Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ivanr
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
91.
▲
by
ivanr
5y ago
When multiple CSRs [and thus multiple private keys] are involved you end up with multiple wildcard certificates. There is no sharing, technically speaking, but obviously the hostnames in all the wildcards are the same. However, that doesn&#
92.
▲
by
ivanr
5y ago
> By the way, EasyRSA still isn't that easy, but it's better than using OpenSSL directly. The trouble with EasyRSA (and similar tools) is that they make decisions for you and restrict what's possible and how. For example,
93.
▲
by
ivanr
5y ago
There are some nuances to Certificate Transparency (CT) that are worth highlighting: - Technically, certificates are not required to be recorded in CT logs. If not submitted, they're still perfectly valid, but they won't be accept
94.
▲
by
ivanr
5y ago
Small suggestion: If Gazette is ready for a wider adoption, it may be useful to bump it up to 1.0 as a signal of confidence.
95.
▲
by
ivanr
5y ago
You mention web security in the title and that normally means web application security, but the body of your question talks about network security. Which of the two do you care about more? There won't be a book that covers both. For ne
96.
▲
by
ivanr
5y ago
Yeah, I realise I could do that. But I'd prefer to just play the game and reward the author financially for the convenience.
97.
▲
by
ivanr
5y ago
I'd love to play it, but it seems to be Windows only. Any plans to support other platforms, for example macOS? FWIW, I'd probably prefer to play it on iOS if the controls are decent.
98.
▲
by
ivanr
5y ago
Indeed, it's a misuse of TLS session IDs for pervasive surveillance. The early web application firewalls also used TLS session IDs to better understand clients, for example correlating the observed values with HTTP session identifiers.
99.
▲
by
ivanr
5y ago
What you're describing can be achieved by misusing TLS session IDs, but the technique doesn't work reliably and it's not secure. In essence, when client and server handshake, a unique session ID is generated. The server can a
100.
▲
by
ivanr
6y ago
Here you go: https://news.ycombinator.com/item?id=24142626
101.
▲
by
ivanr
6y ago
I would love to be able to send an email tomorrow. I like to respond to some emails to get them out of the way, but the more email I send, the more I get. I would therefore love to be able to slow down the exchanges. Gmail has only a limite
102.
▲
by
ivanr
6y ago
Try these as a starting point: - Think Java (programming, foundational; free) https://greenteapress.com/wp/think-java/ - Think Data Structures (programming, foundational; free) https://greenteapress.com
103.
▲
by
ivanr
6y ago
One of the AddTrust root certificates has just expired. This is the certificate: https://crt.sh/?id=1 This certificate was originally deployed some 20 years ago and expired today. There will be servers out there configured
104.
▲
by
ivanr
8y ago
That's great to hear, thanks! Is there a page in the docs where this is documented? I'd also like to know if there are any restrictions (e.g., are all outbound ports open, etc)? If you could comment on when/whether compute in
105.
▲
by
ivanr
8y ago
Sorry, my question was about outbound IPv6. At the backend, we need full IPv4 and IPv6 network connectivity to the outside world. (I haven't tried Cloud Run, but I read through the docs and there are no indications [that I could find]
106.
▲
by
ivanr
8y ago
Can you provide some information about when you might be adding support for IPv6? It's a deal-breaker for our particular use cases.
107.
▲
by
ivanr
8y ago
Depending on what type of SaaS you're building exactly, you may find the Enterprise Ready web site quite useful: https://www.enterpriseready.io From their homepage: 'Created for people who build SaaS products (founders
108.
▲
Introducing MTA Strict Transport Security (MTA-STS)
(hardenize.com)
2 points
by
ivanr
8y ago
|
0 comments
109.
▲
by
ivanr
8y ago
Additionally, MTA-STS has recently been approved as Proposed Standard, so we may see increased support for it in the near future. [1] The key advantage of MTA-STS is that it can be deployed quickly, without almost any disruption of the alre
110.
▲
by
ivanr
8y ago
I came here to add an important detail about WAFs that's missing in this thread. For context, I am the original author of ModSecurity (but haven't worked on it since at least 2009). I wrote ModSecurity for three use cases that sti
111.
▲
by
ivanr
8y ago
I would appreciate if you could list some of those differences and tradeoffs, for some of us who are interested in Citus but haven't yet had time to look at it in more detail. Thanks!
112.
▲
by
ivanr
9y ago
To add to this, there's potentially a similar security problem if you have a bunch of systems with different certificates sharing the same TLS session caching backend or session ticket keys. It doesn't allow any one system to impe
113.
▲
by
ivanr
9y ago
If you continue to use the same public key, your existing pin will work with your new certificate. So there's nothing to do. IIRC, many (all?) LE clients generate new keys by default, so this is something you need to plan for in advanc
114.
▲
by
ivanr
9y ago
Yes, you're right. IIRC, that approach was considered and rejected in the design phase. Some other pinning proposals (e.g. http://tack.io ) rely on delayed activation to reduce the damage potential.
115.
▲
by
ivanr
9y ago
HPKP, in its current shape, is difficult to justify even to larger companies. Presumably, those companies who do consider it determined that there is a non-significant risk that they would be attacked via fraudulent (but of course valid) ce
116.
▲
by
ivanr
9y ago
No, you're wrong. There are no guarantees that you'd be able to get a fresh certificate from the same intermediate certificate. CAs rotate the intermediates all the time, for various reasons. Of course, CAs can choose to make such
117.
▲
by
ivanr
9y ago
It's a tricky question, and I've spent years of my life trying to answer it. Hey, I am a security person and a developer and I don't always trust myself to do the right thing. No matter how much time I spend educating myself,
118.
▲
Monitoring deprecated Symantec certificates
(hardenize.com)
1 points
by
ivanr
9y ago
|
0 comments
119.
▲
by
ivanr
9y ago
For a comprehensive check-up of network and security configuration, take a look at Hardenize https://www.hardenize.com . It covers a variety of things such as DNS/DNSSEC/DANE and CAA, email security (e.g., SPF, DMARC),
120.
▲
by
ivanr
9y ago
I've already explained in one of my earlier posts in this very thread: In my opinion, it was dishonest to advertise certificates as "100% free" when they charged for revocation. Just because the revocation charges were docume
More ›