Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ivanr
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
20 ms
·
181.
▲
by
ivanr
12y ago
If you're going to change your messages after posting them, at least disclose that you did so. Some of the replies don't make sense with the new content you added.
182.
▲
by
ivanr
12y ago
I don't think it's that easy. My book on Amazon currently has one 5-star review that's just one word and two 5-star reviews with two words each. I am the author and the publisher, and I know for a fact that these reviews are
183.
▲
by
ivanr
12y ago
There is. MyBatis, which is a minimal ORM that aims to keep you as close to SQL as possible, has support for dynamic SQL: https://mybatis.github.io/mybatis-3/dynamic-sql.html Edit [responding to moe, below]: that'
184.
▲
by
ivanr
12y ago
I think the most important lesson from the last couple of years is that all our security protocols must come with adversarial testing suites -- from inception. Clearly, there's a long way between designing a secure protocol (I am not s
185.
▲
by
ivanr
12y ago
You can get it directly from me (Feisty Duck is my small publishing business) here: https://www.feistyduck.com/books/bulletproof-ssl-and-tls/ This is the best option, because you get all digital formats (PDF, EPUB
186.
▲
State Machine Attacks against TLS
(smacktls.com)
19 points
by
ivanr
12y ago
|
0 comments
187.
▲
by
ivanr
12y ago
Well, actually you can, but only as part of Bulletproof SSL and TLS. OpenSSL Cookbook is Bulletproof chapters 11 and 12, plus SSL/TLS Deployment Best Practices (another guide I wrote) in the appendix. Or, you can simply print it yourse
188.
▲
Attack of the week: FREAK (or 'factoring the NSA for fun and profit')
(blog.cryptographyengineering.com)
197 points
by
ivanr
12y ago
|
41 comments
189.
▲
Show HN: OpenSSL Cookbook 2nd Edition
(feistyduck.com)
57 points
by
ivanr
12y ago
|
6 comments
190.
▲
by
ivanr
12y ago
Just as an aside: the SSL Labs test is slow on purpose -- that's how we stay under the radar and avoid too many complaints from server operators. That said, it's a common complaint and I intend to optimize some operations in the n
191.
▲
by
ivanr
12y ago
My book, Bulletproof SSL and TLS, is available at 50% with the coupon BLACKFRIDAY: https://www.feistyduck.com/books/bulletproof-ssl-and-tls/bla... Please note that the discount on the bundle (paperback and digital
192.
▲
Uphold the VAT Exemption Threshold for businesses supplying digital products
(change.org)
9 points
by
ivanr
12y ago
|
1 comments
193.
▲
Book Review: Bulletproof SSL and TLS
(virusbtn.com)
1 points
by
ivanr
12y ago
|
0 comments
194.
▲
AWS Key Management Service
(aws.amazon.com)
4 points
by
ivanr
12y ago
|
0 comments
195.
▲
by
ivanr
12y ago
I built a similar single-source publishing workflow to publish my books, but it's based around DocBook. I am very happy with DocBook because it has all the features I need for technical publishing (styling, indexing, cross-references,
196.
▲
by
ivanr
12y ago
Sadly, I've come to the conclusion that it's no longer possible to build future-proof cipher suite configuration in a generic way. There are simply too many rules to follow, if you want to get everything right. I spent lots of tim
197.
▲
by
ivanr
12y ago
I would recommend that you reduce the DH parameter strength to 2048 bits. You're not noticing it now because most clients end up using ECDHE, but 4096-bit DH parameters are _very_ slow and yet don't provide any meaningful increase
198.
▲
by
ivanr
12y ago
And here's a similar patent from Akamai (via @cloudpundit) http://www.google.com/patents/US20130156189
199.
▲
by
ivanr
12y ago
Do you use per-site session ticket keys?
200.
▲
by
ivanr
12y ago
This blog post http://blog.ivanristic.com/2014/09/sha1-deprecation-what-you... gives some background for this change and discusses dual-certificate deployment as a way to remain warning-free in Chrome and continue
201.
▲
SSL Labs 1.10.31, with SHA1 warnings, is now live
(ssllabs.com)
2 points
by
ivanr
12y ago
|
1 comments
202.
▲
by
ivanr
12y ago
I haven't tried, but I think at the moment Apache supports only multiple certificates with different private key algorithms. Anything else would have to be implemented in custom code. IIRC, OpenSSL 1.0.2 (not yet released) has better s
203.
▲
by
ivanr
12y ago
Actually, Apache already supports deployments with more than one certificate for the same host: http://httpd.apache.org/docs/2.4/mod/mod_ssl.html#sslcertifi...
204.
▲
by
ivanr
12y ago
Not responding directly to your point (that this might make the Internet less secure), but there is also another approach -- deploying with two certificates. You can have a RSA/SHA1 certificate for older software and an ECDSA/SHA2
205.
▲
by
ivanr
12y ago
It also says "[...] which include a SHA-1-based signature as part of the certificate chain". In other words, SHA1 is deprecated in the entire chain (minus the root, where the signature is irrelevant).
206.
▲
by
ivanr
12y ago
Do you review your own changes, or someone else's? Asking because the former is unusual, but the latter works much better with OxygenXML's built-in change tracking. It's fantastic for working with editors (in combination with
207.
▲
by
ivanr
12y ago
By the way, this blog post does not mention that Microsoft already effectively killed SHA1 last year when it announced that it wouldn't accept SHA1 certificates after 2016: http://blogs.technet.com/b/pki/archi
208.
▲
Gradually sunsetting SHA-1
(googleonlinesecurity.blogspot.com)
146 points
by
ivanr
12y ago
|
98 comments
209.
▲
by
ivanr
12y ago
Out of curiosity, why not write DocBook directly using a WYSIWYM editor -- for example OxygenXML? Edit: I don't think it's worth using for blog posts and such, but for anything that you plan to publish -- papers and books -- it wo
210.
▲
by
ivanr
12y ago
You might want to add "Connection: close" to the request. Otherwise the server won't close the connection immediately, but only after a keep-alive timeout. In the meantime, your program will be waiting to read on the socket.
More ›