Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ivanr
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
16 ms
·
121.
▲
by
ivanr
9y ago
Thanks for coming back some days later to answer my question!
122.
▲
by
ivanr
9y ago
Whether revocation works has nothing to with my point about StartCom, which is that they weren't honest about what was free and what wasn't. I know this because I was annoyed with it at the time and actively looked at how they pre
123.
▲
by
ivanr
9y ago
Actually, it's not necessarily a great thing. Issuing certificates cost money and has to be paid one way or another. Having one very dominant CA -- even if it's free -- is not healthy long term. We need competition in this space.
124.
▲
by
ivanr
9y ago
You're forgetting that they had a charge for revocation, which was also automated. Even after Heartbleed, they refused to revoke the potentially compromised certificates without being paid. They also advertised their certificates as 10
125.
▲
by
ivanr
9y ago
No. Quite the opposite, AWS automates certificate issuance for you. You'd have to automate the process yourself if you switched to LE. Of course, AWS only issues certificates when you're using their stuff. For everything else, use
126.
▲
by
ivanr
9y ago
For what it's worth, SSL Labs also has a command-line tool that enables you to scan in bulk https://github.com/ssllabs/ssllabs-scan However, although they don't trust WoSign and StartCom any more, it's p
127.
▲
by
ivanr
9y ago
That's a bit simplistic. For example, you at the very least want to have a "-servername" there to account for SNI-only hosts. You'll then need to worry about prefixed and non-prefixed hosts (e.g., www.example.com and exa
128.
▲
by
ivanr
9y ago
I don't think you're being fair toward Mozilla. They had a meeting with Symantec and reported on it; there were no details because Symantec is going to soon publish everything. They probably had the meeting only because Gerv was i
129.
▲
by
ivanr
9y ago
Are you asking because you have a large number of hosts and can't check them all manually? (Edit: Because the obvious answer is to use your browser or a tool such as SSL Labs or Hardenize to see who issued the certificate.) Out of curi
130.
▲
by
ivanr
9y ago
Perhaps you're right, but it would be useful if you mentioned those other choices here.
131.
▲
On the Usability of Deploying HTTPS [pdf]
(sba-research.org)
28 points
by
ivanr
9y ago
|
6 comments
132.
▲
by
ivanr
9y ago
Hey Evan. CORS is on my todo list for Hardenize and will be added. We've done some work already, but it's hidden for now until I am certain our assessments are correct. Happy to work with you if you're interested. You have my
133.
▲
by
ivanr
9y ago
That's generally a big problem with print-on-demand: they literally print one copy at a time, so you have to rely on the printer to do quality control well. Even if you're checking regularly (as we did in the early days), you can
134.
▲
by
ivanr
9y ago
Yes, they're print-on-demand books, printed by Lightning Source (the last time I checked). They're not cheap to print, at least not at the list price; I don't know what deal O'Reilly might have. However, they're vas
135.
▲
by
ivanr
9y ago
Interesting. How much do you charge per book sold (e.g., as a percentage of the list price)? Also, do you collect consumer taxes for the EU (and other countries that require them)?
136.
▲
by
ivanr
9y ago
Hey, thanks for creating it. It's fantastic!
137.
▲
by
ivanr
9y ago
Technically, a full handshake adds 2 RTTs, and it's only one RTT on a successful resumption. In practice, I think that most modern browsers currently use something called False Start, where they cheat and send some data early, so even
138.
▲
by
ivanr
9y ago
(1) Yes, that's the argument against the RSA key exchange. I can break into your server, bribe or blackmail your system administrators, or take you to court to get your private key. This last case happened to Lavabit, for example. Hand
139.
▲
by
ivanr
9y ago
Well, the default is that TLS traffic cannot be decrypted or interfered with without detection, so no eavesdropping. A proxy can relay traffic at the TCP layer, but it won't be able to see any of the information (except for the parts t
140.
▲
by
ivanr
9y ago
I think SSL Labs could be an option, but its penalty for configurations that don't support forward secrecy is not strong enough. That's my fault (sorry!), but I'll hopefully fix it soon. Ultimately, I think the only way to ki
141.
▲
by
ivanr
9y ago
No, the attacker can't sign anything using either client's or server's private keys. The process assumes these keys haven't been compromised. But, as a client, you do need to be able to reliably verify that the private k
142.
▲
by
ivanr
9y ago
In short, yes! But just to be 100% sure, I would encourage you to read the detailed table of contents (it's can be downloaded along the free first chapter from the book's homepage, in the right column: https://www.feist
143.
▲
by
ivanr
9y ago
Right. As you say, on most web sites the client is anonymous as far as TLS is concerned, and the server proves its right to respond to the requested hostname with a CA-backed certificate (and proof that it holds the private key that corresp
144.
▲
by
ivanr
9y ago
As others have already pointed out, this explanation focuses on the RSA key exchange, which has been deprecated. It's not recommended for use with the current line of protocols (TLS 1.2 and earlier) and it's been completely remove
145.
▲
by
ivanr
9y ago
My goal is to promote good engineering and security practices, and to make it easy to adopt them and deploy them correctly. I feel that's one area that doesn't get enough attention. At the same time, it's the only direction t
146.
▲
by
ivanr
9y ago
For some time now I've been working on a new project with the idea that you want to use a single testing tool that can give you comprehensive, coherent, and deep advice. It's early days and there's a lot to add still, but eve
147.
▲
by
ivanr
10y ago
Small correction: the CA industry doesn't self-regulate. Both browsers and CAs participate in the CA/Browser Forum and my (admittedly outsider) impression is that browsers almost always have the upper hand.
148.
▲
by
ivanr
10y ago
If your servers are all public, you can use the (also free) SSL Labs API: https://www.ssllabs.com/projects/ssllabs-apis/
149.
▲
by
ivanr
10y ago
Indeed, a couple of people have asked for that already. I will try to make that happen. Edit: The development site is already used for the testing of new versions before they are deployed to production, but with the new grading perhaps we c
150.
▲
by
ivanr
10y ago
I should have fixed that a long time ago and I apologise that I haven't yet. But I will! At the moment, sites with "too strong" security (e.g., 4096-bit RSA, 4096-bit DH, etc) are still rewarded for it, but they shouldn'
More ›