla.org/show_bug.cgi?id=2011713 ) then it's trivial for them to use it a
43.
▲
by
agwa
8mo ago
Having the customer send me the key is less secure because that key never gets rotated. Google wants to discourage long-lived credentials so badly that new organizations can't even create service account keys by default anymore. Havin
44.
▲
by
agwa
8mo ago
Ah, I didn't know that dialback doesn't use TLS. That's too bad.
45.
▲
by
agwa
8mo ago
Google Chrome (along with Mozilla, and eventually the other root stores) distrusted Symantec, despite being the largest CA at the time and frequently called "too big to fail".
46.
▲
by
agwa
8mo ago
Is there a reason why dialback isn't the answer? I would think it's more secure than clientAuth certs because if an attacker gets a misissued cert they'd have to actually execute a MitM attack to use it. In contrast, with a m
47.
▲
by
agwa
8mo ago
XMPP identifiers have domain names, so the XMPP server can check that the DNS SAN matches the domain name of the identifiers in incoming XMPP messages. I've seen non-XMPP systems where you configure the DNS name to require in the clien
48.
▲
by
agwa
8mo ago
After the WebPKI banned the issuance of new SHA-1 certificates due to the risk of collisions, several major payment processors (Worldpay[1], First Data[2], TSYS[3]) demanded to get more SHA-1 certificates because their customers had credit
49.
▲
by
agwa
8mo ago
They denied my request for a service account quota increase even though my use case[1] was literally straight from their documentation. They only increased it after I complained on Twitter and got retweeted by Corey Quinn. [1] https:/
50.
▲
by
agwa
9mo ago
Logs are sharded by the expiration date of the certificate, not the issuance date, so you should expect to see growth in shards covering the next 398 days (the maximum lifetime of certificates). As for the 2025h2 logs, these will not be acq
51.
▲
by
agwa
9mo ago
That doesn't work, as neither SNI nor the server_name field of the ECHConfig are allowed to contain IP addresses: https://www.ietf.org/archive/id/draft-ietf-tls-esni-25.html#... Even if it did work, the priva
52.
▲
by
agwa
9mo ago
> GitHub's migration guide tells developers to treat the new IDs as opaque strings and treat them as references. However it was clear that there was some underlying structure to these IDs as we just saw with the bitmasking Great,
53.
▲
by
agwa
9mo ago
2FA doesn't stop phishing unless it's WebAuthn. But SendGrid, which is owned by Twilio, only supports 2FA based on SMS or the Authy App (which is also made by Twilio): https://www.twilio.com/docs/sendgrid/
54.
▲
by
agwa
9mo ago
It gets its data from Open Street Map, so it's only up-to-date if volunteers are keeping it up-to-date. That said, https://nl.wikipedia.org/wiki/Centrale_Hemweg says the plant was converted to natural gas, not dec
55.
▲
by
agwa
9mo ago
The checksums are published in a transparency log, which uses a Merkle Tree[1] to make the attack you describe detectable. Source Spotter, which is unaffiliated with Google, continuously verifies that the log contains only one checksum per
56.
▲
by
agwa
9mo ago
> The Go module proxy doesn't make any guarantee that it will permanently store the checksum for any given module Incorrect. Checksums are stored forever, in a Merkle Tree, meaning if the proxy were to ever delete a checksum, it w
57.
▲
by
agwa
9mo ago
Interesting. In any case, libsodium's fiscal sponsor (Open Source Collective - https://opencollective.com/opensource ) is not a 501(c)(3) non-profit.
58.
▲
by
agwa
9mo ago
Any non-profit, or just charitable non-profits (aka 501(c)(3))? Unfortunately, the US does not consider producing open source software to be charitable activity.
59.
▲
by
agwa
10mo ago
If you add .git to the end of your module path and set $GOPRIVATE to the hostname of your Forgejo instance, then Go will not make any HTTPS requests itself and instead delegate to the git command, which can be configured to authenticate wit
60.
▲
by
agwa
10mo ago
There is no way to create an account for the Debian bug tracker. You have to jump through these hoops every single time you want to follow a bug.
More ›