Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ekr____
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
151.
▲
by
ekr____
1y ago
Android does same-provider auto-upgrade if it determines that the recursive supports DoH (last I checked, if it's on Google's list). However, this means that unless you configure your own resolver, you're vulnerable to whoeve
152.
▲
by
ekr____
1y ago
> In practice, TLS certificates are given out to domain owners, and domain ownership is usually proven by being able to set a DNS record. This means compromise of the authorative DNS server implies compromise of TLS. Yes, except for CT,
153.
▲
by
ekr____
1y ago
This isn't true. Even if the DNS server is secure, the network between you and the server cannot be trusted.
154.
▲
by
ekr____
1y ago
Yes, that's correct. The purpose of the WebPKI and TLS is not to protect against this form of attack but rather to protect against compromise of the network between the client and the server.
155.
▲
by
ekr____
1y ago
This isn't correct, because your domain name server may be insecure even while the one used by the CA is secure. Moreover, CT helps detect misissuance but does not detect incorrect responses by your resolver.
156.
▲
by
ekr____
1y ago
Sort of. Firefox doesn't filter the list of revoked certificates the way Chrome does.
157.
▲
by
ekr____
1y ago
The problem with requiring OCSP stapling is that it's not practically enforceable without breakage. The underlying dynamics of any change to the Web ecosystem is that it has to be incrementally deployable, in the sense that when elemen
158.
▲
by
ekr____
1y ago
As a number of people have observed, what's happening now is mostly about key establishment, which tends to happen relatively infrequently, and so the overhead is mostly not excessive. With that said, a little more detail: - Current PQ
159.
▲
by
ekr____
1y ago
More or less. Corporations fund research all the time. Just to pick a random example, check out the acknowledgements on this paper: https://eprint.iacr.org/2025/132 "This work was funded in part by NSF Award CNS-2
160.
▲
Understanding Memory Management, Part 7: Advanced Garbage Collection
(educatedguesswork.org)
9 points
by
ekr____
1y ago
|
0 comments
161.
▲
by
ekr____
1y ago
No, not really. It's just not even in the same order of magnitude in terms of level of effort.
162.
▲
by
ekr____
1y ago
> If you cut that compensation in half you could have funded a small team of devs to have finished Oxidation of Firefox and have a really interesting browser, and potentially a really rich GUI stack, JavaScript Engine and who knows what
163.
▲
by
ekr____
1y ago
> I get that it's a quirk of the sport's history, but it's funny and dumb that swimming awards medals and records for being the fastest at a slower stroke. It's like if track meets would have a 100m sprint, a 100m ski
164.
▲
by
ekr____
1y ago
The usual argument against clothing restrictions (see also supershoes in running and various aero stuff in cycling) is that you want the sport to reward the best athletes rather than turning into a technological arms race. This is especiall
165.
▲
by
ekr____
1y ago
Basically none. First the success rate of any new IP-based protocol through most devices is incredibly low, especially now that NAT is so common. Second, part of why QUIC runs over UDP is because the operating system generally won't le
166.
▲
by
ekr____
1y ago
Well, this is basically what we do, except that we try to negotiate to the highest version during the period before the flag day. This is far more practical for three reasons: 1. You actually get benefit during the transition period because
167.
▲
by
ekr____
1y ago
As I noted below, there was real discussion around the version number for TLS 1.3. I don't recall any such discussion for 1.1 and 1.2.
168.
▲
by
ekr____
1y ago
FWIW, these aren't actually in TLS 1.0. Extensions (including SNI) are in later spec but introduces in RFC 3546 ( https://www.rfc-editor.org/rfc/rfc3546 ). Session tickets are in RFC 4507. What TLS 1.0 did was to le
169.
▲
by
ekr____
1y ago
Yes, this is a seriously difficult problem with only partial solutions. The basic math of any kind of negotiation is that you need the minimum set of cryptographic parameters supported by both sides to be secure enough to resist downgrade.
170.
▲
by
ekr____
1y ago
Just on a technical note, TLS 1.3 only uses AEAD ciphers where the nonce is determined by the record numbers, so it actually is in principle possible to decrypt the packets even if they are received out of order by trial decrypting with dif
171.
▲
by
ekr____
1y ago
There used to be, though it's less true now. However, the reason to treat them distinctly (as different origins, technically) is that HTTPS provides integrity whereas HTTP does not. So, consider the case where the client enters an HTTP
172.
▲
by
ekr____
1y ago
This has a number of negative downstream effects. First, recall that links are very often inter-site, so the consequence would be that even when a server upgraded to TLS 1.2, clients would still try to connect with TLS 1.1 because they were
173.
▲
by
ekr____
1y ago
This seems like a truly unreasonable level of political skill for nearly any setting. We're talking about changing every endpoint in the Internet, including those which can no longer be upgraded. I struggle to think of any entity or se
174.
▲
by
ekr____
1y ago
There's really not much chance of that, given that the protocol is maintained by the IETF TLS Working Group.
175.
▲
by
ekr____
1y ago
Moreover, there's not really much in the way of choices here. If you don't have this kind of automatic version negotiation then it's essentially impossible to deploy a new version.
176.
▲
by
ekr____
1y ago
IIRC they were using a cipher suite to signal the new version. Cipher suites were basically the only signaling mechanism in SSLv2 (and SSLv3/TLS 1.0 before extensions were introduced).
177.
▲
by
ekr____
1y ago
Yes, I understood your reasoning. I'm just saying that I don't think anyone floated calling it SSL 3.4.
178.
▲
by
ekr____
1y ago
When TLS 1.3 was finally standardized, there was quite a bit of debate about whether in light of the how different it was from TLS 1.2 we should continue to use the 1.3 version number. ISTR that TLS 2 and TLS 4.0 were both floated--though I
179.
▲
by
ekr____
1y ago
The situation is additionally confused by the fact that the version numbers do not give a good clue to how different the protocols were. Specifically: SSLv2 was the first widely deployed version of SSL, but as this post indicates, had a num
180.
▲
by
ekr____
1y ago
Generally, ultra food preferences are really personal. The broad facts are: (1) you need a certain level of calories to keep going and it's more than you'd think (though see below) (2) running long distances is hard on your digest
More ›