Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
sudoyear123
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
sudoyear123
7y ago
This is a very good question. We actually did consider proxy certs and name constraints certs first and had a long discussion at the IETF about these different options. At the end the consensus was that it would be much better to have a ver
2.
▲
by
sudoyear123
7y ago
As a CA you can issue certificates for other domains as well which might be undesirable. There are existing mechanisms such as Name constrained CAs and proxy certificates to reduce this scope. While they were originally considered there are
3.
▲
by
sudoyear123
7y ago
generalized asn1 parsing can be super tricky and the industry is generally avoiding asn1 for new protocols. There has been some really interesting work from microsoft on verified parsers for asn1 https://www.usenix.org/syste
4.
▲
by
sudoyear123
7y ago
DER encoded ASN.1 is used for the X.509 end-entity certificate, however generally this follows how CertificateVerify works in TLS 1.3 https://tools.ietf.org/html/rfc8446#section-4.4.3
5.
▲
Delegated Credentials in TLS
(engineering.fb.com)
41 points
by
sudoyear123
7y ago
|
15 comments
6.
▲
Edge and Chromium canary speak HTTP/3 to facebook.com
(twitter.com)
2 points
by
sudoyear123
7y ago
|
0 comments
7.
▲
Chrome same-origin bypass using the portal element
(research.securitum.com)
1 points
by
sudoyear123
7y ago
|
0 comments
8.
▲
Chrome same-origin bypass using the element
(research.securitum.com)
1 points
by
sudoyear123
7y ago
|
0 comments
9.
▲
Fraud Resistant, Privacy Preserving Reporting Using Blind Signatures
(github.com)
8 points
by
sudoyear123
7y ago
|
0 comments
10.
▲
by
sudoyear123
7y ago
This would make a great comparison. I'm not certain whether or not K8's mutual auth supports session ticket resumptions and distribution of short lived ticket keys. The ticket rotation design would probably make a great addition t
11.
▲
by
sudoyear123
7y ago
Ya they're similar in that they are all signed blobs of data, but different in the sense that they are specifically designed to send authentication information via several layers of proxies
12.
▲
by
sudoyear123
7y ago
There are several access control mechanisms. One such ACL as mentioned in the post is identity certificates which are used to perform access control. Other mechanisms for identity are CATs which have been talked about in the past https:&#x
13.
▲
Building Facebook's Service Encryption Infastructure
(code.fb.com)
166 points
by
sudoyear123
7y ago
|
45 comments
14.
▲
Mvfst: Facebook's Implementation of IETF QUIC
(github.com)
1 points
by
sudoyear123
7y ago
|
0 comments
15.
▲
Moving fast at scale: Experience deploying IETF QUIC at Facebook [pdf]
(conferences2.sigcomm.org)
7 points
by
sudoyear123
8y ago
|
0 comments
16.
▲
Building Zero protocol for fast, secure mobile connections
(code.facebook.com)
2 points
by
sudoyear123
10y ago
|
0 comments