Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
cubesnooper
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
cubesnooper
4y ago
> How is this more secure than simply creating new certificates and replacing the old ones is the authorized_keys files? It’s more convenient for me than updating authorized_keys. When I build a new machine, for example, I first genera
32.
▲
by
cubesnooper
4y ago
SSH provides native support for certificates; they’re a custom (non‐X.509) format. The signatures are generated with the ssh-keygen command; I set my infrastructure up purely by reading the manpage, not referring to any blog posts or anythi
33.
▲
by
cubesnooper
4y ago
I’m glad Userify works well for you. For my purposes, whipping up a couple of cronjobs involving curl and OpenSSH is more appropriate than relying on an external cloud service. > But I've been burned before when a central auth serve
34.
▲
by
cubesnooper
4y ago
> So anyone on your LAN can visit the URL and download the CA private key? No, the only files served to the LAN are the certificates, which contain the signatures by the CA of the public keys of other machines. Those are safe to distribu
35.
▲
by
cubesnooper
4y ago
You’re thinking of known_hosts, not authorized_keys.
36.
▲
by
cubesnooper
4y ago
Rotation is actually a lot easier with certificates. I just generate a new key on the client, copy the public key to the CA, and I’m done, with no need to repopulate authorized_keys on all my other machines. In another comment I went into m
37.
▲
by
cubesnooper
4y ago
I have a Raspberry Pi dedicated to generating certificates. It serves the files to my LAN statically via a webserver, and is otherwise heavily firewalled. I don't run any other software on the Pi, so barring an exploit in the webserver
38.
▲
by
cubesnooper
4y ago
> On the other side, as a personal user of SSH with basically one person to worry about, the effort of setting up a certificate seems like just a waste versus the existing key-based infrastructure; I don't understand at all what att
39.
▲
by
cubesnooper
4y ago
I’m reading the third book right now and so far the series has been a real struggle to get through. In the first two I found the setting mildly interesting, but mixed with uninteresting characters, dialogue, and plot, with writing that was
40.
▲
by
cubesnooper
4y ago
Ubisoft actually sells some DRM‐free games on GOG—the first Assassin’s Creed, Far Cry 1 and 2, Rayman Origins (but not Rayman Legends). If you have disk space to spare, I would recommend downloading GOG’s offline installers as a backup. The
41.
▲
by
cubesnooper
4y ago
I would love to have a voice changer so I could put video streams online without fear of having my voice cloned: https://www.forbes.com/sites/thomasbrewster/2021/10/14/huge-... Sure, I’m nowhere nea
42.
▲
by
cubesnooper
4y ago
> the main thing you're getting out of the VPS is the static IP. Yes, that and RDNS. > If you're paying for that, why not just pay for a static IP at home? That’s a good question. I too hear that mail providers consider IP b
43.
▲
by
cubesnooper
4y ago
> You need a dedicated box, not a VPS. … Unlike some people are saying, you should never do this off a VPS if you have an interest in keeping the email secure and functioning for a long time. I agree that hosting a mail server directly o
44.
▲
by
cubesnooper
4y ago
You don’t have to store your DKIM keys on the VPS. I keep my signing infrastructure local, and send outgoing mail over a WireGuard tunnel so it looks like it was sent from the VPS.
45.
▲
by
cubesnooper
4y ago
Spam is often sent from big providers, too. For several years I hosted my email the “middle ground” way (i.e., relaying outgoing mail via Google Workspace), and despite using DMARC correctly it was not infrequent that my emails would go to
46.
▲
by
cubesnooper
4y ago
> I just don't understand the attraction of self hosting email. For several years I’ve hosted in the “middle ground” sense described by the OP, running my own incoming mail server and relaying outgoing mail through a big provider. T
47.
▲
by
cubesnooper
4y ago
TOTP is not as secure as WebAuthn, because if you enter the TOTP code into a phishing site, the phisher can now successfully authenticate as you. WebAuthn was specifically designed to be immune to this case: if you were to use your WebAuthn
48.
▲
by
cubesnooper
4y ago
It’s almost as trivial with this format too, at least to guess what address is used for other services, though it has a strong advantage over using ‘+’ in GMail in that nothing will try this automatically. It’s hard to believe anyone would
49.
▲
by
cubesnooper
5y ago
I know there are CT search services like crt.sh, but is it practical to download the raw data and search it locally? If the logs are append‐only, it feels like a perfect usecase for rsync.
50.
▲
by
cubesnooper
5y ago
> That said, the only caveat to hosting in your own house is it could suffer a fire, and your data is wiped Well, there are other reasons to prefer using external hosting. Home connections are typically port‐filtered, have dynamic IP add
51.
▲
by
cubesnooper
5y ago
Recursive resolution leaks all my DNS queries in plaintext to my ISP, the nameservers, and everyone in between; on top of that, my ISP can monitor what sites I’m viewing through SNI and server IP. If my DNS queries are encrypted and anonymi
52.
▲
by
cubesnooper
5y ago
But that would leak all of my DNS queries in cleartext. I use cloudflared to do DNS lookups via Cloudflare’s Tor onion. It’s weak to vulnerabilities like this one, but it disassociates my DNS lookups from myself, and TLS certificates mitiga
53.
▲
by
cubesnooper
5y ago
I’ve hosted a personal Matrix server (Dendrite) and web client (Element) for the last six months, with unhappy results. In practice an entirely self‐hosted Matrix stack seems to be kind of unreliable for me. Having joined just a couple of l
54.
▲
by
cubesnooper
5y ago
I’ve seen a few venues where it’s possible to digitally buy DRM‐free movies, as a straight up downloadable 1080p MP4. Unfortunately the selection is very limited, to pretty much just a handful of indie documentaries and short films. I kno
55.
▲
by
cubesnooper
5y ago
For personal domains, I bite the initial cost and buy the domain for 10 years, then every year top it up to 10 again. For a $20/yr domain that’s only $200 up front, and if the cost suddenly goes up or some other TLD policy changes that
56.
▲
by
cubesnooper
5y ago
To keep Google from maintaining a profile of my behavioral patterns and video viewing history based on my IP address.