Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
nickf
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
91.
▲
by
nickf
2y ago
What non-HTTP services need publicly-trusted certificates and care about revocation?
92.
▲
by
nickf
2y ago
Try datatables.net - they have a sample 'server' (in PHP, plus more you can find on Github) that allow for dynamic search/filtering.
93.
▲
by
nickf
2y ago
Which ‘big players’?
94.
▲
by
nickf
2y ago
APILayer = ZeroSSL
95.
▲
by
nickf
3y ago
...and many of the cloud providers with HSM-backed services (Azure KeyVault, AWS KMS) don't give you any verifiable proof. At least with GCP you can download the attestations and verify them with the HSM vendor. With Azure you pay more
96.
▲
by
nickf
3y ago
Is there anything folks are adding to Pico that adds a nice CSS grid? For dashboards and such.
97.
▲
by
nickf
3y ago
You are correct - I say this as the website ‘landlord’ (scroll right to the very bottom!) The fun part was hosting this myself 20-something years ago and seeing traffic spike like mad. Rented cheap servers from Kimsufi or Ikoula and tuning
98.
▲
by
nickf
3y ago
That really isn't how this works. DigiCert don't have any 'power' as you suggest - the .be government are free to choose any CA they wish from those who are globally trusted. These are for serverAuth certificates, too, s
99.
▲
by
nickf
3y ago
(Full disclosure, 20+ year veteran and CTO of big-CA-you-probably-know, but I really like how your product looks - just need a bit more time to explore!) People do weird things with private CAs. Be it for testing or corporate shenanigans, t
100.
▲
by
nickf
3y ago
Any reason why? That could limit the usefulness of the solution, I'd think. Do you allow issuance of not-hosted-by-anchor CAs for TLS inspection, for example?
101.
▲
by
nickf
3y ago
"...because they have very limited use in public CAs" Not really. It was/is mostly because NCs aren't 'widely' supported, even now. Name Constraints (referred to as 'Technical Constraints') allows - c
102.
▲
by
nickf
3y ago
The crt.sh code is all open on GitHub, so can be hosted yourself. Last I checked a few months ago, the main ‘certificates’ table and indexes etc was close to 20TB, and there’s more than just that. It’s big, but has everything. A slimmed dow
103.
▲
by
nickf
3y ago
Agreed. This is a new kind of obnoxious I haven’t seen before. Another app/service I simply won’t use on the basis of these attempted ads.
104.
▲
by
nickf
3y ago
I really think you’ve missed the point. Opening any of those apps after receiving the notification requires a network connection to then update. It’s not done via the push notification itself. I have never seen that happen in my experienc
105.
▲
by
nickf
3y ago
I made a comment up-thread, but name-constrained CAs can issue for anything . It's enforced client-side, and not supported in far, far too many places to work. You'd be giving everyone the ability to issue for anything. Not to me
106.
▲
by
nickf
3y ago
A wildcard covers one single level of sub-domains. An NC'd CA can be used to issue for anything . Nameconstraints are 'enforced' on the client side and many don't support it. Running a public CA - even with a nameconstr
107.
▲
by
nickf
3y ago
You're right of course, but there's progress being made to require multi-perspective verification (do DNS lookups from many different and ideally randomised locations, only issue if you get consensus). It's not perfect, but i
108.
▲
by
nickf
3y ago
I am 100% not arguing with any of your points, you and I agree absolutely on DNSSEC. However...Comodo don't issue anything anymore - it's Sectigo now. Nitpicky, I know!
109.
▲
by
nickf
3y ago
You can't, but a certificate that isn't logged won't work for the overwhelming majority of practical use-cases (ie any Google or Apple owned product). If you need a certificate that doesn't care about those, you perhaps
110.
▲
by
nickf
3y ago
Not sure what you really mean here - CAs are required to get SCTs from multiple, independently-operated logs. Even then, I think what you're implying here is mathematically impossible, and easily and immediately detectable. Bear in min
111.
▲
by
nickf
3y ago
Aside from what mjg59 said, it's clear you don't quite understand how CT works. Logs are stood up and then go through a fairly rigorous acceptance process by Google (and Apple) before finally being used. 'Used' in that a
112.
▲
by
nickf
3y ago
Clients do not get pre-certs. Those are generated by the CA, and submitted to the log in return for an SCT. Forging a ‘fake CT log’ isn’t possible, either. Nor do clients talk to CT logs, at all.
113.
▲
by
nickf
3y ago
This happened before a couple of years ago, and the problem seems to have repeated itself. https://news.ycombinator.com/item?id=27728287
114.
▲
Random bit-flip invalidates certificate transparency log – again?
(groups.google.com)
141 points
by
nickf
3y ago
|
115 comments
115.
▲
by
nickf
4y ago
…and with more frequency in the future. 90 day certs are going to make it happen all the more often.
116.
▲
by
nickf
4y ago
Honestly, he may be able to grab Twitter for a few picodollars in a month or so.
117.
▲
by
nickf
4y ago
Again, that's really not how it works.
118.
▲
by
nickf
4y ago
That's not quite how CT works. The client doesn't (currently) need to have any access to the CT logs themselves. Generally, a 'pre' certificate is submitted to a number of logs by the CA. The log returns a signed timesta
119.
▲
by
nickf
4y ago
There certainly is a backlog of certs being ingested from the logs: https://crt.sh/monitored-logs - but as you can see, it's tiny. crt.sh does contain all the certificates the CT logs know about. Google certs are there
120.
▲
by
nickf
5y ago
"although in practice the ecosystem went along with it" - not that there was much choice, but some CAs were less surprised and grumbled less than others...
More ›