Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dc352
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
19 ms
·
151.
▲
How Certbot and Letsencrypt Work (DNS and SNI-TLS
(dan.enigmabridge.com)
3 points
by
dc352
10y ago
|
0 comments
152.
▲
Powering Simplicity of Certbot and Letsencrypt – Domain Verification
(dan.enigmabridge.com)
1 points
by
dc352
10y ago
|
0 comments
153.
▲
HTTPS Certificates Show Where Their Key Comes From
(dan.enigmabridge.com)
66 points
by
dc352
10y ago
|
20 comments
154.
▲
by
dc352
10y ago
Can I attribute this to a particular name?
155.
▲
by
dc352
10y ago
It is an interesting one - here is the original source (and there were many more mentioning 300 days). https://community.letsencrypt.org/t/dns-authorization-lifeti... It is from 14 June 2016 (a few months back), @pfg s
156.
▲
by
dc352
10y ago
So do you imply that the account key is created from scratch for every new certificate? Why we were surprised (and we don't say the implementation is necessarily wrong!) is that I can use the account key anywhere. If the genuine user k
157.
▲
by
dc352
10y ago
The difference is that I need to access your file system only once to get your account key. I need permanent access to exploit your automation. Attackers can also scale revenues, potentially, by selling account keys to third parties.
158.
▲
by
dc352
10y ago
I've updated the blog post. I don't think, though, it has any material impact on the rest of the text.
159.
▲
Let's Encrypt AUTHZ Reuse and Eternal Account Key
(dan.enigmabridge.com)
107 points
by
dc352
10y ago
|
39 comments
160.
▲
Let’s Encrypt’s Vulnerability as a Feature – AUTHZ Reuse and Eternal Account Key
(dan.enigmabridge.com)
2 points
by
dc352
10y ago
|
0 comments
161.
▲
RSA Signatures in Java8 Without Bouncy Castle
(bits.enigmabridge.com)
1 points
by
dc352
10y ago
|
0 comments
162.
▲
EJBCA PKI with CloudHSM
(enigmabridge.com)
2 points
by
dc352
10y ago
|
0 comments
163.
▲
The importance of DNS to startup – get emails delivered
(dancvrcek.com)
1 points
by
dc352
10y ago
|
0 comments
164.
▲
by
dc352
10y ago
Bugger. Thanks!
165.
▲
The importance of DNS to startup – get emails delivered
(dancvrcek.com)
1 points
by
dc352
10y ago
|
2 comments
166.
▲
Jekyll blog, version control, and publishing with a Git hook
(bits.enigmabridge.com)
2 points
by
dc352
10y ago
|
0 comments
167.
▲
Neural net, client-side password strength meter. Is downloading 640K worth it?
(usenix.org)
1 points
by
dc352
10y ago
|
0 comments
168.
▲
by
dc352
10y ago
My last comment was towards key generation, not curves. Bug as I said, I am not in a position to say what the impact is.
169.
▲
by
dc352
10y ago
My err - rubbish wording as I was thinking primes and talking curves. Still, while I'm punching here a wee bit above my weight - I should read the 186-4 again - there are some tests to verify the strength of the prime. Is it enough for
170.
▲
by
dc352
10y ago
ECDH doesn't give you authenticity, i.e., you can't get a certificate for that. When you look at ways to generate ECC keys, there are classes of vulnerable numbers for which you need to test.
171.
▲
by
dc352
10y ago
I don't say switching is a bad idea but not sure it would prevent this kind of attack :)
172.
▲
by
dc352
10y ago
A short discussion on my blog: https://www.dancvrcek.com/re-investigating-the-origins-of-rs...
173.
▲
The Million-Key Question: Investigating the Origins of RSA Public Keys
(usenix.org)
106 points
by
dc352
10y ago
|
33 comments
174.
▲
Re: Investigating the Origins of RSA Public Keys
(dancvrcek.com)
1 points
by
dc352
10y ago
|
0 comments
175.
▲
Anatomy of Passwords
(lightbluetouchpaper.org)
1 points
by
dc352
10y ago
|
0 comments
176.
▲
How we screwed-up ProductHunt launch
(dancvrcek.com)
1 points
by
dc352
10y ago
|
0 comments
177.
▲
by
dc352
10y ago
Not quite the answer, but well spotted! It still seems to be just KMS - we can do crypto operations in secure hardware as well. Thanks!
178.
▲
Disrupting CloudHSM – any takers?
1 points
by
dc352
10y ago
|
2 comments
179.
▲
My favourite programming language is .. solder
(boldport.com)
3 points
by
dc352
10y ago
|
5 comments
180.
▲
Compute password for any UPCxxxxxxx WiFi hotspot
(dancvrcek.com)
7 points
by
dc352
10y ago
|
0 comments
More ›