Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ivanr
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
26 ms
·
241.
▲
by
ivanr
13y ago
Yes, they are problematic. Cipher suites are typically tied to a particular key algorithm. Microsoft does support the DHE key exchange, but only in combination with DSA keys (DSS in the cipher suite string). There are a couple of problems w
242.
▲
by
ivanr
13y ago
[I am the author of SSL Labs.] I agree with you that SSL Labs currently does not help non-experts very much; the test is still focused on presenting the details, but without guidance. The next version should be very explicit about what shou
243.
▲
by
ivanr
13y ago
For specific advice, here's my blog post with a proposed configuration that will work with any program that relies on OpenSSL: http://blog.ivanristic.com/2013/08/configuring-apache-nginx-and-openssl-for-f
244.
▲
MinimaLT: Encrypted network protocol as fast as TCP/IP
(ethos-os.org)
2 points
by
ivanr
13y ago
|
0 comments
245.
▲
Tcpcrypt: opportunistic encryption proposal for TCP (2011)
(tcpcrypt.org)
1 points
by
ivanr
13y ago
|
0 comments
246.
▲
by
ivanr
13y ago
It's all matter of risk assessment, which will depend on what your security requirements. Trust that they won't issue an interception certificate when a government agency asks them (with a warrant)? No. But, if you choose a well-e
247.
▲
by
ivanr
13y ago
Convergence is a great idea, but, sadly, the project appears to be dead. The last commit to the repo was 2 years ago, and (as far as I know) the Firefox plugin has been broken for a very long time. We (Qualys) are running several notaries a
248.
▲
by
ivanr
13y ago
No, not as far as I can tell. The linked document has two options for opportunistic encryption, one of which is without server authentication, but that does not mean without certificates. The draft http://tools.ietf.org/html
249.
▲
by
ivanr
13y ago
Great decision! When Google started to work on SPDY and made it SSL-only, we saw what the future could be: people upgrade to the new protocol for performance, but get better security too. What's not to like! I was really afraid that th
250.
▲
by
ivanr
13y ago
The performance aspect will definitely be included in the next version. It's a valuable lesson (in human behaviour) I learned from the current version. People love getting higher and higher scores and, before, when the overall numerica
251.
▲
by
ivanr
13y ago
You are probably aware of the Rating Guide: https://www.ssllabs.com/projects/rating-guide/ but would like to see scoring hints within the test itself? The current scoring approach does not make that easy, w
252.
▲
by
ivanr
13y ago
What functionality are you missing?
253.
▲
OpenSSL Cookbook v1.1 (free ebook)
(feistyduck.com)
2 points
by
ivanr
13y ago
|
0 comments
254.
▲
by
ivanr
13y ago
Encrypted tokens might help against CSRF, but if I have your session ID, it's game over. The best you can do is restrict the user agent used with the session, but that's an obstacle that can be overcome. You might try to restrict
255.
▲
by
ivanr
13y ago
Performance issues (I'd say most are imagined, but there is definitely an increase in latency) and higher cost of deployment with SSL (essentially more expensive CDNs). Some sites that rely on 3rd party services might struggle to deplo
256.
▲
by
ivanr
13y ago
There are two ways in which HSTS is deployed. First, it is activated when the HSTS response header is sent by the site. Normally, the browser will remember the HSTS response for a period of time. Clearly, a correctly implemented private mod
257.
▲
by
ivanr
13y ago
That's interesting, but I don't think it raises the bar a lot. Private keys are still kept in process memory, from where they can be easily extracted by the attacker who can attach to the process. A great innovation would be to ha
258.
▲
by
ivanr
13y ago
Here you go: https://github.com/ioerror/duraconf I don't know how good it is because I have not looked.
259.
▲
by
ivanr
13y ago
You are wrong. Attacks against sites with self-signed certificates are trivial to execute (you just need to download the tools and learn how to run them) and can be fully automated. Obtaining fraudulent certificates is occasionally possible
260.
▲
by
ivanr
13y ago
Deploying SSL partially is very dangerous, because then you have to be _very_ careful that the session ID is not compromised. I'd go as far as to say that it's virtually impossible to do that securely (for the average web site, bu
261.
▲
by
ivanr
13y ago
What tacticus said: disable SSL 2. But there's nothing wrong with the web server. (Also, given that you're using IIS, it's unusual that TLS 1.1 and 1.2 are not enabled.)
262.
▲
by
ivanr
13y ago
The bigger problem with CentOS (Red Hat) is that they do not support Elliptic Curves, which are necessary for Forward Secrecy. If you're using Apache, you can compile your own from source, using static linking against OpenSSL. That way
263.
▲
by
ivanr
13y ago
Yes, try CheckTLS: http://www.checktls.com/ Although, ironically, their web site does not seem to use TLS properly, not enforcing encryption on login and using mixed content.
264.
▲
by
ivanr
13y ago
If you want that level of security, your only solution is to own all your servers and have very strong physical security. The problem is that most web sites cannot justify the expense. If you follow all the recommendations from the guide --
265.
▲
by
ivanr
13y ago
I understand your point, but I am trying very hard to keep the guide as short as possible. The problem is that, if you start to be inclusive, the size balloons. I've written hundreds of pages on this topic so far (for my forthcoming bo
266.
▲
by
ivanr
13y ago
It makes sense in the context of (my) blog post. I start by showing one configuration for those who wish to use RC4 to mitigate the BEAST attack (better suites are used for the clients that support TLS 1.2). In the subsequent section, for t
267.
▲
by
ivanr
13y ago
Thanks. We also have a step-by-step configuration guide called SSL/TLS Deployment Best Practices. I've just submitted it here: https://news.ycombinator.com/item?id=6447518 In the nutshell, it's a conti
268.
▲
SSL/TLS Deployment Best Practices v1.3
(ssllabs.com)
152 points
by
ivanr
13y ago
|
37 comments
269.
▲
by
ivanr
13y ago
FYI, in my research, about 10% of Alexa top 1 million sites support SSL. For the configuration of those 10%, see SSL Pulse https://www.trustworthyinternet.org/ssl-pulse/
270.
▲
by
ivanr
13y ago
You probably meant to say that they are the only CA Comodohacker admitted attacking and failing to obtain any fraudulent certificates. Given that there are over 100 CAs, it's likely that the same person/organisation attempted atta
More ›