Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mcpherrinm
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
31.
▲
by
mcpherrinm
6mo ago
It doesn't matter what the network is doing; the phone needs to disable 2g. There's various ways to get the phone to downgrade to 2g otherwise, eg https://montsecure.com/files/2021_downgrade.pdf Android has i
32.
▲
by
mcpherrinm
6mo ago
There's zero spam filtering interfering this way, and you can target your messages very precisely.
33.
▲
by
mcpherrinm
6mo ago
2g networks didn't have the phone verify the network, so yes they can do this. At least as of today, most phones have an option to turn off 2g but that isn't a default.
34.
▲
by
mcpherrinm
6mo ago
Yeah, Chrome only partly supports revocation (Not sure exactly the criteria, but our test sites don't match it).
35.
▲
The difficulty of making sure your website is broken
(letsencrypt.org)
71 points
by
mcpherrinm
6mo ago
|
38 comments
36.
▲
by
mcpherrinm
6mo ago
Git bisect is one of the important reasons IMO to always squash-merge pull requests: Because the unit of review is the pull request. I think this is all Github's fault, in the end, but I think we need to get Github to change and until
37.
▲
by
mcpherrinm
6mo ago
Squash merge is the only reasonable way to use GitHub: If you update a PR with review feedback, you shouldn’t change existing commits because GitHub’s tools for showing you what has changed since your last review assume you are pushing new
38.
▲
by
mcpherrinm
7mo ago
Yes, it's just a number referenced in one of a few databases. > The 15-digit pet microchip is the international standard (see ISO 11784:1996 and ISO 11785:1996) https://www.aaha.org/for-veterinary-professionals/
39.
▲
by
mcpherrinm
8mo ago
It does mean Unix timestamps. The blog post doesn’t have the full details. You can read the RFC draft at https://datatracker.ietf.org/doc/html/draft-ietf-acme-dns-pe... It says: CAs MUST properly parse and interpr
40.
▲
by
mcpherrinm
8mo ago
Note that we only do best-effort submission of final certs, so it's not actually guaranteed that they end up being logged.
41.
▲
by
mcpherrinm
8mo ago
Two current mitigations and one future: DNSSEC prevents any modification of records, but isn’t widely deployed. We query authoritative nameservers directly from at least four places, over a diverse set of network connections, from multiple
42.
▲
by
mcpherrinm
8mo ago
It has these primary advantages: 1. It matches what the CAA accounturi field has 2. Its consistent across an account, making it easier to set up new domains without needing to make any API calls 3. It doesn’t pin a users key, so they can ro
43.
▲
by
mcpherrinm
8mo ago
This wasn’t the first version of the ballot, so there was substantial work to get consensus on a ballot before the vote. CAs were already doing something like this (CNAME to a dns server controlled by the CA), so there was interest from eve
44.
▲
by
mcpherrinm
8mo ago
We (Let’s Encrypt) also agree 10 days seems too long, so we are migrating to 7 hours, aligning with the restrictions on CAA records.
45.
▲
by
mcpherrinm
8mo ago
Yes, you can limit both challenge types and account URIs in CAA records. To revoke the record, delete it from DNS. Let’s Encrypt queries authoritative nameservers with caches capped at 1 minute. Authorizations that have succeeded will soon
46.
▲
by
mcpherrinm
8mo ago
There is no username in ACME besides the account URI, so the UUID you’re suggesting isn’t needed. The account uri themselves just have a number (db primary key). If you’re worried about correlating between domains, then yes just make multip
47.
▲
by
mcpherrinm
8mo ago
As I understand it, greynoise is monitoring scanner traffic, so yes this would all be scans or attacks
48.
▲
by
mcpherrinm
8mo ago
The current PKI system was designed by Netscape as part of SSL to enable secure connections to websites. It was never independent of the web. Of course PKIs and TLS have expanded beyond that. "WebPKI" is the term used to refer to
49.
▲
by
mcpherrinm
9mo ago
The "client cert" requirements were specifically not a CABF rule because that would rule it out for everyone complying with those rules, which is much broader than just the CAs included in Chrome. Some CAs will continue to run PKI
50.
▲
by
mcpherrinm
9mo ago
This is a two-sided solution, and one significant reason for shorter certificate lifetimes helps make revocation work better.
51.
▲
by
mcpherrinm
9mo ago
I chose 160 hours. The CA/B Forum defines a "short-lived" certificate as 7 days, which has some reduced requirements on revocation that we want. That time, in turn, was chosen based on previous requirements on OCSP responses.
52.
▲
by
mcpherrinm
9mo ago
Some ACME clients that I think currently support IP addresses are acme.sh, lego, traefik, acmez, caddy, and cert-manager. Certbot support should hopefully land pretty soon.
53.
▲
by
mcpherrinm
9mo ago
I'm sure this is a difference-of-learning or whatever, but I'm usually unwilling to try a product until I can understand it and how it works from the documentation
54.
▲
by
mcpherrinm
10mo ago
You can look at who the "Stratum 2" servers are, in the NTP.org pool and otherwise. Those are servers who sync from Stratum 1, like NIST. Anyone can join the NTP.org pool so it's hard to make blanket statements about it. I be
55.
▲
by
mcpherrinm
10mo ago
Hm, it's supposed to be https://letsencrypt.org/docs/integration-guide/ - but it looks like the link is broken. I'll fix it.
56.
▲
by
mcpherrinm
10mo ago
It was actually outside of my small apartment with bad lighting
57.
▲
by
mcpherrinm
10mo ago
We’ve already started drafting it :)
58.
▲
by
mcpherrinm
10mo ago
Let’s Encrypt does operate CT logs. I wrote a blog post about our current-generation logs at https://letsencrypt.org/2024/03/14/introducing-sunlight
59.
▲
by
mcpherrinm
10mo ago
Let’s Encrypt currently has a single primary with a handful of replicas, split across a primary and backup DC. We’re in progress of adopting Vitess to shard into a handful of smaller instances, as our single big database is getting unwieldy
60.
▲
by
mcpherrinm
10mo ago
I'm the technical lead for Let's Encrypt SRE. Publishing more about our resilience engineering sounds like a great idea! I'll get that on our blogging schedule for next year
More ›