Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mnordhoff
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
mnordhoff
9y ago
Hey, you support Ed25519! Only some of the time -- I'd bet your PowerDNS resolvers support it but your Unbound ones don't -- but you might be the first public recursive DNS provider to support Ed25519 at all. (Recent versions of U
32.
▲
by
mnordhoff
9y ago
You can usually tell from the NS and SOA records. For example, "dig io ns", "dig io soa", "dig org ns", "dig org soa". Afilias is the only registry operator i know of that uses nameservers with names
33.
▲
by
mnordhoff
9y ago
I would hope CAs run their own DNSSEC validating resolvers, and they don't just plug "nameserver 8.8.8.8" into resolv.conf.
34.
▲
by
mnordhoff
9y ago
The standard way to do that is: example.com. CAA 0 issue ";" https://tools.ietf.org/html/rfc6844#section-5.2
35.
▲
by
mnordhoff
10y ago
Your Firefox fork could take inspiration from the relicensing process Mozilla followed last time. ;-) https://www-archive.mozilla.org/MPL/relicensing-faq.html
36.
▲
by
mnordhoff
10y ago
There are some release builds that do. https://wiki.mozilla.org/Add-ons/Extension_Signing#Unbranded...
37.
▲
by
mnordhoff
10y ago
You're right, but i'm afraid to imagine how much it costs to get an enterprise account with one of the major CAs with API access to issue hundreds of thousands of certificates.
38.
▲
by
mnordhoff
10y ago
The newer EBS types don't charge per I/O operation. (Provisioned IOPS types charge for the speed you theoretically can do, but don't charge for the ops you do do.) https://aws.amazon.com/ebs/pricing&#
39.
▲
by
mnordhoff
10y ago
I mean, some organizations do take precautions against this point of failure and use a separate status domain. Most don't. https://www.dynstatus.com/ (using Route 53, at least today) https://www.cloudflarest
40.
▲
by
mnordhoff
10y ago
I've had an IP address from a certain cloud provider for a month. Some abandoned domain still has its nameserver and glue records pointing to the IP, and i get DNS queries all the time. The domain expires in January. I hope it's n
41.
▲
by
mnordhoff
10y ago
Now i have ten tabs open catching up on tweets from you and @sleevi_ https://bugzilla.mozilla.org/show_bug.cgi?id=1261919 is fun
42.
▲
by
mnordhoff
10y ago
Not particularly. https://security.googleblog.com/2015/09/improved-digital-cer... https://security.googleblog.com/2015/10/sustaining-digital-c...
43.
▲
by
mnordhoff
10y ago
How about AWS Certificate Manager? Their certificates are free and integrated with AWS services like ELB. https://aws.amazon.com/certificate-manager/ (No doubt they're free because they're integrated with A
44.
▲
by
mnordhoff
10y ago
Snowden literally said "I left on crutches." https://twitter.com/snowden/status/776543206938906625
45.
▲
by
mnordhoff
10y ago
You realize modern Intel CPUs include a TRNG, with the RDRAND and RDSEED instructions, for no extra cost. Can't get cheaper than that, if you already have one. https://en.wikipedia.org/wiki/RdRand The potential of
46.
▲
by
mnordhoff
10y ago
The first stable version of xz with threading was 5.2.0, released in December 2014. A lot of people are running older packages, or were until recently, and habitually use pixz instead.
47.
▲
by
mnordhoff
10y ago
However much space you personally need, it's beneficial to be isolated on a separate /64 from other clients. A lot of services block IPv6 abuse on a /64 basis. It sucks when one jerk gets everyone else in the data center bloc
48.
▲
by
mnordhoff
10y ago
Really really. It's 16 IPs. By comparison, your IPv4 mask is /24 or something, but that doesn't mean the whole subnet is yours.
49.
▲
by
mnordhoff
10y ago
Kind of? There was the infamous Brandon Mayfield case a decade ago, where the FBI came down on an innocent American lawyer for the 2004 Madrid train bombings, despite the skepticism of Spanish security, because he was one of twenty people w
50.
▲
by
mnordhoff
11y ago
www.sprint.net has address 208.24.22.50 www.sprint.net has IPv6 address 2600::
51.
▲
by
mnordhoff
11y ago
All three are good choices, with their own advantages and disadvantages. Argon2 may be clearly the best choice a few years from now, but both the algorithm and software implementations are immature. It's makes sense to be conservative
52.
▲
by
mnordhoff
12y ago
You don't really have to chase down hundreds of tweets. Just open up https://twitter.com/justkelly_ok and start scrolling. If you want to go chronologically, the first tweet I see is https://twitter.com/
53.
▲
by
mnordhoff
12y ago
I believe CloudFlare's free "Universal SSL" uses ECDSA. Support isn't, um, universal, but it seems to be widespread enough among modern clients.
54.
▲
by
mnordhoff
12y ago
It even suggests you replace the key "more often if possible"! :(
55.
▲
by
mnordhoff
12y ago
Wait, Diffie-Hellman keys? Don't those have to be unique? Do you mean the session ticket keys, used to encrypt session resumption information? https://www.imperialviolet.org/2013/06/27/botchingpfs.html
56.
▲
by
mnordhoff
12y ago
That vulnerability only applies to HVM guests. No doubt there are other reasons to have rebooted since 2013, but if one of Rackspace's servers only has paravirtualized guests (do they use HVM at all? I don't know), they can get by
57.
▲
by
mnordhoff
12y ago
> ... wouldn't it be nearly impossible for them to decrypt a properly encrypted hard drive unless they had an powerful supercomputer? It would be entirely impossible for them to decrypt a "properly encrypted" hard drive ev
58.
▲
by
mnordhoff
12y ago
Some people define "reasonable" as not seizing information from journalists, destroying their stuff, offering them choices that include getting shut down... Edit: How effectively they can cloak themselves in legalism is beside the
59.
▲
by
mnordhoff
12y ago
That doesn't follow. You don't have to use jackbooted thugs to intimidate someone. Ordering government agents to be sent to a newspaper to destroy information sounds pretty intimidating to me, even if the agents in question are fr
60.
▲
by
mnordhoff
12y ago
More or less. See http://veridicalsystems.com/blog/of-money-responsibility-and... . That's kind of one of the problems with OpenSSL: The paid work they do may help most of the OpenSSL developers pay their bills, bu
More ›