Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ivanr
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
18 ms
·
151.
▲
by
ivanr
10y ago
No, it is not; locally-installed CAs (roots) bypass HPKP.
152.
▲
by
ivanr
10y ago
For what it's worth, my impression is that CAA will be mandated by the CA/Browser forum at some point. But, indeed, that's the main weakness of CAA—it requires that substantially all CAs support it.
153.
▲
by
ivanr
10y ago
Maybe, but there's no memory effect associated with CAA and you can change your configuration it any time. You're not actually locked in.
154.
▲
by
ivanr
10y ago
Well, there's an idea: require a special certificate (via an extension) to enable pinning.
155.
▲
by
ivanr
10y ago
I think high profile sites are better served by static pinning, which seems simpler to maintain and also comes with the benefit of preloading. Thus, if you have those sites at one end, and lots of small/no-large-risk sites who don'
156.
▲
by
ivanr
10y ago
No, when HPKP breaks your site no longer works, period. The error page doesn't allow clicking through. Some browsers (e.g., Chrome) support manual editing of the HPKP configuration so some users might be able to get around the problem,
157.
▲
by
ivanr
10y ago
Just to clarify: in my article I discuss mostly HPKP as defined in RFC 7469. I think static pinning works great (and also has the benefit of being preloaded). Mobile and other types of pinning where you control both sides of a conversation
158.
▲
by
ivanr
10y ago
You tested Netscape Navigator 2.01 and SSLv3 isn't supported in it? I'll check myself; in the meantime, I removed that sentence from the timeline. Thanks!
159.
▲
by
ivanr
10y ago
I suppose it's a question of balance; I am trying to include all that's relevant while at the same time keeping the list reasonably small. If I add too many items, the main ones will be lost in the noise. (I have an idea of how I
160.
▲
SSL/TLS and PKI Timeline: Detailed History of Events
(feistyduck.com)
4 points
by
ivanr
10y ago
|
0 comments
161.
▲
by
ivanr
10y ago
That's absolutely correct; the goal should be to get an A+. (SSL Labs author.)
162.
▲
by
ivanr
10y ago
You're right, sorry! I've added a couple of links now. I spent a lot of time thinking about what I was going to write that I forgot to think about anything else :)
163.
▲
by
ivanr
10y ago
It might still be, but the per-category scores are no longer shown. (You can infer the values from the chart.) There's also a per-report score that is not shown any more either. That's because those scores are not really important
164.
▲
by
ivanr
10y ago
Having been on the inside, everyone at Qualys simply loved SSL Labs in the same way everyone else did. There's never been an agenda for it, only "it's good for security so we'll keep supporting it". There's a f
165.
▲
by
ivanr
10y ago
Thanks! (No, 4096-bit RSA has never been required for A+.)
166.
▲
by
ivanr
11y ago
Indeed, a simple search for "passive ssl fingerprinting" would have given them a few leads, including my blog posts from 2009. It's not something anyone can claim to be novel in 2016. To their credit, they focus on traffic pa
167.
▲
by
ivanr
11y ago
Try clearing your recent browsing history, cookies, and such. The link wasn't working for me either, but it started working after I had cleared everything.
168.
▲
by
ivanr
11y ago
FYI, Amazon recently purchased a widely distributed CA root: https://www.awstrust.com/repository/
169.
▲
by
ivanr
11y ago
I quite like the idea of TinyCert and often wanted to do something similar myself. Although creating a private CA is not a lot of work initially, maintaining it is a hassle, especially when you'd rather be doing something else. TinyCer
170.
▲
by
ivanr
11y ago
It doesn't affect security, they're already in browsers' trust stores. It does affect availability, but only because (the last time I checked) WoSign's OCSP responders operated from China only. To address network latency
171.
▲
How Bulletproof SSL and TLS is a living book
(blog.ivanristic.com)
4 points
by
ivanr
11y ago
|
0 comments
172.
▲
by
ivanr
11y ago
In my opinion, the high-school grading system is one of the best features of SSL Labs. Most people don't have the time or interest to read the RFCs and follow the issues closely. The grading system help them easily understand what is i
173.
▲
by
ivanr
11y ago
Would being able to specify a HTTP (CONNECT) proxy to SSL Labs be useful to you for the testing of your internal hosts?
174.
▲
by
ivanr
11y ago
I am not completely against de-facto standards, but, in the TLS space, Chacha20/Poly1305 is not one. At this time it's mostly used only by Google/Chrome (AFAIK, no other clients support it); we'd need to see better brows
175.
▲
by
ivanr
11y ago
(Author of SSL Labs here.) From Chrome's perspective, it's easy to complain about obsolete cryptography because it takes only its connections into account. When you take a wider view and include other browsers, all sites today eff
176.
▲
by
ivanr
11y ago
For completeness, also be aware that it's possible to get (yellow and red) warnings in Chrome even if you're serving a full SHA2 certificate chain and have the best possible configuration otherwise. Apparently, this is because Ch
177.
▲
by
ivanr
12y ago
If Amazon has any secure cookies, they're not going to affect this particular attack. The traffic leg between the attacker and Amazon's servers can be encrypted, which means that she will receive the secure cookies. Because the le
178.
▲
by
ivanr
12y ago
Once the attacker hijacks the plaintext HTTP connection, she can pretty much do whatever she wants with the user. Of course, that's provided we're talking about a casual user, who isn't going to pay much attention to the HTTP
179.
▲
by
ivanr
12y ago
Indeed. Hopefully browser vendors will consider this certificate for explicit blacklisting using their proprietary channels. (I've already asked.)
180.
▲
by
ivanr
12y ago
No. Certificate Transparency [1] might eventually make it possible, but it's still early days. A much wider adoption is needed. [1] http://www.certificate-transparency.org/
More ›