Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Scott_Helme_
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
No Hacking Required: The Manchester Airports Group Data Breach
(scotthelme.co.uk)
5 points
by
Scott_Helme_
10d ago
|
0 comments
2.
▲
by
Scott_Helme_
3mo ago
No, it was more broad than just SE domains, but trying to detect whether a site is suitable for passkeys support automatically is quite the challenge. Some don't allow themselves to be crawled so require manual verification.
3.
▲
by
Scott_Helme_
3mo ago
I'm not entirely sure that it does, which bit of passkeys are you concerned most with?
4.
▲
by
Scott_Helme_
3mo ago
This is fixed now: https://whynopasskeys.com/country/se
5.
▲
The most popular sites that still don't support passkeys
(whynopasskeys.com)
4 points
by
Scott_Helme_
3mo ago
|
8 comments
6.
▲
by
Scott_Helme_
4mo ago
Interesting, could you link me to some of those sites so I can investigate?
7.
▲
by
Scott_Helme_
4mo ago
I can kind of see it, but you can also just use an authenticator from any manufacturer, or have multiple types that you use? I'm just curious what I'm overlooking.
8.
▲
by
Scott_Helme_
4mo ago
What's the concern with using passkeys?
9.
▲
by
Scott_Helme_
8mo ago
I did try to make it clear in the article. We're powering 2 x EVs, have two adults working from home full time, I have a server rack under the stairs, and we have a hot tub outside.
10.
▲
by
Scott_Helme_
8mo ago
Absolutely — tariff choice, storage, and automation make a huge difference. The article isn’t claiming this setup is universally optimal, just showing what’s possible when those pieces are combined and used deliberately.
11.
▲
by
Scott_Helme_
8mo ago
We had an expensive solar install due to restrictions around our roof, so the solar would typically have been cheaper. Another consideration is that battery installations in the UK are charged at 20% VAT, but if they're installed as pa
12.
▲
by
Scott_Helme_
8mo ago
The only restriction placed on you is the export rate, which is provided to you by the DNO here in the UK. We had a limit of 3.8kW placed, which is programmed in to the batteries by the installer. Octopus also have more flexible battery exp
13.
▲
by
Scott_Helme_
8mo ago
Nah, there's no Bitcoin mining, honest!
14.
▲
by
Scott_Helme_
8mo ago
How did you know about my laser?!
15.
▲
by
Scott_Helme_
5y ago
Thanks! Sometimes the simple tricks are the best ones :)
16.
▲
by
Scott_Helme_
5y ago
There is no reason to differentiate between free certificates and paid certificates. The process works in exactly the same way for either.
17.
▲
by
Scott_Helme_
5y ago
They're all 3 certificates long (leaf/intermediate/root) apart from Let's Encrypt which, due to their cross-signature, are 4 certificates long for ECC.
18.
▲
by
Scott_Helme_
5y ago
If you were to use the same private key for the 4 certificates then you could seamlessly switch between whichever leaf certificate you wanted to serve to the client. I'm not aware of the ability to send multiple leaf certificates to a
19.
▲
by
Scott_Helme_
5y ago
Let's Encrypt can issue from an ECC chain, I've tweeted[1] the details on how to enable your account for that. [1] https://twitter.com/Scott_Helme/status/1392101598852222976
20.
▲
by
Scott_Helme_
5y ago
If you get a 1 year certificate then yeah, but otherwise no. The requirement to re-validate the DNS record comes not from the CA or the use of ACME, but the Baseline Requirements[1] §4.2.1, to prove you are still in control of the domain on
21.
▲
by
Scott_Helme_
7y ago
That's not what I asked, that's a straw man. Browser vendors have tested the efficacy of the current EV indicator, resulting in the current action. If you feel that testing an alternative indicator consistent with other platforms
22.
▲
by
Scott_Helme_
7y ago
But, didn't browser vendors do that and that's why the EV indicator is being moved to a less prominent location?..
23.
▲
by
Scott_Helme_
7y ago
As the organisations that stand to benefit financially from selling these indicators, perhaps it's CAs that should invest in the research? CAs seem to constantly point at the browsers as the party responsible for doing that research, b
24.
▲
Hacking IoT Cameras with s/swnb479e7d24/swn1bf9f32f2/g
(scotthelme.co.uk)
2 points
by
Scott_Helme_
8y ago
|
0 comments
25.
▲
by
Scott_Helme_
8y ago
The only way you could do that is on a hosted platform where they do maintenance for you. There's no way a server would last online for decades without being patched, it would have been hosed countless times over by now. Installing cer
26.
▲
by
Scott_Helme_
8y ago
I expected less to be honest. The adult entertainment industry has been on a huge drive to encryption recently. It makes sense if you think about the content they serve, I guess people want more privacy there!
27.
▲
by
Scott_Helme_
8y ago
I'd really recommend watching the video in this blog post: https://www.troyhunt.com/heres-why-your-static-website-needs...
28.
▲
by
Scott_Helme_
8y ago
My guess would be that maybe sites have different infrastructure in different regions and maybe they aren't completely aligned on their progress. I really don't know why you'd intentionally have it like that.
29.
▲
by
Scott_Helme_
8y ago
It might also be useful to note I have a HSTS Cheat Sheet for more info: https://scotthelme.co.uk/hsts-cheat-sheet/
30.
▲
by
Scott_Helme_
8y ago
"Please put yourself in the shoes of someone actually operating a site." - I run 8 sites right now and one of them is processing 10,000,000,000+ requests a month. I speak from a position of experience on this topic. "Every si
More ›