Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
nickf
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
22 ms
·
1.
▲
by
nickf
3mo ago
Hanno - we may have communicated before some years ago, but am more than happy to offer any help I can (if some of our customers are/were affected, happy to reach out and see if they can give you more answers as to which products). nic
2.
▲
by
nickf
3mo ago
For any target of sufficient value that a government would do that, yes. Of course it doesn't happen anyway, because governments don't have some kind of secret access to CAs.
3.
▲
by
nickf
3mo ago
I would imagine, as a CA that issues only DV certs, they'd disallow issuance to various ccTLDs, and perhaps stop newAccount registrations with email addresses at those ccTLDs. That's about as much as they could do - IP-blocking by
4.
▲
by
nickf
3mo ago
ZeroSSL aren't an EU-based alternative, unfortunately.
5.
▲
by
nickf
4mo ago
If a cert doesn't contain the requisite number of valid SCTs from logs that are specifically usable in the browser - it will not work.
6.
▲
by
nickf
4mo ago
You’re right of course, but Apple won’t do it - they’re happily running a two-tier system where Uber, eBay, Doordash can force spam notifications on you with impunity. All my settings for marketing are off - eBay still sends me notification
7.
▲
by
nickf
6mo ago
While I sort-of see what you're trying to say, if you knew the groups and teams involved - you'd know there was no favouritism and a strong degree of separation between CA and root programs. The root programs who have their own CA
8.
▲
by
nickf
6mo ago
That's absolutely incorrect. While CABF sets the 'Baseline Requirements' that ultimately go into the WebTrust audit scheme that root programs use to accept roots into their trust stores...browsers can and do set their own rul
9.
▲
by
nickf
7mo ago
Your failure to see the problem doesn’t mean it doesn’t exist. 40x the size might not really be an issue for the hypothetical server you’ve suggested - but that isn’t the reality for the world. Many devices do HTTPS and TLS. Not to mention
10.
▲
by
nickf
7mo ago
Google dominate the space because they have an active, robust trust-store program that they manage well. Apple the same. Mozilla and Microsoft too (though to a lesser extent). If any ecosystem - such as XMPP - wishes to, they could start th
11.
▲
by
nickf
7mo ago
Not really, no. There are a number of reasons for cert lifetimes being made shorter.
12.
▲
by
nickf
7mo ago
A public CA checks it one-time, when it's being issued. Most/all mTLS use-cases don't do any checking of the client cert in any capacity. Worse still, some APIs (mainly for finance companies) require things like OV and EV, b
13.
▲
by
nickf
7mo ago
Eh, it's pretty easy to impersonate if the values in the certificate aren't checked, and you could get one from any of a list of public CAs. If you're relying on a certificate for authentication - issue it yourself.
14.
▲
by
nickf
7mo ago
Publicly-trusted client authentication does nothing. It's not a thing that should exist, or is needed.
15.
▲
by
nickf
7mo ago
Client authentication with publicly-trusted (i.e. chaining to roots in one of the major 4 or 5 trust-store programs) is bad. It doesn't actually authenticate anything at all, and never has. No-one that uses it is authenticating anythin
16.
▲
by
nickf
7mo ago
You are correct, and the answer is - no-one using publicly-trusted TLS certs for client authentication is actually doing any authentication. At best, they're verifying the other party has an internet connection and perhaps the ability
17.
▲
by
nickf
8mo ago
It’ll be 5 years soon.
18.
▲
by
nickf
9mo ago
I was mostly just typing out what they had listed under 'products' on their pages. I'm aware of what Mozilla do, know folks there and that have been there. They've been roundly criticised for adding 'products'
19.
▲
by
nickf
9mo ago
...which is arguably the problem. Firefox. Thunderbird. That should be it. According to their own site, beyond that they have the browser app for mobile devices. A VPN service, an email-forwarding service, and MDN. Hardly 'many product
20.
▲
by
nickf
9mo ago
There are ways to do this as pointed out below - CNAME all your domains to one target domain and make the changes there. There’s also a new DCV method that only needs a single, static record. Expect CA support widely in the coming weeks and
21.
▲
by
nickf
9mo ago
It might never 'touch' the internet, but the certificates can be easily automated. They don't have to be reachable on the internet, they don't have to have access to modify DNS - but if you want any machine in the world
22.
▲
by
nickf
9mo ago
Not quite true - some CAs were not 'held hostage' - some agree with the changes and supported them. See the endorsers for SC-081.
23.
▲
by
nickf
9mo ago
Honestly don't recall discussing 17 days, but I could be wrong. 47 days was a 'compromise' in that it's a step-down over a few years rather than a single big-bang event dropping from 397->90/47/less.
24.
▲
by
nickf
9mo ago
Can I ask - if you're using publicly-trusted TLS server certificates for client authentication...what are you actually authenticating? Just that someone has a certificate that can be chained back to a trust-anchor in a common trust-s
25.
▲
by
nickf
9mo ago
Sure, but in those examples - automation and short-lifetime certs are totally possible.
26.
▲
by
nickf
9mo ago
Chrome root policy, and likely other root policies are moving toward 5-years rotation of the roots, and annual rotation of issuing CAs. Cross-signing works fine for root rotation in most cases, unless you use IIS, then it becomes a fun pro
27.
▲
by
nickf
9mo ago
Where did you get 17 days from?
28.
▲
by
nickf
9mo ago
If it doesn’t run a web service, or isn’t publicly routable - why do you need it to work on billions of users browsers and devices around the world?
29.
▲
by
nickf
9mo ago
You assume it’s just the certs being purchased - and not support, SLAs, other related products, management platforms, private PKI and more. If all you do is public TLS, sure, that might be an issue.
30.
▲
by
nickf
9mo ago
Roots for all CAs are going to be rotating much more frequently now. Looking to be every 5 years.
More ›