Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
grittygrease
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
grittygrease
11y ago
The OpenSSL AES-GCM and P256 assembly code was also written by Vlad. There's no better person to write the Golang version.
32.
▲
by
grittygrease
12y ago
This is something more people should pay attention to when implementing forward secrecy. Session resumption counteracts forward secrecy when done incorrectly.
33.
▲
CloudFlare Enables ChaCha20/Poly1305 for all sites
(blog.cloudflare.com)
16 points
by
grittygrease
12y ago
|
3 comments
34.
▲
by
grittygrease
12y ago
The key server only accepts mutually authenticated TLS 1.2 connections with a strong cipher suite. We also require both certificates to be signed by CloudFlare's internal Certificate Authority.
35.
▲
by
grittygrease
12y ago
Breaking into a CloudFlare server does not get you this private key. CloudFlare does not keep this authentication key unencrypted on disk.
36.
▲
by
grittygrease
12y ago
We find that Android 2.2 and 2.3 are also relevant platforms that require alternative toolchains. Upgrades are not possible for many of these devices. As for setting up your CA, openssl's command line interface can be very clunky. CFSS
37.
▲
by
grittygrease
12y ago
Sign up for the next one on July 16 here: http://www.meetup.com/CloudFlare-Meetups/events/191252182/
38.
▲
by
grittygrease
13y ago
Thanks for the update. Happy revocation day!
39.
▲
by
grittygrease
13y ago
The CSR contains the public key for a unique private key. How do you have a new private key with an old CSR?
40.
▲
by
grittygrease
13y ago
This is completely the wrong approach. Your private key might have been compromised and you're generating another certificate for the same compromised private key? What is that supposed to do?
41.
▲
by
grittygrease
13y ago
If your site is protected by CloudFlare (like HN is), you are automatically protected from this vulnerability (see: http://blog.cloudflare.com/staying-ahead-of-openssl-vulnerab... ).
42.
▲
Serious OpenSSL vulnerability disclosed, CloudFlare sites safe
(blog.cloudflare.com)
2 points
by
grittygrease
13y ago
|
0 comments
43.
▲
ECDSA: The digital signature algorithm of a better internet
(blog.cloudflare.com)
10 points
by
grittygrease
13y ago
|
1 comments
44.
▲
by
grittygrease
13y ago
Not currently, but the system is open source and designed to be easily extensible.