Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mmalone
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
15 ms
·
91.
▲
by
mmalone
7y ago
Competition is always good. For one, a completely decoupled and separately managed system on a different stack would improve availability of ACME-based certificates. It would also reduce the concentration of trust in one entity. While LE is
92.
▲
by
mmalone
7y ago
That's just stupid enough to be the answer :).
93.
▲
by
mmalone
7y ago
Yea that's why I'm surprised that Google has issued more certs than Amazon has :P.
94.
▲
by
mmalone
7y ago
Hey, author here. There are some pros and cons, but here's my (obviously biased) position. I'm not a CFSSL expert so I invite people to correct me if I'm wrong anywhere here. - CFSSL by default runs open -- it's an unaut
95.
▲
by
mmalone
7y ago
Kinda surprised that Google is so much bigger than Amazon...
96.
▲
by
mmalone
8y ago
Yea, by default anyways, but that doesn’t mean you need to use/trust them for a particular request. I’m talking mostly about service-to-service traffic fwiw, not browsers.
97.
▲
by
mmalone
8y ago
If you’re talking about services that you’re accessing via a browser, true. If you actually do pinning (properly). For service-to-service stuff and APIs the number of TLS clients that respect pinning is approximately zero. Either way, the o
98.
▲
by
mmalone
8y ago
It sounds like using Let’s Encrypt makes sense for your use case since people are accessing these appliances via a web browser, but for “normal internal servers” the right answer is almost definitely to use your own internal PKI, not to use
99.
▲
by
mmalone
8y ago
And if you just rely on the default trust stores you’re actually introducing over 100 third parties, some of which are known to be controlled by (or at least work with) the NSA, China, etc.
100.
▲
by
mmalone
8y ago
The disadvantages are: it’s less secure — you’re trusting (many) third parties with your security and relying on the security of DNS it’s less flexible — you can’t sign certificates with internal names (e.g., *.cluster.local) and certs must
101.
▲
by
mmalone
8y ago
This is a new project I've been working on with my colleagues. We believe every non-trivial cloud infrastructure would benefit from real public key infrastructure (a private CA and management tools). The challenge is making this stuff
102.
▲
Show HN: Autocert – use TLS to access internal kubernetes services from anywhere
(github.com)
12 points
by
mmalone
8y ago
|
1 comments
103.
▲
by
mmalone
8y ago
There’s nothing special about a “client certificate” —- they’re not (necessarilly) any different than a TLS server certificate. Technically a relying party might check that a client certificate includes the “client auth” key use, but most (
104.
▲
Step Certificates: issue, renew and manage certs for internal use of TLS (OSS)
(smallstep.com)
1 points
by
mmalone
8y ago
|
0 comments
105.
▲
by
mmalone
8y ago
Hi, am author. Ah, yea, I know that CAs are supposed to check CAA before issuing and I do understand the security model. Figured browsers could/should too, but just dug a bit more and you’re right that CAA is explicitly not supposed
106.
▲
by
mmalone
8y ago
Lol oops. Thanks.
107.
▲
by
mmalone
8y ago
That’s weird. Screen shot or something? (Edit: work at smallstep; want to fix)
108.
▲
by
mmalone
8y ago
I work at smallstep and figured I'd add a bit more context. `step` implements a bunch of "zero trust" primitives: authenticated encryption (X.509, TLS), single sign-on (OAuth OIDC), multi-factor authentication (OATH OTP), and
109.
▲
by
mmalone
8y ago
Oh, I assumed we were talking distributed. Fsync to more than one disk. My biases :).
110.
▲
by
mmalone
8y ago
Log structured merge is the last piece of your architecture. It solves the latency part. It can also solve your durability issues, if you fsync when necessary and you understand your hardware.
111.
▲
by
mmalone
8y ago
ACID semantics subtley and indirectly requires locks. Any scenario where lock contention might be a problem would be a problem for an RDBMS (assuming the traditional definition of RDBMS as a ACID compliant). Those scenarios can easily be “s
112.
▲
by
mmalone
9y ago
What’s that opinion based on? Apparently 75% of auto execs have a different opinion. I just read the two posts in this thread and it seems the argument is that hydrogen is less efficient to produce and distribute? Well even if that’s true i
113.
▲
by
mmalone
9y ago
It looks like they’re saying that we’ll move to hydrogen fuel cells, not that we’ll stick with gasoline. That’s not really a bad thing.
114.
▲
by
mmalone
9y ago
This is a whole lot of conjecture. Auto manufacturers were investing in alternative fuel way before Tesla came around. BMW lost some ground on electric because they made a huge bet on hydrogen in the late 90s/early 2000s that didn’t pa
115.
▲
by
mmalone
9y ago
Daemons running on user VMs? Or is ssh terminated in a bastion and forwarded somehow? Edit: sorry didn’t read far enough and have now answered my own question. In VMs. So yea, Amazon could not duplicate without getting people to change AMIs
116.
▲
by
mmalone
9y ago
Kerberos / Needham-Schroeder usually refers to an authenticated encryption protocol that uses symmetric keys (shared secrets). It lets two parties who have never communicated, but who both mutually trust some third party, establish one
117.
▲
by
mmalone
9y ago
Are you talking about the `gcloud compute ssh` stuff? I wonder what magic google is using to grt public keys on boxes. I’d think there’d have to be some coordination with the machine image being run for this to work, so it wouldn’t be somet
118.
▲
by
mmalone
9y ago
Around 6%/yr... more than a savings account, but pretty reasonable. I think the IRS charges 6%/yr too.
119.
▲
by
mmalone
9y ago
Still easy to argue that no rational person would do x, therefore x should not be allowed. Really I think it's just too hard to scale the protections and legal mechanisms. ICO solves some (not all) of the scalability problems.
120.
▲
by
mmalone
9y ago
Not necessarily. You should be able to write a halting computation to determine whether a number is prime in a Turing complete language. It may be stupid hard to encode, or take a really long time to run, however. The halting problem says t
More ›