Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
pde3
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
12 ms
·
31.
▲
by
pde3
10y ago
You can now get those instructions in concise form from the simple widget at https://certbot.eff.org . Let us know if there are any tweaks you'd like to see made to them (or send a PR to https://github.com/ce
32.
▲
by
pde3
10y ago
Perhaps you mean HPKP, not HSTS?
33.
▲
by
pde3
10y ago
We're working on it: https://github.com/certbot/certbot/issues/2782
34.
▲
by
pde3
10y ago
At the moment you can get that behaviour with "certonly --csr". You'll need to make a CSR file yourself. It'll drop your cert and chain files in the current directory. You'll still have an account key and some othe
35.
▲
by
pde3
10y ago
Hooks to perform arbitrary restarts and housekeeping upon renewal were added in version 0.5.0. Run with "--help renew" and/or see https://certbot.eff.org/docs/using.html#renewal
36.
▲
by
pde3
10y ago
This is a discussion about letsencypt-auto, not the underlying letsencrypt/certbot program. Here's what the docs said about letsencrypt-auto: "Because not all operating systems have packages yet, we provide a temporary solu
37.
▲
by
pde3
10y ago
This should be fixed in the new release. For backwards compatibility we've kept the behavior of letsencrypt-auto the same, but certbot-auto will request (Y/N) permission before installing things. For the many folks who want the pr
38.
▲
by
pde3
10y ago
Yes, there are definitely multiple ways to configure it. We focused first on working successfully for as many people as possible, which meant shipping the letsencrypt-auto wrapper script which requires sudo. But with some extra work you can
39.
▲
by
pde3
10y ago
I think your criticisms were pretty fair of the earliest releases of the Let's Encrypt client, but they seem to be less accurate now. We see the client (aka Certbot) being used successfully by many hundreds of thousands of site operato
40.
▲
by
pde3
10y ago
Oh, and it's in use on 500K - 1 million webservers. So extra eyes auditing it are always welcome :)
41.
▲
by
pde3
10y ago
certbot-auto (previously known as letsencrypt-auto) is definitely a hack -- it allows people to run the client on typically older OSes that don't have backported native packages. It's basically a tiny autoupdate and packaging sys
42.
▲
by
pde3
10y ago
https://github.com/certbot/certbot/issues/2373 (if you want to reuse a CSR; reusing the key is probably easier)
43.
▲
by
pde3
10y ago
The official client (now Certbot) actually supports a whole bunch of different use cases; some people want full automation of everything; other people find that "invasive". The software supports both, but people would often find t
44.
▲
by
pde3
11y ago
If you use the letsencrypt python client with "certonly --webroot", it will never touch your config files at all. You can add "-n" to make everything non-interactive and command line-only. If you use letsencrypt with &q
45.
▲
by
pde3
11y ago
You're right, even with Let's Encrypt HTTPS is still more work than speaking insecure HTTP. But it's a brand new project, and we're working to ensure the amount of effort involved is monotonically decreasing. In the next
46.
▲
by
pde3
11y ago
> That was weird, the no-js version didn't work. It just sat there spinning. What extensions do you have installed? There's a known and unfixable issue with browsers that both block JS and absolutely block all requests to trac
47.
▲
by
pde3
11y ago
Spoofing your user agent on your own typically makes you easier to fingerprint, not harder. See footnote 3 of the Panopticlick 1.0 paper: https://panopticlick.eff.org/static/browser-uniqueness.pdf It's more plaus
48.
▲
by
pde3
11y ago
It's arguably true that we set out to build some of the more complicated pieces of the client first, when we could have tried with simpler versions that simply ignored important parts of the HTTPS deployment task. But the traditional U
49.
▲
by
pde3
11y ago
ublock is great software (it didn't exist when we started work on PB!) and so there are only a few things PB will catch that it doesn't. But there are some. For instance, PB will replace widgets such as Tweet and Facebook like b
50.
▲
by
pde3
11y ago
As many as we can implement! Pull requests are welcome :) Good starting places for the current heuristics: https://github.com/EFForg/privacybadgerchrome/blob/stable/sr... https://github.com&#x
51.
▲
EFF: Which apps do (and don't) stop Verizon and Turn's zombie tracking?
(eff.org)
3 points
by
pde3
12y ago
|
0 comments
52.
▲
by
pde3
12y ago
In the US, consider Credo Mobile or T-Mobile. Even AT&T discontinued this practice when called out on it, while Verizon's is flatly recalcitrant; their privacy policy says, "If you do not want information to be collected for m
53.
▲
by
pde3
12y ago
This is a question about the policy layer of the CA using the ACME protocol. The previous issuing CA should have revoked the cert they issued when the domain was transferred. But a CA speaking the ACME protocol might choose to look at whoi
54.
▲
by
pde3
12y ago
Those free certs will encrypt from the browser to CloudFlare's CDN. You still need to do something to encrypt from CloudFlare to the publishing webserver. Self-signing can work for that hop, though Let's Encrypt may wind up being
55.
▲
by
pde3
12y ago
The CAs have agreed to stop using SHA-1 by 2016, and Let's Encrypt will launch with something stronger on day one. But SHA-1 attacks are going to be a huge problem all over our protocol stack :(
56.
▲
by
pde3
12y ago
We'll be in a position to deploy defenses like pinning ( http://www.ietf.org/id/draft-ietf-websec-key-pinning-21.txt ) for site operators who want more protection against the structural problems of the CA system. Th
57.
▲
by
pde3
12y ago
Let's Encrypt is going to publish records of everything it signs, either with Certificate Transparency or some other mechanism. Browsers will be able to check any cert signed by the Let's Encrypt CA against the published list. If
58.
▲
by
pde3
12y ago
You're absolutely right. From first principles, HTTP should have a louder warning than self-signed HTTPS. Our hope is that Let's Encrypt will reduce the barriers to CA-signed HTTPS sufficiently, that it will become realistic for
59.
▲
by
pde3
12y ago
This is just a pre-announcement to let folks (OSes, hosting providers, other platforms) plan and do integration work. Per our own warnings, we definitely don't want this running on production machines until it launches in 2015. Our
60.
▲
by
pde3
12y ago
Sorry, I tried to reply here yesterday but was rate-limited out of the conversation :/ Our aim with this project is to not give advice about what works "right now", because we aren't convinced there are any secure messag
More ›