Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
sleevi
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
12 ms
·
61.
▲
by
sleevi
13y ago
Part of the reason it's so hard to get code into NSS is because no one really knows who owns those bits, and so they linger in obscurity. I think my TLS Channel Bindings patch is lingering on 3 or 4 years now. However, I think you'
62.
▲
by
sleevi
13y ago
> My bet is that the answers to those questions will be more favorable for NSS, even with the crappy certificate handling. Here's the thing, the SSL libraries are so much more than "just" SSL libraries, and products that u
63.
▲
by
sleevi
14y ago
The Authority Info Access extension ( http://tools.ietf.org/html/rfc3280#section-4.2.2.1 ) can contain caIssuers field that point to URIs from which the issuer certificate may be downloaded. In practice, there's not a "single" chain for a
64.
▲
by
sleevi
14y ago
Internet Explorer, Mozilla Firefox, and Google Chrome all respect name constraints. I believe Opera does as well. The issue is that according to RFC5280, nameConstraints MUST be marked critical, which would break all clients that don't supp
65.
▲
by
sleevi
14y ago
You're talking about http://lists.w3.org/Archives/Public/public-webcrypto/2012Sep... , right? I replied, and also tried to clarify in a follow-up message on http://lists.w3.org/Archives/Public/public-webcrypto/2012Sep... As far as "arra
66.
▲
by
sleevi
14y ago
In other words, you're claiming that some few skilled cryptographers will produce a safe, high-level API (eventually) and the low-level API is already useful to many web developers. The implication is that many web develope
67.
▲
by
sleevi
14y ago
While the trust issue you raise is legitimate, it's not one we're trying to solve (or at least, not yet, and I hope not soon) You may ask then, "Well, what's the point of this API if you're not going to solve it?" The answer is that solutio
68.
▲
by
sleevi
14y ago
For what it's worth, while I object to your tax-and-spend approach with cupcakes, I do subscribe to your TLS-only newsletter for key-utilizing operations, and had proposed that already. Keyless operations are more of a gray area of policy r