Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ivanr
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
61.
▲
by
ivanr
3y ago
You'll find that, often, if not always, if you buy directly from a publisher, the ebook will be free with the paperback purchase. (Manning is one example, not sure about others off hand.) However, if someone is buying your book from Am
62.
▲
by
ivanr
3y ago
I've been buying lots of cryptography books lately as I wanted to learn about the evolution of our understanding of this topic. How about some of the following: - "Real-World Cryptography" is my recommendation for the first b
63.
▲
by
ivanr
4y ago
That’s so depressing.
64.
▲
by
ivanr
4y ago
Do you know what's behind the performance degradation of OpenSSL 3.0? Has the problem been documented anywhere?
65.
▲
by
ivanr
4y ago
Take a look instead at the DNS SVCB and HTTPS resource records, which have already been adopted in practice: - Service binding and parameter specification via the DNS (DNS SVCB and HTTPS RRs) https://datatracker.ietf.org/doc
66.
▲
by
ivanr
4y ago
CAs don't have to report their certificates to CT logs, and actually there is no reporting in a variety of use cases. However, modern browsers no longer trust certificates for which there is no (cryptographic) evidence of logging to CT
67.
▲
by
ivanr
4y ago
Would you mind sharing the details of the consultant? My email is "ivan.ristic" at gmail. Much appreciated.
68.
▲
by
ivanr
4y ago
We haven't yet gone through any audits [we're small/young], but we've began to prepare for SOC2. The policy itself is absolutely insufficient for anything of the sort and we expect that we will generate a ton of further
69.
▲
by
ivanr
4y ago
The struggle between security and usability is very real. Personally, I don't think that it's possible to lock dev equipment whilst not significantly impacting productivity. That said, ensuring that high-value environments (e.g.,
70.
▲
by
ivanr
4y ago
When I needed a security policy for my startup, I looked everywhere and couldn't find anything that made sense. I only found policies that are very, very, verbose, so much that I didn't know what to do with them. And most often ou
71.
▲
by
ivanr
4y ago
I imagine that's the limit per client IP address [for a single server port], no? The Linux kernel can use multiple pieces of information to track connections: client IP address, client port, server IP address, server port. Cloudflare h
72.
▲
by
ivanr
4y ago
Hardenize's paid plan is intended for larger businesses, where we combine infrastructure discovery with continuous monitoring and many other things. However, ad-hoc assessments are free for everyone and we intend to keep it that way. I
73.
▲
by
ivanr
4y ago
SSLPing was a tool that was designed to test SSL/TLS/PKI server configuration. According to the author's message, it was built on top of OpenSSL. There have been significant changes made to OpenSSL since 2016, many focused on
74.
▲
by
ivanr
5y ago
Here's a very good guide from GOV UK: https://www.gov.uk/guidance/keeping-your-domain-name-secure It's written for domains under gov.uk, but, ignoring that, the rest is universal and thorough.
75.
▲
by
ivanr
5y ago
DocBook has served me very well. For my books I put together an automated publishing workflow that starts with DocBook and produces output for both print and digital (in my case, PDF, EPUB, and HTML). For context, I wrote and published two
76.
▲
by
ivanr
5y ago
Personally I'd go with a third-party service that will manage the PKI side of things, possibly two. That would relieve you of a big burden, leaving you to only invoke their APIs as needed. Most big CAs have specific IoT products. On th
77.
▲
by
ivanr
5y ago
If you don't want to do mutual authentication then may not need to do anything special. In theory, your servers can get a regular certificate from a public CA. You would get better security with a private CA, ensuring that your devices
78.
▲
by
ivanr
5y ago
There isn't a section in the book that covers IoT specifically. Most of the book is relevant to the topic because it provides a generic foundation that's necessary for more specific use cases. I feel that in many situations the so
79.
▲
by
ivanr
5y ago
That, too, would be most welcome :)
80.
▲
by
ivanr
5y ago
I think TLS 4 would have been a good choice, given the massive changes made to the protocol. Fun fact: internally, the protocol version still follows the original SSL numbering scheme. TLS 1.3 is actually SSL 3.4 :)
81.
▲
by
ivanr
5y ago
Agreed. Many modern systems need only TLS 1.3 and nothing older. Unfortunately, TLS 1.3 is saddled with the baggage of backward compatibility. This is not something you might care if you're deploying it, but if you're studying how
82.
▲
by
ivanr
5y ago
Well, ECH (Encrypted ClientHello) got... complicated and it's still in development. For context: one of the long-standing problems with TLS was and still is the fact that it leaks a lot of metadata. You could say that it's a chick
83.
▲
by
ivanr
5y ago
Do you mean the text in the "What's In The Book" section? I adapted that bit from the preface and it was actually written late last year. I'll look into rewording it to read better. Thanks!
84.
▲
by
ivanr
5y ago
I spent a lot of time thinking about that, but, in the end, I don't think anyone could justify the words "bulletproof" and "ssl" next to each other. So that was that. The "SSL" part was in the title chiefl
85.
▲
by
ivanr
5y ago
While we're here, please feel free to ask me anything, either about SSL/TLS and PKI or about the publishing process. I'll be around to answer your questions. Thanks.
86.
▲
Show HN: My Book Bulletproof TLS and PKI (Second Edition) Is Out
(feistyduck.com)
134 points
by
ivanr
5y ago
|
34 comments
87.
▲
by
ivanr
5y ago
Are your AAAA records misconfigured? $ dig +short antonok.com aaaa @phoenix.ns.cloudflare.com fe80::216:3eff:fea9:4e8f
88.
▲
by
ivanr
5y ago
My first question would be: do you really want to self-host? Google have a service that's affordable: https://cloud.google.com/certificate-authority-service AWS has a similar service but, the last time I checked, it wa
89.
▲
by
ivanr
5y ago
There's already a system in place to record most public certificates in a way that facilitates monitoring and auditing. It's called Certificate Transparency (CT); you'll find more about it at https://certificate.tr
90.
▲
by
ivanr
5y ago
Postmark have a free service: https://dmarc.postmarkapp.com It's simple, but works well for what it is. They added a separate commercial service fairly recently.
More ›