Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ivanr
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
ivanr
2y ago
If you're struggling to the extent that you're questioning your sanity, you're trying to do too much. There's a limit to what a single person can do. If you want to stay a one-person company and keep your sanity, do less
32.
▲
by
ivanr
3y ago
Yes, that's very radical. How will the person who asked the top question know that they're supposed to validate their ideas before they build, for example? And how do you validate your ideas? And how do you figure out what to buil
33.
▲
by
ivanr
3y ago
April Dunford has two great books. Positioning comes first, then sales. As a small outfit, you probably don't want to actually sell. The approach that worked for me was to focus on inbound marketing and let customers self-select and co
34.
▲
by
ivanr
3y ago
There is also the third option, when you start off as a partner of a larger business, and it goes well, and they eventually decide that they want to buy you.
35.
▲
by
ivanr
3y ago
It's one of those things... what works for you may not work for other people. For someone who's made-up differently, the right chair can make all the difference in the world. I do what you do (and more) _and_ I have the best chair
36.
▲
by
ivanr
3y ago
> Founded and sold this venture and had a great time doing it. It was a 24/7 on-screen AI therapist/companion for people with extreme anxiety/mental issues. After selling it, I made it public for free to help as many peopl
37.
▲
by
ivanr
3y ago
Here's another one: - Show response status. For example, when you lookup a non-existent domain, you say "No records returned", but that's not accurate. You should show NXDOMAIN so that it's clear the domain doesn&#x
38.
▲
by
ivanr
3y ago
Looks very nice and clean visually. I have some suggestions from a lookup or two: - Add support for SVCB and HTTPS records - When you lookup CAA, you return flags as a string. It should be an integer. - JSON is nice as an option, but I woul
39.
▲
by
ivanr
3y ago
I liked Founding Sales a lot, and, re-reading one chapter today, I still do. In what way do you see it as outdated?
40.
▲
by
ivanr
3y ago
I am not sure this is a 100% match for what you're looking for, but my OpenSSL Cookbook (free) has a chapter where you go through all the necessary steps to generate a root CA, intermediates, server and client certificates. You'll
41.
▲
by
ivanr
3y ago
You may also want to look at https://github.com/digicert/pkilint There are other similar tools (cablint, x509lint, zlint), but there's been a lot of good talk about pkilint recently.
42.
▲
by
ivanr
3y ago
Indeed, you're right. Must-staple and short-lived certificates have the same problem with clock skew.
43.
▲
by
ivanr
3y ago
I think you're right about CRLSets. IMO, Mozilla really wanted to solve the problem, whereas Chrome just wanted to have a solution that they could use for emergency revocation of certificates of high-profile sites (and intermediates&#x
44.
▲
by
ivanr
3y ago
Yes, agreed on the primary problem with "classic" OCSP. OCSP stapling and must-staple (for the benefit of other readers: a flag that's set on a certificate to indicate that it's only valid with an attached—stapled—fresh
45.
▲
by
ivanr
3y ago
I am sorry, I can't watch someone else's talk to understand what you mean. If you're willing to engage in a conversation, could you say here what you think the problems with OCSP are? (If you're not, just ignore me.) As
46.
▲
by
ivanr
3y ago
For reference: https://github.com/chromium/chromium/tree/main/net/data/ssl It's been a long time since I looked at them, not sure what's in there exactly any more. Ask Ryan perhaps :)
47.
▲
by
ivanr
3y ago
That's a fair point [PKI without TLS], but I'd argue that 99.9% of situations will be with TLS. Thus supporting revocation can provide value for those. Out of curiosity, what without-TLS use cases do you have in mind?
48.
▲
by
ivanr
3y ago
Agreed. I don't see NIST's test suites [1] on the list, though. Maybe they're embedded somewhere and I've missed it? [1] https://csrc.nist.gov/projects/pki-testing EDIT If the authors are reading, a
49.
▲
by
ivanr
3y ago
Sure, but then you can just use OCSP. If you care about privacy very much, support only stapled OCSP. CRL is better suited for "high-volume" exchanges, for example for a CA to publish all their revocations [so that a system such a
50.
▲
by
ivanr
3y ago
Not quite. OCSP responses can be stapled to TLS handshakes to provide fresh revocation information. Online is needed if you want 100% fresh information, of course.
51.
▲
by
ivanr
3y ago
Genuine question: does the `webpki` crate provide a good path building implementation?
52.
▲
by
ivanr
3y ago
Well, yes. If you choose to ignore revocation entirely, you will never have a dead path because of it. That will happen only if you path-build, then check revocation as two steps. (IIRC, Windows used to do this, or is still doing it.) IMO,
53.
▲
by
ivanr
3y ago
Any chance you could expand on "In practice, they're both operationally complicated and an unreliable source of truth about certificate validity."?
54.
▲
by
ivanr
3y ago
There is also the third option, via must-staple, where OCSP responses are attached to the TLS handshake. This resolves the privacy issue [because otherwise clients have to talk directly to CAs and reveal what sites they're visiting]. A
55.
▲
by
ivanr
3y ago
Exactly. Because you currently don't check for revocation, you may end up selecting a path that's a dead end and you won't be able to recover. However, if your implementation has pluggable [dynamic] constraints, once you add
56.
▲
by
ivanr
3y ago
Do you think that it's possible to implement a good path building algorithm without support for revocation? For example, without revocation checking you may select a chain with a revoked certificate in it, only to discover that later.
57.
▲
by
ivanr
3y ago
You're right. I answered in the context of technical books, where you do tend to get a free ebook if you buy the paperback directly from the publisher. Since that response, I checked a few of the other publishers and it's correct.
58.
▲
by
ivanr
3y ago
Yes, it's essentially Amazon. But what can we (or anyone) do about it? Not sure what the situation is today but, early on, we had to give up 70% of the list price if we wanted Amazon to sell our digital books. It's just mind-boggl
59.
▲
by
ivanr
3y ago
As a book author and publisher, I don't mind if you do. I would give you the ebook for free if I could [cost-effectively].
60.
▲
by
ivanr
3y ago
I am not convinced that it's greed. See my longer reply https://news.ycombinator.com/item?id=38882694 . We tried our best and wasted a lot of effort in an attempt to do what's right, and still failed in the end. I
More ›