Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
sleevi
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
sleevi
6y ago
Eh, my point was just that: - Policy is largely encapsulated on the certificate properties in the root store - Local Policy is implemented via registry keys, with somewhere like 100+ odd registry keys (... many undocumented, as they
32.
▲
by
sleevi
6y ago
Chrome on ChromeOS has had its own trust store for ages. Chrome on Android similarly uses Google’s Android store.
33.
▲
by
sleevi
6y ago
I suppose it’s a question of whether you count “documentation” as engineering. It is elegantly complex and featureful. And (sometimes intentionally) poorly documented, as much of that implementation is seen as “an implementation detail”.
34.
▲
by
sleevi
6y ago
For folks discovering this: Unfortunately, this isn’t a good idea, and can seriously harm your system. I’ll be the first to tell you that I believe Google and Mozilla have done a lot for supervising TLS, but realize that the trust stores co
35.
▲
by
sleevi
6y ago
One of the challenges in this space is similar to captive portal detection. It’s not enough to have a solution, you need the vendors of those devices to adopt the solution. Unfortunately, just like captive portals want to avoid detection by
36.
▲
by
sleevi
6y ago
Perhaps? But I’m not aware of anyone (besides the DMARC crew) who could implement this, or even having been involved, so it seems mostly moot?
37.
▲
by
sleevi
6y ago
Yes. The WebAuthN case in particular is quite unfortunate, and one I tried to discourage early on (along with the whole app facets approach)
38.
▲
by
sleevi
6y ago
We are. Deliberate sabotage like that would take quite a while before it was noticed, however, and it wouldn’t magically fix cookies and how people use them. To the extent it is used by cookies, we still want to maintain a fair and equitabl
39.
▲
by
sleevi
6y ago
https://publicsuffix.org/list/ (See the Algorithm) Is actually hard to implement correctly and interoperably, even among browsers, and there are sharp edge cases along the way (such as holes within domain trees). The a
40.
▲
by
sleevi
6y ago
Not oversight nor historical: political. Countries view ccTLDs as their sovereign property and territory on the Internet, and refuse to be (involuntarily) bound to any rules or requirements as a matter of sovereignty. It’s a huge source of
41.
▲
by
sleevi
6y ago
It concluded because, despite everyone agreeing they wanted a unicorn, they couldn’t agree which breed of unicorn they wanted, and thus were unable to get one. Which is to say: things went wrong in circles because different folks had differ
42.
▲
by
sleevi
6y ago
PSL maintainer here: please don’t use the PSL! Yes, it’s weird to have a maintainer asking people not to use their project, but the PSL was a very specific (and unfortunate) hack for a very specific (and unfortunate, and browser-created) pr
43.
▲
by
sleevi
6y ago
Which the EU is debating making an equivalent European wide version mandatory, and requiring websites/private companies adopt and use it (via SAML; instead of username/passwords or things like OAuth/OpenID Connect). In this v
44.
▲
by
sleevi
6y ago
I’m not sure your point? Any HTTP/ALPN request first begins with DNS, so if you’re trying to compare those, they all share the same base issue. In theory, this can be mitigated by DNSSEC, but that’s not relevant when comparing these va
45.
▲
by
sleevi
6y ago
Where have you seen Let’s Encrypt using Google’s servers? CAs are required to run full recursive resolvers, up to the root, and can’t just point at someone else’s DNS infrastructure. Which, if you think about it, is what you want: you don’t
46.
▲
by
sleevi
6y ago
Both of those are reasonable concerns, if all other factors were ignored. However, in practice, the DNS challenge (which demonstrates control over DNS) is greatly preferred over HTTP/TLS challenges (which demonstrate control over a sin
47.
▲
by
sleevi
6y ago
If Apple is the sleeping giant of PKI, Microsoft is the come-back kid. The actual set of CAs trusted by Microsoft has massively shrunk under the leadership of their new Root Program manager, and their transparency greatly improved. https:&
48.
▲
by
sleevi
6y ago
You said Comodo throughout, but it was DigiCert :)
49.
▲
by
sleevi
6y ago
While folks may be thinking “number of queries” must mean it was performance concerns, the answer for Chromium was simpler: SRV records just didn’t resolve for a number of users. Neither do TXT records, for that matter ( https://
50.
▲
by
sleevi
6y ago
Google has, in the past. Look at the ChangeLog for 1.0.0 - the massive improvements made (around PKITS) were sponsored by Google. Google has a healthy Patch Rewards program ( https://www.google.com/about/appsecurity
51.
▲
by
sleevi
6y ago
It isn’t, but then again, in 1995 we might have said the same for expirations in 2015, and yet so, so many poorly managed CAs were expunged in the past 5 years. A healthy root store would set revocation at a much more aggressive period; say
52.
▲
by
sleevi
6y ago
Search for “Needham & Schroeder” It’s not either/or expiration vs revocation; they are the same thing. Expiration is natural revocation and a ceiling function to the overall cost. The statement “when a CA’s root certificate expires
53.
▲
by
sleevi
6y ago
It’s not true that expiration is not about security. Dan Geer’s talk in 1998, noted at https://cseweb.ucsd.edu/~goguen/courses/275f00/geer.html , is just as relevant today in the design of key management syst
54.
▲
by
sleevi
6y ago
Andrew Ayer has a write-up about this at https://www.agwa.name/blog/post/fixing_the_addtrust_root_exp... At the core, this is not a problem with the server, or the CA, but with the clients. However, servers have t
55.
▲
by
sleevi
6y ago
There are no rules for ccTLDs, which their countries like to claim as sovereign property (see https://meetings.icann.org/en/dublin54/schedule/wed-ccnso-me... and https://gac.icann.org/principl
56.
▲
by
sleevi
7y ago
This has been a common suggestion since before the Publix Suffix List existed, as you can see from the linked issues in the text (and the references to the IETF DBOUND WG). Like most things, on first glance, it seems like it does make sense
57.
▲
by
sleevi
7y ago
You may also enjoy https://wiki.mozilla.org/CA/Incident_Dashboard , which all the CAs responding to such incidents need to be aware of, and which shows that there is a rather large amount of proportionality, based on a
58.
▲
by
sleevi
11y ago
This is exactly correct. The answer is that we should build better routing into OpenSSL - and all the other PKI-validating products. It's complex and complicated, but if you only have a very narrow and particular purpose (e.g. just c
59.
▲
by
sleevi
12y ago
Because it was seen as easier to use X.509 (aka a certificate) as a delivery of a Trust Anchor (specifically, a "subject name" and "public key" pair) than to invent yet another storage format. Certificate verification st
60.
▲
by
sleevi
12y ago
"It's one of the Internet's biggest security flaws" - aww, you're killing me here :) We have looked at it. Repeatedly. First when porting Chrome to Linux (and trying to decide what sort of UI there should be for NSS
More ›