Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ivanr
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
37 ms
·
271.
▲
by
ivanr
13y ago
That's correct: control over the first few bytes (the size of the encryption block) is needed. In addition, in practice you will also need a Same-Origin Policy bypass in order to submit requests to the target web site. Surprisingly, th
272.
▲
by
ivanr
13y ago
sillysaurus2 is talking about the Flame malware, which used a previously unknown MD5 collision attack technique: http://blog.cryptographyengineering.com/2012/06/flame-certif... Why are you finding it unsettling? I
273.
▲
by
ivanr
13y ago
All Java installations support only up to 128-bit AES by default. Oracle calls that "strong encryption". You can upgrade to "unlimited strength" by changing some policy files, after which 256-bit AES will be possible. I
274.
▲
by
ivanr
13y ago
Yes, I agree. To get an A these days, a site should at the very least support TLS 1.2, and use a key stronger than 1024 bits. That's where we're heading. P.S. If you have SSL 2 enabled, you'll get an F.
275.
▲
by
ivanr
13y ago
First of all, I think it's perfectly reasonable to not get an A if your security is not perfect. Thus, BEAST does not carry "so much weight". For a lot of weight, look at SSL 2 or insecure renegotiation -- if you have those e
276.
▲
by
ivanr
13y ago
I think one of the biggest pitfalls of SSL/TLS (and many other security technologies available now) is that they are so configurable and flexible. The approach assumes everyone has the knowledge and the time to invest to tune everythin
277.
▲
by
ivanr
13y ago
In general, I don't think the protocol specifications call for some suites to be allowed with certain protocol and some not to. (There are some exceptions, when weak suites need to be deprecated.) In practice, it comes down to how libr
278.
▲
by
ivanr
13y ago
Yes, there is: Zen Buddhism. In fact, zazen, the key practice of Zen, is most commonly practiced in front of a blank wall. Being present, being _really_ present, is Zen in its pure form.
279.
▲
by
ivanr
13y ago
It's really impossible to give you a concise answer, because there are many details to take care of. My advice is to download the SSL/TLS Deployment Best Practices guide: https://www.ssllabs.com/projects/
280.
▲
by
ivanr
13y ago
[I wrote that document.] With wildcard certificates, the main danger is that multiple groups with the organization will have access to the same private keys. The larger the group the worse the security gets: the chances of the private key l
281.
▲
by
ivanr
13y ago
Yes, it's possible. OpenSSL does not allow for per-protocol tuning, but there are some tricks you can use to achieve the same effect. In particular, GCM suites and SHA256/SHA384 suites work only in TLS 1.2, so if you put those fir
282.
▲
by
ivanr
13y ago
Both (BEAST and RC4) are proven to be real. The only question is which is worse, and if the attacks are practical. In my view, both are equally unlikely to be a threat for an average web site. I'd love to get rid of the BEAST penalty,
283.
▲
by
ivanr
13y ago
You are not going to get a failed connection if you only disable RC4. I suspect you've been too strict with the suites on your end.
284.
▲
by
ivanr
13y ago
It is actually possible to achieve 100%, but you have to run only TLS 1.2, IIRC. But that would also make your web site inaccessible to most users. But don't blame us, that's just the current situation with SSL/TLS. We'r
285.
▲
by
ivanr
13y ago
[SSL Labs author here.] At this point, the A rating is the minimum you should expect. But, to have a really good configuration, you really ought to also implement 1) HTTP String Transport Security, 2) Forward Secrecy, and 3) Public Key Pinn
286.
▲
by
ivanr
13y ago
That's right. Good stats on BEAST are difficult to come by, so we're running a passive handshake analyzer[1] on our site in order to determine what amount of our clients support the 1/n-1 split. The last time I looked, about
287.
▲
by
ivanr
14y ago
> Although old browsers don't support HSTS, they still respect the "secure" flag in cookies. So if an old browser ever requests an insecure resource, no cookies are sent with it, so the bad guys can MITM your connection all day long and
288.
▲
by
ivanr
14y ago
I wasn't arguing for redirecting to the home page, only to avoid redirecting (to the intended destination on port 443) automatically. If a user's browser ever sends a port 80 request, you've already lost (assuming the MITM is there). On you
289.
▲
by
ivanr
14y ago
You can check the logs even with a single web server instance, provided you keep separate access logs for ports 80 and 443. But people don't do that. Forcing the web site to break is also forcing the developers to realize there is a problem
290.
▲
by
ivanr
14y ago
By the way, you will probably want to apply [B] to that rewrite rule. In order for mod_rewrite to do its thing, it has to URL-decode the path, which means that you will get decoded data in the $1 capture. In some cases, the resulting URL (a
291.
▲
by
ivanr
14y ago
That's clearly true from the usability perspective. However, the problem is that bulk redirections like that make it very difficult to catch insecure resources. For example, let's suppose you have a secure page that's referencing some JavaS
292.
▲
by
ivanr
14y ago
Knowing what we know today, attacks against RC4 are not yet practical, and thus there is no reason to panic. But we must act now. Given the huge incentive for researchers to continue to break RC4, it's reasonable to expect that the attacks
293.
▲
by
ivanr
14y ago
No, there isn't a reason why a session cookie needs to remain constant forever. I think rotating the cookie on every request would be challenging (because, at any given time, there may be several requests active), but it's very easy to rota
294.
▲
by
ivanr
14y ago
[I am the author of SSL Labs.] Not all major browsers implement 1/n-1 record splitting. In particular, the last time I checked, Apple did not in Safari and the iOS devices. In that light, downgrading the grade to a B is a reasonable way to
295.
▲
by
ivanr
14y ago
The RFC may or not matter, but what does matter is doing the right thing. For example, if critical Name Constraints are not universally supported, does that make it right to use the non-critical ones? I don't think so. If Name Constraints a
296.
▲
by
ivanr
14y ago
Are they audited by GlobalSign, or by an independent third-party (i.e., same as all other CAs)?
297.
▲
by
ivanr
14y ago
Let me rephrase the question: if Name Constraints are used and the extension is marked as critical (as 5280 requires), do you know (or can estimate or guess) what percentage of public users will not trust the certificate?
298.
▲
by
ivanr
14y ago
Can you expand further on the practicality of the Name Constraints extension? My understanding is that not all browsers/libraries enforce them and IIRC, that certs that use them may not work in some browsers?
299.
▲
by
ivanr
14y ago
Sure. Once they verify one or more root domain names, the customer can have control over their domain space (subdomains). EDIT: The control is enforced by having the customer issue the certificates via a GlobalSign-owned portal. (Disclaimer
300.
▲
by
ivanr
14y ago
Strictly speaking, the mechanism is there (Name Constraints, see section 4.2.1.10 in the RFC 5280), but it's not practical due to it not being implemented consistently across all major browsers. EDIT: Changed RFC number from 2459 (obsolete)
More ›