Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
pfg
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
18 ms
·
151.
▲
by
pfg
9y ago
If tls-sni-02 is affected too (as Josh indicated it probably is below), I'd suspect something like a major CDN or hosting provider allowing deployment of arbitrary, attacker-controlled certificates on arbitrary domains under "acme
152.
▲
by
pfg
9y ago
Caddy's current implementation is more resilient than most other ACME clients in the event of an incident like the one Let's Encrypt is currently experiencing. Typical client implementations (such as certbot, but most others too
153.
▲
by
pfg
9y ago
I'm not aware of any public discussion of the ongoing incident. This[1] is the thread on the ACME WG mailing list that lead to tls-sni-02 being introduced. [1]: https://mailarchive.ietf.org/arch/msg/acme/
154.
▲
by
pfg
9y ago
I think we're talking about slightly different scenarios. HTTP-01, for example, cannot be solved by just echoing back the file name the validation server requests because the client is supposed to return "token || '.' ||
155.
▲
by
pfg
9y ago
tls-sni-02 is not supported on the production ACME server. It is part of the latest ACME draft (ACME v2), which recently got deployed on Let's Encrypt's staging server, but the certificates signed in that environment aren't p
156.
▲
by
pfg
9y ago
Interesting, definitely looking forward to the details, and great to see Let's Encrypt react this quickly even though this might cause a small amount of disruption to users. The latest ACME draft - mostly referred to as what will becom
157.
▲
by
pfg
9y ago
RFC 7710 solves this via DHCP. What's missing is support both on operating systems and captive portal devices.
158.
▲
by
pfg
9y ago
As I understand it, the Supreme Court already ruled against states' right on this matter in Gonzales v. Raich. That case was about medical marijuana, but I don't think that matters. (IANAL.)
159.
▲
by
pfg
9y ago
The vulnerabilities affect multiple layers in a virtualized environment. Amazon patching the virtualization host is what would prevent things like guests reading host memory (essentially a guest escape - one VM gaining access to other VMs r
160.
▲
by
pfg
9y ago
To clarify, the problem here wasn't with their DNS servers, but rather the registrar being compromised. You could run your own DNS servers and still get compromised like this unless you also happen to run your own registrar.
161.
▲
by
pfg
9y ago
As I understand it they're in the process of changing this behaviour[1]. [1]: https://blog.archive.org/2017/04/17/robots-txt-meant-for-sea...
162.
▲
by
pfg
9y ago
Using a TXT record for this purpose would achieve nothing. Just like an SSLStrip attack would strip https:// links and redirects, an attacker can simply block or spoof the DNS response. This doesn't add anything that you do
163.
▲
by
pfg
9y ago
Certainly, but depending on the type of attack, that might not be of much use. In a targeted attack, the damage might already be done by the time the certificate is detected. Additionally, revocation as a whole is broken in various ways[1],
164.
▲
by
pfg
9y ago
The flag was removed in Chrome 63 because the certificate link is now enabled by default[1]. [1]: https://bugs.chromium.org/p/chromium/issues/detail?id=718553
165.
▲
by
pfg
9y ago
It's worth mentioning that they also acquired two root certificates from GlobalSign that are already trusted by most root programs. Some of their sites are already using this trust chain.
166.
▲
by
pfg
9y ago
I fail to see how something like "stripe-service.com" with an EV certificate showing "Stripe, Inc [US]" would be less likely to trick users in a phishing campaign.
167.
▲
by
pfg
9y ago
> I'm pretty sure the running costs of LE is nihil for them. Why ask for donations? For one thing, it's not the best idea to depend on a small number of large enterprises for most of your budget. It's not in any way a conc
168.
▲
by
pfg
9y ago
Without getting into whether I agree with this or whether there's any data supporting such a statement, I think you could make the argument that the EV indicator might make users feel like there's a legal entity behind a site that
169.
▲
by
pfg
9y ago
I still don't quite follow. You were talking about adoption among top 10 sites - is your argument that Twitter is not using an EV certificate[1] because a judge might say something along the lines of "That's all great but how
170.
▲
by
pfg
9y ago
I'm not sure I follow, why does a site's use of Extended Validation affect your ability to sue them? Or do you mean it's a psychological thing - "If our site uses EV, we're more likely to get sued"?
171.
▲
Sandboxing ImageMagick with nsjail
(offbyinfinity.com)
3 points
by
pfg
9y ago
|
0 comments
172.
▲
Sandboxing ImageMagick with nsjail
(offbyinfinity.com)
2 points
by
pfg
9y ago
|
0 comments
173.
▲
by
pfg
9y ago
For me, the most exciting aspect of this product is that they don't require attribution[1]. All the other translation services I looked at[2] required the service's name and/or logo to be part of the UI where the call to the
174.
▲
by
pfg
9y ago
I found this[1]. Appears to be an invite-only preview for now; waiting for my application to be processed. [1]: https://aws.amazon.com/translate/
175.
▲
by
pfg
9y ago
It's a great keyboard! Except for the reliability. Even small bits of dust or other dirt can easily prevent a key from working, and if you're not able to clean it from the outside, you're SOL and need a $400 keyboard replacem
176.
▲
by
pfg
9y ago
I agree with most of this. I switched from a 13" MBP of the previous design to a 15" 2016 MBP. I do appreciate the size and weight reduction - the new one barely feels larger or heavier than my previous 13" MBP. I like the fe
177.
▲
by
pfg
9y ago
Just to clarify, do you want to give every one of those big hosters the keys to the internet, as in either a new root CA or one that's cross-signed by an existing CA? If you're not giving them that, I'm not sure what they wou
178.
▲
by
pfg
9y ago
I'm not sure if this is still the case, but for some time, Twitter served both EV and non-EV certificates depending on where the visitor was located. I don't think they ever publicly explained this behaviour.
179.
▲
by
pfg
9y ago
Domain names are only one small part of the privacy equation. Plus, for many sites, there is a 1:1 mapping between its IP address and the domain. There was some talk about SNI encryption in the TLS working group. Not sure where that went, t
180.
▲
by
pfg
9y ago
This is not what the Baseline Requirements state and it's also not how issuance works in practice. The validation requirements for things like "Organization" always apply "[if] the Applicant requests a Certificate that w
More ›