Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
joshmoz
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
31.
▲
Let's Encrypt Launch Schedule
(letsencrypt.org)
233 points
by
joshmoz
11y ago
|
66 comments
32.
▲
by
joshmoz
11y ago
HSMs can typically duplicate keys to other HSMs (though usually only other HSMs from the same vendor). All of the Let's Encrypt private keys are stored on multiple HSMs.
33.
▲
Add Amazon root certificates
(bugzilla.mozilla.org)
238 points
by
joshmoz
11y ago
|
77 comments
34.
▲
by
joshmoz
11y ago
It's also on our website. https://letsencrypt.org/about/
35.
▲
by
joshmoz
11y ago
Maybe, but it's hard to get me too worked up about this mechanism when the government has people lined up to be killed.
36.
▲
by
joshmoz
11y ago
It's cool that they were able to do this with two machines, and I don't want to detract from that, but it's probably worth pointing out that a "machine" is not a very useful unit of capacity. These two machines coul
37.
▲
by
joshmoz
11y ago
Will see if we can clarify re: your first point. Probably have to live with the caps but will ask about that too. Thanks for the feedback.
38.
▲
by
joshmoz
11y ago
The idea here is that we need to be able to modify terms quickly if need be (e.g. if a critical issue is identified), but hopefully that will never be the case. Under normal circumstances we will post the updated agreement quite a while bef
39.
▲
by
joshmoz
11y ago
You're looking at the key which defines what CRITICAL means. Look further down the page for info about actual vulns. I believe they're running a bit late posting the vulns for 38 today.
40.
▲
PKI.js
(github.com)
2 points
by
joshmoz
12y ago
|
0 comments
41.
▲
by
joshmoz
12y ago
The CA itself is not ready yet. When it is, you can use the client in a simple mode to grab a certificate and drop it wherever you want, without automated configuration.
42.
▲
MozJPEG v3.0 released
(github.com)
4 points
by
joshmoz
12y ago
|
0 comments
43.
▲
by
joshmoz
12y ago
Thanks for pointing this out! Filed a bug: https://github.com/mozilla/mozjpeg/issues/139 I said in another comment that we'd release 3.0 tomorrow, we'll probably hold up the release to investigate t
44.
▲
by
joshmoz
12y ago
We have no plans to use mozjpeg in Firefox, it will continue to use libjpeg-turbo. The decoder that comes with mozjpeg is unmodified from libjpeg-turbo, mozjpeg is focused on compression for those serving up images.
45.
▲
by
joshmoz
12y ago
FYI, I plan to officially release mozjpeg 3.0 tomorrow. Thanks for the writeup and your work on this release, Kornel!
46.
▲
by
joshmoz
12y ago
We'll have very broad compatibility from day one via cross-signing by IdenTrust.
47.
▲
by
joshmoz
12y ago
What you're seeing today is demos, not the software in its final form. You're also seeing it demo'd with a focus on the most simple usage. There are, and will be, advanced options. We'll be doing quite a bit of work base
48.
▲
by
joshmoz
12y ago
This is not an attempt to reduce the CA system to a single CA. The intent here is to provide a simple and free way for anyone to get basic DV certs. If we can also contribute to CA best practices, and help improve the CA system in general,
49.
▲
by
joshmoz
12y ago
IdenTrust will be cross-signing our roots while we apply to root programs.
50.
▲
Choose Firefox Now, Or Later You Won't Get A Choice
(robert.ocallahan.org)
175 points
by
joshmoz
12y ago
|
126 comments
51.
▲
by
joshmoz
12y ago
"cjpeg" is the basic command-line tool for making use of the mozjpeg library to create JPEG images. libjpeg-turbo and IJG JPEG libraries also have "cjpeg" tools as their basic command-line encoder. The tool for mozjpeg w
52.
▲
by
joshmoz
12y ago
I don't think that fact that you're only looking at lossless compression is clear enough in the post. People see "JPEG" and "compression" and they assume you're talking about lossy compression. The post do
53.
▲
by
joshmoz
12y ago
Yes, building the source will produce (among other things) a command line application called "cjpeg", which can encode or re-encode.
54.
▲
by
joshmoz
12y ago
Daala development is proceeding at a rapid pace. We're just not ready to bring Daala into this conversation quite yet.
55.
▲
by
joshmoz
13y ago
IIRC... That is in reference to libpkix, the certificate validation component of NSS. I believe Mozilla developers are working on a replacement for it, called mozilla::pkix, in large part due to libpkix being overly complex. Last time I che
56.
▲
by
joshmoz
13y ago
The Mozilla WebP bugs are a mess due to loads of poor comments. Read at your own risk. The bug you cite has been superseded by a new bug with the same poor quality of comments. I recently posted a more detailed summary of my own views on th
57.
▲
by
joshmoz
13y ago
This was discussed with the author of libjpeg-turbo. His priorities are different, it was agreed that a fork is best.
58.
▲
by
joshmoz
13y ago
We would like to develop in the open, and hopefully with community participation.
59.
▲
by
joshmoz
13y ago
No shell script or second step involved. Functionality is built in and on by default. This is just a start, we wanted to have something people could use on day one. Further developments to come.
60.
▲
Introducing the ‘mozjpeg’ Project
(blog.mozilla.org)
409 points
by
joshmoz
13y ago
|
128 comments
More ›