Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
konklone
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
konklone
10y ago
I think that's an open question. Right now, it's not the millions, that'd be too much to bundle with browsers. But browsers may well change their delivery mechanism for preload information to allow this to scale higher. In an
32.
▲
by
konklone
10y ago
Co-author of the post here, happy to answer questions. =) This is a GSA initiative, not an 18F initiative. But 18F has a recent post detailing executive branch progress on HTTPS that may also be relevant: https://18f.gsa.gov/
33.
▲
Automatic HTTPS Enforcement for New Executive Branch .gov Domains
(cio.gov)
88 points
by
konklone
10y ago
|
78 comments
34.
▲
by
konklone
10y ago
But unless clients or humans do anything in response to the extra OV information, or in response to a lack of the extra OV information, that information has no security value. No browsers do anything with OV data unless humans manually take
35.
▲
by
konklone
10y ago
As it happened, we were migrating production infrastructure to a new service tonight, and had a few minutes of time where the cert was invalid. Sorry about that.
36.
▲
by
konklone
10y ago
You're right, this is (unfortunately) very common. I wish there were clearer guidelines about this. The White House Office of Management and Budget publishes IT policies, and they ask for specific URLs with www in front: https:/&
37.
▲
by
konklone
10y ago
We (18F/GSA) have been using DHS's tool in production for a few months now, and have fixed various bugs as they've come up. Before that, pshtt's methodology was replicated in a Ruby tool (site-inspector) that we grafted
38.
▲
by
konklone
10y ago
And 18F/GSA employee and open source collaborator here. =) Can definitely help answer any questions folks have.
39.
▲
Open source collaboration across agencies to improve HTTPS deployment
(18f.gsa.gov)
104 points
by
konklone
10y ago
|
19 comments
40.
▲
by
konklone
10y ago
And this is a White House policy, with their official blog post and rationale here: https://www.whitehouse.gov/blog/2015/06/08/https-everywhere-... "It is critical that federal websites maintain the
41.
▲
by
konklone
10y ago
Tough to say without knowing more about the stack. But in terms of first byte latency, some things you can look at: * TLS False Start * HTTP/2 + ALPN * Optimizing TLS record size Some 2013-era advice for nginx here: https://
42.
▲
by
konklone
10y ago
Yes, the federal CIO is a presidential appointment.
43.
▲
by
konklone
10y ago
Right, but if it's HTTPS, only the website can give you a virus. If it's HTTP, the website can give you a virus, plus the owner of any network device your requests traveled through on the way to and from the website. That's o
44.
▲
by
konklone
10y ago
It's just basic connection integrity -- without HTTPS, there's no guarantee the user is actually getting the content that the site meant to send, and vice versa. Those kind of attacks really do happen, and at scale (e.g. Verizon X
45.
▲
A vulnerability disclosure policy for the Technology Transformation Service
(18f.gsa.gov)
5 points
by
konklone
10y ago
|
0 comments
46.
▲
by
konklone
10y ago
Analytics makes websites better, and Piwik is not easy or cheap to use at scale. Sharing web traffic data with Google Analytics (especially with IPs anonymized) is a pretty small issue IMO, especially when the benefits are you get good data
47.
▲
by
konklone
10y ago
It's open source. ;) https://github.com/18f/analytics.usa.gov#analyticsusagov
48.
▲
by
konklone
10y ago
While it might assuage some kneejerk skepticism like this, I don't think they're obligated to omit that Chrome has mitigations in place when disclosing a vulnerability.
49.
▲
by
konklone
10y ago
While this is plausible for the past, I think this info is outdated now. https://analytics.usa.gov has lots of data on this (and you can break it out by agency using the dropdown at the top). It also estimates that only 5% of da
50.
▲
by
konklone
10y ago
Or it's just P0 following their policy. Which is the only way P0 can maintain credibility and exert pressure on vendors to fix things. Especially after Google management just publicly overrode them regarding an Apple vulnerability a we
51.
▲
by
konklone
10y ago
It's both. 18F hosts the code and led the development, but there were major contributions from USDS (such as the visual design). And the program itself is owned and directed by the Digital Analytics Program, another team in the GSA. It
52.
▲
by
konklone
10y ago
Wordpress did this by issuing Let's Encrypt certs on demand for every domain people CNAME their way.
53.
▲
by
konklone
10y ago
> Overall, GSA is one of the best agencies when it comes to open source. It has definitely come a long way, but still a long way to go. I think it's never been a better time to get approvals/clarifications/etc for open sou
54.
▲
by
konklone
10y ago
Sure, we have a lot of ATO/compliance stuff in the open: https://pages.18f.gov/before-you-ship/ And there's a GitHub repo with an issue tracker that would make for better conversation capturing than HN: http
55.
▲
by
konklone
10y ago
Compliance: https://pages.18f.gov/before-you-ship/ Hiring: https://pages.18f.gov/joining-18f/
56.
▲
by
konklone
10y ago
This is actually a great time to talk about this stuff, but maybe easier on email (firstname.lastname@gsa.gov) than HN. Drop me a line!
57.
▲
by
konklone
10y ago
It's down for some internal IT reasons, but should be back up at some point soon (but not this weekend).
58.
▲
by
konklone
10y ago
Yeah, I'm torn on it. It's clearly not the right information. But one of the benefits of an automated approach is that everyone's being treated equally, and people can't complain about unfair treatment. In the case of th
59.
▲
by
konklone
10y ago
The world is a complicated place, and the US government is a highly decentralized organization. (And in the case of the executive and legislative branches, decentralized very much by design.)
60.
▲
by
konklone
10y ago
Yes, the IPv6 is a White House (not GSA) mandate, like https://https.cio.gov . It doesn't apply to the legislative or judicial branches, and in that blog post, GSA is advertising the services it can offer other agencies to h
More ›