Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
pfg
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
17 ms
·
121.
▲
by
pfg
9y ago
I'm not saying that you need to grant any kind of permission in order to use U2F tokens, but rather that a user thinking "I want to login to Google" and "I need to use that USB key thingy to do that" is quite likely
122.
▲
by
pfg
9y ago
Convincing users to grant access to a USB device when they're attempting to log in to a service using said USB device sounds like something that would work more often than not. We wouldn't need phishing-resistant authentication me
123.
▲
by
pfg
9y ago
There is a permission prompt, but it's fairly easy to convince users to accept it during a login attempt when they're expecting their USB U2F device to be used.
124.
▲
by
pfg
9y ago
They're not claiming the certificates were compromised because of their own practices, in fact they repeatedly emphasise that there was no issue on their end. I'm not questioning that the certificates became compromised the moment
125.
▲
by
pfg
9y ago
Symantec is already getting distrusted and the Web PKI community has decided on a plan that minimizes user impact while doing that. It's very doubtful that a company as incompetent as Trustico has the expertise to come up with a more w
126.
▲
by
pfg
9y ago
To clarify, other certificate types do not judge content either. The difference is that they verify your organisational details (to a varying degree, depending on the validation level) and include them in the certificate. The CA is not goin
127.
▲
by
pfg
9y ago
He's arguing that the various issues that lead to Symantec being gradually distrusted mean that they believed all their existing non-expired, non-revoked certificate were compromised (in the sense that they should not be trusted) and s
128.
▲
by
pfg
9y ago
> The secondary part is that they requested mass revocation of active certificates, including from brands such as RapidSSL which were not being browser distrusted AFAIK (even though some others were.. if I need to be corrected on this pl
129.
▲
by
pfg
9y ago
Trustico now posted a statement on their site[1]. My favourite part is this: > Trustico® followed the requests of DigiCert by initially recovering Private Keys from cold storage and subsequently e-mailing the associated order number and
130.
▲
by
pfg
9y ago
This is not wrong, but in the context of them generating and storing private keys for their users it means there's nothing in the Baseline Requirements preventing them from doing so if the subscriber (user) agrees to it. However, even
131.
▲
by
pfg
9y ago
Not all parts of the source code are available under the same license. The individual source code files include the applicable license. Doing this is fine for compatible licenses and not unusual for projects, though it can make certain thin
132.
▲
by
pfg
9y ago
Researchers have found many, many flaws in Estonia's e-voting system[1]. [1]: https://estoniaevoting.org/
133.
▲
by
pfg
9y ago
One way that sites can use this service is to check whether a password has been leaked when users sign up. By handing over the SHA-1 hash of the password you're effectively trusting this service (and anyone who might have compromised i
134.
▲
by
pfg
9y ago
kiallmacinnes already mentioned that rate limits have no effect on renewals, but more importantly: There's a fairly simple process to bump rate-limits if your use-case requires it[1]. [1]: https://docs.google.com/forms&
135.
▲
by
pfg
9y ago
U2F is the only generally available two-factor method that is phishing-resistant. Phishing accounts for a large percentage of targeted attacks, something that is highly relevant in a threat model for journalists.
136.
▲
by
pfg
9y ago
The most notable exception to this would be Chrome OS (which also served as a starting point for CoreOS and, IIRC, Google's container OS). This hasn't stopped Google from using a Debian variant internally as a desktop OS, so they
137.
▲
by
pfg
9y ago
Generally speaking, Chrome uses whatever is in the OS trust store, with certain exceptions for CAs that have been naughty (e.g. StartCom, WoSign, Symantec) or subCAs that were revoked via CRLSets. Private CAs present in the OS trust store w
138.
▲
by
pfg
9y ago
It's fairly trivial to request a rate limit adjustment from Let's Encrypt[1]. [1]: https://docs.google.com/forms/d/e/1FAIpQLSetFLqcyPrnnrom2Kw8...
139.
▲
by
pfg
9y ago
Users often have very little choice when it comes to their ISP. Regional ISP monopolies are very much a thing in many countries.
140.
▲
by
pfg
9y ago
Safe Browsing is implemented in a fairly privacy-preserving way. The block list is downloaded periodically and sites are checked against this list locally. The only time most browsers implementing Safe Browsing will share potentially privac
141.
▲
by
pfg
9y ago
The courts recently ruled on a similar case[1] and came to the conclusion that it was not a CFAA violation. That said, there's a difference between a public website such as LinkedIn and a host that just happens to be reachable over the
142.
▲
by
pfg
9y ago
It's generally a good idea to avoid JWT. There are a lot of foot-guns in JWT, and many implementations have gotten it wrong in the past. This[1] is a good summary on the topic. [1]: https://paragonie.com/blog/2017&
143.
▲
by
pfg
9y ago
> What would be insecure about a https-01 challenge, that esentially works identical to the http-01 challenge but allows any certificate? There's a specific reason http-01 is HTTP-only, and it's actually quite similar to the tl
144.
▲
by
pfg
9y ago
An option that's often overlooked is to use a CNAME record for the _acme-challenge label pointing to a domain under your control. acme-dns[1] explains this approach in detail. The usability of the HTTP and TLS challenges is still bette
145.
▲
by
pfg
9y ago
Thanks. I signed up for the first shared web hosting provider I could find that uses DirectAdmin and was able to reproduce this. I'll bring this up in the relevant thread on mozilla.dev.security.policy, this is definitely concerning.
146.
▲
by
pfg
9y ago
> Is this a problem for Let's Encrypt? Doesn't Let's Encrypt's verification require creating files with random names in http://example.com/.well-known/acme-challenge where example.com is the cert
147.
▲
by
pfg
9y ago
It eliminates one possible foot gun. A web host or CDN might allow arbitrary domains to be added, and arbitrary certificates to be uploaded for said domains, all without any validation. That would ... not be my favourite implementation, but
148.
▲
by
pfg
9y ago
> Is it possible to make Caddy deterministically use the capabilities of the ACME protocol to try the intersection of challenges you want to use, and the ACME server supports? No. It's not. Very, very few ACME clients have a renewal
149.
▲
by
pfg
9y ago
> This whole thread is responding to the author of Caddy saying specifically that people need to intervene or Caddy won't necessarily renew properly. No, that's not what Matt said: > Your sites will likely not go offline eve
150.
▲
by
pfg
9y ago
It's definitely an option , but the question is whether someone who has set up certbot at some point in the past will benefit from it without manual intervention (as is the case for Caddy). If you're following the standard setup,
More ›