Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jaas
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
61.
▲
by
jaas
3y ago
As the person who negotiated the agreements between Let's Encrypt and Identrust I can tell you that they have provided valuable services, including but not limited to cross-signs. I would not describe it as rent seeking. We are sincere
62.
▲
by
jaas
3y ago
ISRG / Let's Encrypt | General Counsel | Half Time | Fully Remote If you’re an attorney looking for a flexible half-time position with great work/life balance and a mission that matters, this could be the job for you! Interne
63.
▲
by
jaas
3y ago
You can read more about multi-perspective validation here: https://www.cs.princeton.edu/~jrex/papers/multiva20.pdf
64.
▲
by
jaas
3y ago
Thanks in large part to our research partnership with the group at Princeton CITP, Let's Encrypt has deployed a system we call multi-perspective validation. We validate domain control from multiple network perspectives so that an attac
65.
▲
by
jaas
4y ago
There is a C API for anyone who wants to use Rustls from C: https://github.com/rustls/rustls-ffi/
66.
▲
by
jaas
4y ago
I edited the title to note that it is a TLS library. Apologies for any confusion!
67.
▲
Rustls TLS Library 0.21.0 Released with New Features
(memorysafety.org)
34 points
by
jaas
4y ago
|
7 comments
68.
▲
by
jaas
4y ago
Any CA can revoke a certificate they issued without the subscriber being involved, so subscribers aren't necessarily revoking their own certs. When that happens ARI is a more efficient automated mechanism by which to let people know th
69.
▲
by
jaas
4y ago
If Let's Encrypt needs to revoke the certificate prior to expiration (for compliance or any other reason) ARI can let a client know in advance of the revocation. The client can then renew early and avoid a disruption in service. Client
70.
▲
A Safer High Performance AV1 Decoder
(memorysafety.org)
2 points
by
jaas
4y ago
|
0 comments
71.
▲
Klint: Compile-Time Detection of Atomic Context Violations for Kernel Rust Code
(memorysafety.org)
1 points
by
jaas
4y ago
|
0 comments
72.
▲
by
jaas
4y ago
So they're 2-4 years away from a big announcement that they're becoming more efficient and maximizing shareholder value by not developing their own OS any more and instead they're "collaborating" with Google and shi
73.
▲
by
jaas
4y ago
The OS X platform code for Firefox is written in Objective-C++. It's not without issues, but overall it's a nice way to use Objective-C from within a larger C++ code base. I didn't find it difficult to work with, particularly
74.
▲
by
jaas
4y ago
There is a list of NTP vulnerabilities in this article. If you're interested in a more secure NTP client we've been building one: https://github.com/memorysafety/ntpd-rs Server functionality and NTS support i
75.
▲
by
jaas
4y ago
We still store the certificate in the same ways we did, we just don't talk about it in the subscriber agreement any more as it's redundant with our CP/CPS documents.
76.
▲
by
jaas
4y ago
Yeah, this writing is just rude and unproductive. I hope this being on HN doesn’t make more people believe that communicating like this is a good way to get attention.
77.
▲
by
jaas
5y ago
Divvi Up (ISRG) | Remote | United States | Full Time Divvi Up is a privacy-respecting system for the collection of aggregate statistics, being built by Internet Security Research Group. We allow application owners to collect user data, tele
78.
▲
by
jaas
5y ago
You know that people can and do buy/own apartments in apartment buildings, right? And that on the flip side of the coin, many people rent single family homes?
79.
▲
by
jaas
5y ago
From the FAQ: In short: we believe the Xen architecture allows for the creation of more secure systems (i.e. with a much smaller TCB, which translates to a smaller attack surface). We discuss this in much greater depth in our Architecture S
80.
▲
by
jaas
5y ago
Head of Let’s Encrypt here. This is a compliance issue, there is no security or validation integrity risk.
81.
▲
by
jaas
5y ago
Who exactly are the customers for this chip?
82.
▲
Mod_TLS: Safer TLS for Apache Httpd
(github.com)
3 points
by
jaas
5y ago
|
0 comments
83.
▲
by
jaas
5y ago
It’s not all about you. Unvaccinated people are more likely to infect others. Stop being selfish and get vaccinated.
84.
▲
by
jaas
5y ago
Can/will this be used in Firefox at some point?
85.
▲
by
jaas
5y ago
Let's Encrypt / ISRG | Software Engineer (SRE) | REMOTE (U.S. or Canada) | FULL-TIME Billions of people rely on Let's Encrypt (ISRG) to operate critical digital infrastructure for a more secure and privacy-respecting world. L
86.
▲
by
jaas
5y ago
The Olympics are an extremely wasteful way to see athletes do fun and sometimes heartwarming stuff. They need to stop building massive new infrastructure every time. Aside from the environmental issues, it seems like it almost always come
87.
▲
by
jaas
5y ago
What you are describing matches my impression of things. It has been on the back burner because even if we had a great memory safe version of, say, openbgpd, I am not sure that would have particularly widespread impact. You are probably rig
88.
▲
by
jaas
5y ago
Good ideas! We are already working on plans for DNS. BGP has been in the back of our minds for a while but we haven’t had the bandwidth to start seriously looking into that yet. If you have ideas get in touch!
89.
▲
Supporting Miguel Ojeda’s Work on Rust in the Linux Kernel
(memorysafety.org)
14 points
by
jaas
5y ago
|
0 comments
90.
▲
by
jaas
5y ago
90 days is our choice, 90 days and one second validity isn’t necessarily an issue. The issue is that we said in our CPS that the lifetime was exactly 90 days, and then we did something different, even if just by one second. The problem here
More ›