Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
nickf
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
121.
▲
by
nickf
5y ago
You might want to double-check that. The CAs (all but two, basically) disagreed with the lifetime reduction and actively voted and argued against it.
122.
▲
by
nickf
5y ago
CABF and root programs allow NC'd CAs - they're just a pain to operate. The infra itself, keeping up with compliance and root program changes (which happen with more frequency now!), CT logging, running revocation services (not ea
123.
▲
by
nickf
5y ago
Wish it were as simple - ultimately having a name-constrained and publicly-trusted CA is the same as having any publicly-trusted CA and comes with a ton of wonderful burdens like audits. You're essentially running a public CA at that p
124.
▲
by
nickf
5y ago
Browsers verify the SCTs (in the certificate or less often as part of the TLS handshake). https://blog.pierky.com/certificate-transparency-manually-ve... This verification needs no communication between the browser/use
125.
▲
by
nickf
5y ago
‘Shady business’ - what and how exactly, out of interest?
126.
▲
by
nickf
6y ago
To be clear, Sectigo was split from Comodo by PE. They are separate companies. The CEO at Comodo who did the LE trademarking attempt hasn’t been a part of Sectigo and the CA for 3 years. Sectigo have also worked with LE and helped to sponso
127.
▲
by
nickf
6y ago
Apple did actually make the limit a matter of their policy. Start date is September 1, technical enforcement comes 'later', but the requirement is going to be part of their policy. https://lists.cabforum.org/piperm
128.
▲
by
nickf
7y ago
LE are pretty open about their expenses, ~$3.6m a year currently, if I remember correctly. They got bootstrapped with a cross-signing from IdenTrust and so were able to get off the ground fairly quickly. That won't have been cheap, and
129.
▲
by
nickf
7y ago
That doesn't sound right - I want to look into it for you. Would you be able to send me any info (domain, order IDs) you can to nick (at) sectigo (dot) com, please?
130.
▲
by
nickf
12y ago
I can help get a ECDSA cert for you - my (personal) email is on my profile.
131.
▲
by
nickf
13y ago
No, they don't. The keys are generated using in-browser controls (XEnroll/CertEnroll and HTML 'keygen' tag).
132.
▲
by
nickf
14y ago
What exactly are you looking for in the review? (I'd note that sslshopper.com isn't owned by any CA as far as I'm aware - though it probably has fake reviews.) Certs are really broken down into 3 validation 'standards' and 3 'types' of cert
133.
▲
by
nickf
14y ago
...and a bunch of browsers don't want to trust it. This shouldn't be the case. My email is on my profile if you want to email me any details you can - I'll get this solved!
134.
▲
by
nickf
14y ago
Companies like Microsoft are king-makers so they essentially get to pick and choose who gets to be a "trusted" certificate authority, and therefore we wind up with a competition-less market. Not really. Each browser and OS has it's own be
135.
▲
by
nickf
14y ago
I'd say it's not a bad idea - oddly enough I've tried to do it the other way around (using a physical PKCS#11-compatible token on iOS devices). There are CAC-type smartcard readers that operate over Bluetooth, but they're big and expensive.
136.
▲
by
nickf
15y ago
Not 'yet' valid? Check your system clock...I'm willing to bet it's set a few years in the past!
137.
▲
by
nickf
16y ago
A great response to a pretty horrid marketing fluff-piece. A couple of points: CAs (public ones, at least) are generally phasing out 1024 bit end-entity certs. The VS group are only allowing for 1 and 2 year certs, while GoDaddy, Comodo, Di
138.
▲
by
nickf
17y ago
StartCom were accepted into the Microsoft Root Program late last year, so they work in 'most' modern browsers (IE, FF, Safari, Opera, Chrome etc.) They unfortunately miss out on mobile devices, older browsers and a number of non-browser SSL
139.
▲
by
nickf
17y ago
They did, yes. It was a code-signing certificate, and it was a relatively long time ago. You'd be hard pressed to do that again. Mistakes happen and always will - lessons were learned, procedures tightened. Nowadays getting, say, an EV cert
140.
▲
by
nickf
17y ago
I don't think it's a scam, no. Disclaimer: 'it' pays my wages. As another poster mentioned, encryption is worthless without having some kind of validation of the other end-point you're communicating with. Granted, the CA industry has made s
141.
▲
by
nickf
17y ago
One thing to check about - SSL certs. Should you want one, you may find yourself SoL. A lot of US companies can't do business with Libya (& Iran, Iraq, Cuba, Sudan etc. etc.) which can mean any cert requests for .ly are banned. I can't
142.
▲
by
nickf
18y ago
Ignoring wages, hosting, DR site maintenance, general business costs etc, the other maintenance costs I can see over other SaaS/webhosting/domain businesses (which are similar). mid $xxxxx/mo for CDN hosting mid $xxxxx startup for the hardw
143.
▲
by
nickf
18y ago
Not sure which CA you went with, but we re-validate each time you renew. I don't know about the premiums or your figures - could be right. The same figures could well apply to many hosting companies though, and they don't have the insurance
144.
▲
by
nickf
18y ago
They did cost thousands, but the monopoly is no longer and you can get certs for $10 if you hunt. EV ones can cost up to $1000 again, but they genuniely do cost more to issue. And no, I'm not saying they don't have large costs. You can beco
145.
▲
by
nickf
18y ago
You're right - that should have happened. It didn't of course, because the company(-ies) that started the DV issuance didn't want to go back and fix it. As well as that, if the browser/OS people did 'downgrade' the DV certs, millions of cus
146.
▲
by
nickf
18y ago
I'm not making any excuses. It's just that there's been a lot of discussion about SSL certs the past few months, and I'm willing to bet there's no more than a roomful of people worldwide with the knowledge and experience to understand how t
147.
▲
by
nickf
18y ago
I doubt I can give too much information out publically, sadly. As for the level of vetting, a lot depends on who you bought it from, and what type of cert.
148.
▲
by
nickf
18y ago
I don't know about racket, but you can read my other comments for, I hope, some more insight. As for the green-bar - I'll admit it's taking some time to get hold, but testing (not just from my CA, but all of them) has shown consumer awarene
149.
▲
by
nickf
18y ago
Also: I'll do a shameless plug here. If anyone here on HN needs a cert, or just advise on setting one up, what to buy - I'm more than happy to help (even if you don't get one of ours!). I'll certainly do what I can discounts-wise. I'm a tec
150.
▲
by
nickf
18y ago
Here we go: There's essentially 3 types of certificate: DV - Domain Validation. The cheap, automated ones. Certs contain no more than the domain name they're issued to, and the whole process is automated. OV - Organisational Validation. The
More ›