Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ivanr
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
32 ms
·
301.
▲
by
ivanr
14y ago
My guess is it that, with this service, GlobalSign will create a sub-CA, but retain full control of it (i.e., own the key), issuing all the certificate themselves. Because of that they will be able to ensure that the customer owns all the h
302.
▲
by
ivanr
14y ago
I maintain a complete guide to SSL/TLS deployment: SSL/TLS Deployment Best Practices https://www.ssllabs.com/projects/best-practices/
303.
▲
by
ivanr
14y ago
Several things come to mind; let's take Convergence ( http://www.convergence.io ) as an example. First, the software (Convergence plugin and notary code) need to be stable. This is mainly the job for the project team, but they might need he
304.
▲
by
ivanr
14y ago
It should be available, but you should be prepared to educate your GP first. I did, providing him with research papers. It is also available privately, for example here http://www.76harleystreet.com/sections/news/winterVitD
305.
▲
by
ivanr
14y ago
For CRIME, I don't think that it's necessary to control the cookies. Having control of other parts of the request should be sufficient (e.g., using request headers, request body, etc). As for manipulating cookies from the MITM perspective,
306.
▲
by
ivanr
14y ago
It would be interesting to know if there were any changes in the SPDY implementation. It too supports compression before encryption and may be affected by the same problem.
307.
▲
by
ivanr
14y ago
In my quick test, about 42% of the sites in the SSL Pulse data set (~180k SSL sites in Alexa's top 1m) support compression. For example, mail.yahoo.com does.
308.
▲
by
ivanr
14y ago
To expand on your second point, if you have 3, then in many cases you also have the ability to intercept and modify non-encrypted traffic. Meaning, if the victim is using a secure web site and a non-secure site at the same time, the MITM ca
309.
▲
by
ivanr
14y ago
Using SSL properly is not particularly difficult in theory, but there are many moving pieces so that the whole thing ends up being hard. For example, it's often easy to forget a crucial step. To address this, I wrote SSL/TLS Deployment Best
310.
▲
SSL/TLS Deployment Best Practices
(ssllabs.com)
6 points
by
ivanr
14y ago
|
0 comments
311.
▲
by
ivanr
14y ago
There's a blog post from Fred Wilson that I've found to be most insightful: http://www.avc.com/a_vc/2010/08/what-a-ceo-does.html The main point is this: "A CEO does only three things. Sets the overall vision and strategy of the company an
312.
▲
by
ivanr
14y ago
I am not convinced the current spec addresses that particular attack well. The second visit could happen while the victim is still in the coffee shop. Perhaps a 24 hour delay on the pin activation would be more appropriate. On the other end
313.
▲
by
ivanr
14y ago
TACK is not competing with Chrome, but with the Public Key Pinning Extension, currently in draft (see http://tools.ietf.org/html/draft-ietf-websec-key-pinning-01 ). As the name says, they too are proposing to pin public keys, not certifica
314.
▲
by
ivanr
15y ago
[Note: I am the author of the tool.] Yes, it's somewhat restricted without SNI support. I wrote the tool back in 2009 when having SNI was not very useful (because there was virtually no support for it). Sadly, the situation has not improved
315.
▲
by
ivanr
15y ago
Server Name Indication was added in Java 7, so I would expect that Netty supports it too, assuming you're running the latest version of the Java runtime.
316.
▲
by
ivanr
15y ago
You are correct in pointing out that a license is required no matter what device is used to watch or record broadcasts. However, just owning such a device does not mean that you have to automatically pay. If you use your TV only to watch DV
317.
▲
by
ivanr
15y ago
In the response, thank the user for initiating registration and send her an email with a link (and a token) to continue with the process. Of course, the downside is that you're slowing the user down. It's acceptable for the sites that choos
318.
▲
by
ivanr
16y ago
I wrote my first book for a traditional publisher. Later, with my second book, I decided to effectively self-publish, for two reasons: 1) the money is better and 2) I wanted to be able to update my books whenever I had something to say. My