Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
pfg
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
15 ms
·
91.
▲
by
pfg
8y ago
The segmentation code is keyframe-aware, so it only splits along keyframe edges. In other words: requesting segments of 30 seconds each probably won't get you segments that are exactly 30 seconds long. Still, there could be plenty of o
92.
▲
by
pfg
8y ago
I'm far from an FFmpeg expert, but I believe it's possible to segment the input video, transcode the segments one by one, and then concatenate them. Not sure how the segmentation and concatenation steps perform, but if that's
93.
▲
by
pfg
8y ago
You're free to do anything with the source code that's permitted by the Apache license, including commercial usage. The commercial licensing only affects the binaries offered on the site.
94.
▲
by
pfg
8y ago
Are you sure? The initial post was about .dev being HSTS-preloaded, but the comment I was replying to was an answer to the suggestion that they could use self-signed certificates after importing them to the trust store.
95.
▲
by
pfg
8y ago
Firefox will happily accept self-signed certificates chaining to manually imported CAs. However, there are a lot of severely outdated guides on creating self-signed certificates out there, and many of the certificates produced that way won&
96.
▲
by
pfg
8y ago
Presumably to demonstrate that a phishing site using such a certificate would be visually indistinguishable from the targeted site.
97.
▲
by
pfg
8y ago
By "site", are you referring to the actual site, or the EV indicator? Because the site itself doesn't look anything like Stripe's[1]. [1]: https://stripe.ian.sh/
98.
▲
by
pfg
8y ago
Pretty much any non-obfuscated PoC that anyone could come up with for this vulnerability would be trivial to adapt to run malicious code. This doesn't really lower the bar for anyone, and as long as there's no malicious payload, i
99.
▲
by
pfg
8y ago
I'm not sure why you think GitHub ought to take down code for a proof of concept.
100.
▲
by
pfg
8y ago
The code is released under the Apache License. You're free to compile the source code and use it commercially. You're not allowed to do that with the official binaries.
101.
▲
by
pfg
8y ago
This is under the assumption that CAs fail closed when they encounter DNSSEC errors (which, by some interpretations, is mandatory according to the Baseline Requirements). Merely hijacking the authoritative DNS for a domain does not defeat D
102.
▲
by
pfg
8y ago
The difference between HSTS, Expect-CT and HPKP is that the former two offer a way out (support HTTPS, provide qualified SCTs) whereas HPKP can effectively brick your domain for a couple of months, and it's not even hard to pull off.
103.
▲
by
pfg
8y ago
Presumably that's fairly new. The domain hasn't made it on the HSTS preload list shipped by browsers yet, so my guess would be they started using HSTS in response to this attack.
104.
▲
by
pfg
8y ago
One could argue that in a perfect world the combination of DNSSEC and CAA should stop attacks of this nature. However, this only holds up under a rather limited set of circumstances: 1. The targeted domain would need to make use of both DNS
105.
▲
by
pfg
8y ago
To be more precise, it would be a problem if GitHub got an Extended Validation certificate with the organization field containing the name of the domain owner rather than GitHub itself. It would in fact be perfectly fine for a CA to issue a
106.
▲
by
pfg
8y ago
> I also can't remember whether there's an API for legitimate owners to revoke a cert issued to someone else that's no longer OK. Let's Encrypt does have to be able to do that, but if there's no API it might be v
107.
▲
by
pfg
9y ago
I'm not exactly sure what your threat model is, then. The typical way this gets deployed is with U2F USB devices with non-extractable keys. "Access to all keys" is not exactly technically feasible. If your concern is "we
108.
▲
by
pfg
9y ago
webauthn helps with phishing in the same way that U2F does: by binding the keys to specific domains/origins. A phishing site hosted at gmailsecurelogin.com can still steal your password, but the security key is not going to produce any
109.
▲
by
pfg
9y ago
SNI is part of the first message a TLS client sends to the server - the Client Hello. TLS clients that support SNI (including all modern browsers) will typically always send the SNI extension, regardless of whether the server supports or ma
110.
▲
by
pfg
9y ago
There's a fee of $0.50 per hosted zone and month for Route 53, in addition to the $0.40 per million queries. This is optional if you don't want to use Route 53 for DNS, so you can still use a free option like Cloudflare instead.
111.
▲
by
pfg
9y ago
Would you recommend going with Go's crypto/tls if you can get away with it?
112.
▲
by
pfg
9y ago
MesaLink relies on ring for its crypto operations. Ring is written in a mix of Rust, C and assembly, with most of the C and assembly code coming from (Boring|Open)SSL.
113.
▲
by
pfg
9y ago
Cloudflare would be another example of a large-scale BoringSSL user (with some changes for things like OCSP).
114.
▲
by
pfg
9y ago
You're still leaking that information due to SNI.
115.
▲
by
pfg
9y ago
Publicly-trusted CAs can issue trusted certificates for IP addresses. It's simply far less commonly used, and most CAs either don't offer it at all or only for enterprise clients. (You might have been thinking about issuance for I
116.
▲
by
pfg
9y ago
It's worth noting that Chrome has plans to deprecate header-based pins in a few months and static pins (the ones baked into binaries) at some point after their Certificate Transparency policy covers all non-expired certificates. That&#
117.
▲
by
pfg
9y ago
By "verifying who controls the IP space", do you mean verifying control over the IP a domain resolves to? In that case, what you're missing here is that control over DNS lets you alter that IP address to whatever you'd l
118.
▲
by
pfg
9y ago
The email address is optional, though most clients tend to hide that fact (or make it mandatory).
119.
▲
by
pfg
9y ago
There's a couple of things to keep in mind. First, all major browsers (and many other TLS clients too) have been using SNI for more than a decade now, so it's not so much that TLS 1.3 makes things worse, it just better reflects th
120.
▲
by
pfg
9y ago
Based on what my own tests have shown, it seems that Netlify serves content from EC2 instances in the AWS region that's closest to the visitor (presumably using NS1's Geo Routing). That definitely results in better performance com
More ›