Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
womble
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
womble
2y ago
Little known fact: "Pulumi" is a Zulu word for "unusually large pile of elephant droppings."
2.
▲
Private key redaction: Ur doin it rong (2020)
(hezmatt.org)
83 points
by
womble
3y ago
|
33 comments
3.
▲
Database Encryption: If It's So Good, Why Isn't Everyone Doing It?
(hezmatt.org)
3 points
by
womble
3y ago
|
0 comments
4.
▲
by
womble
12y ago
I'm not developing the co-op based on the assumption that domain validation can be wholly automated -- but it can be automated for the 99+% of domains that don't try to phish people. I'd say the degree of phishing certific
5.
▲
by
womble
12y ago
(disclosure: I'm the SSL co-op guy) Organisations aren't code, so trying to make analogies to "forking" CAcert isn't something that stands up to scrutiny. Yes, audits for WebTrust compliance are quite expensive -- $
6.
▲
by
womble
12y ago
(disclosure: I'm the SSL co-op guy) CAcert's goal is to issue certificates for free, by implementing an alternate identity validation model. The SSL co-op's goal is to issue a subset of certificates for free, by having those
7.
▲
by
womble
12y ago
"No one should have to sacrifice security because they don't want to fork over that sort of cash" It's a bit long to be the SSL co-op's tagline, but as a motto, you've pretty much hit the nail exactly on the he
8.
▲
by
womble
12y ago
Anything that includes a trademark (like info-secure- apple .com) or "risky" term (like atlanta-usbank.com) typically ends up getting manually verified, even for domain-validated certs. Not saying that plenty of dodgy stuff doesn
9.
▲
by
womble
12y ago
I'm a little surprised that so many people deliberately mangle URLs to see if there's anything listening on :443, myself. I might just pull SSL off the other domain on IPv4, and put it on a separate IPv6 address...
10.
▲
by
womble
12y ago
I'm not averse to that idea, in principle. Heck, that sounds like a nice complementary business idea -- you run a DNS registrar that offers a free domain-validated wildcard certificate with every domain sold, and get your certs from t
11.
▲
by
womble
12y ago
Revocation for X509 certs is a very different matter to that of revoking PGP keys. For X509, the CA can revoke the cert unilaterally, or at the request of the subscriber without the need for the subject private key. In fact, I'm not
12.
▲
by
womble
12y ago
Running a revocation service is an annoyingly fiddly job, but all of that needs to be setup and running before you become a CA. Pretty much all of the faffing around is in the need to regularly regenerate (including signing with the CA key
13.
▲
by
womble
12y ago
(disclosure: I'm the SSL co-op guy) All of Google's free services (CDN, DNS, Chrome, etc) are centred around improving the experience of using the web, so more people use it for longer (and, hopefully, do more searches with Google
14.
▲
by
womble
12y ago
(I'm the SSL co-op guy) - Probably in Australia, at least at first, since that's where I'm based. I'd like the DR site to be in Europe, if possible, but that might not be a day 1 achievement. - I'd like to be able
15.
▲
by
womble
12y ago
All we have to do is get all certs flagged with must-staple and have all webservers handle stapling, and we're set ! (Sarcasm? Moi ?)
16.
▲
by
womble
12y ago
(I'm the sslcoop.org guy) Yeah, well, I haven't worked out how to tell nginx to look at the SNI for a HTTPS request and bomb out completely if it doesn't match any SSL-enabled vhost. Unless you've got pervasive IPv6 --
17.
▲
by
womble
12y ago
(I'm the sslcoop.org guy) "If all the money we spent on ssl certificates..." And thus was sslcoop.org born! I'm not sure what you mean by "opensource PKI infrastructure", exactly, but as a long time F/OSS
18.
▲
by
womble
12y ago
There are rules being introduced against issuing certificates for more than about three years (you can still get five years certs at the moment, but not for much longer); this is more to limit the risk of private key compromise than it is t
19.
▲
by
womble
12y ago
(I'm the sslcoop.org guy) That's essentially the model I'm looking to implement. I prefer DNS modification for domain validation, but anything that can be automated will be.
20.
▲
by
womble
12y ago
(I'm the sslcoop.org guy) StartCom's $60 wildcard is the cheapest I've ever seen. I'm impressed with StartCom's model overall, and it was a great inspiration to me with the SSL co-op. I feel like the more diversit