Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
phasmantistes
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
1.
▲
by
phasmantistes
2mo ago
The issue with saying that "there's a 60/40 split, therefore there's no consensus" is that the IETF explicitly documents that that isn't the case: RFC 7282, Section 7, "Five people for and one hundred peop
2.
▲
by
phasmantistes
2mo ago
Sure, you make a good point. I certainly didn't expect to end up at the top of this thread, and stopped paying attention immediately after posting it (for the same reason I don't read every message on the TLS WG list). The kindest
3.
▲
by
phasmantistes
2mo ago
Zero percent LLM-generated, but this is the first time I've had to defend myself against that claim, so thanks for that!
4.
▲
by
phasmantistes
3mo ago
This is not an unbiased article about the situation unfolding on the TLS Working Group mailing list; this is a call to action to join one specific side of the argument that has been ongoing for over a year now. It's an appeal to author
5.
▲
by
phasmantistes
4mo ago
Our code for sending stuff to CT logs is fully open source. But that's the tiniest slice of our compliance regime -- the vast majority of it is things like audit logging certain events, preserving audit logs in specific ways for certai
6.
▲
by
phasmantistes
9mo ago
Yep, the "shortlived" (6-day) profile will be available to the general public later this week. But at this time we explicitly encourage only mature organizations with stable infrastructure and an oncall rotation to adopt that prof
7.
▲
by
phasmantistes
9mo ago
Honest reply: because the infrastructure isn't ready to support 1-day certificates yet. If your cert is only valid for one day, and renewal fails on a Saturday, then your site is unusable until you get back to work on Monday and do som
8.
▲
by
phasmantistes
9mo ago
FWIW, we're acutely aware of the operational risks of super short lifetimes and frequent renewals. That's why our `shortlived` profile is clearly documented as only being appropriate for orgs that have high operational maturity
9.
▲
by
phasmantistes
9mo ago
Yep! Should be available to the general public (as long as you're using an ACME client that can be configured to request a specific profile) later this week.
10.
▲
by
phasmantistes
9mo ago
It's a good question! I know that our first root (ISRG Root X1) used that naming scheme simply because it was cross-signed by IdenTrust's root (DST Root CA X3) which used that same scheme. But where they got the scheme from, I don
11.
▲
by
phasmantistes
10mo ago
Certificates that look like renewals -- for the same set of names, from the same account -- are exempt from rate limits. This means that renewing (for example) every 30 days instead of every 60 days will not cost any rate limit tokens or re
12.
▲
by
phasmantistes
10mo ago
Organizations with many frontends/loadbalancers all serving the same site tend to adopt one of four solutions: - Have one node with its own ACME account. It controls key generation and certificate renewal, and then the new key+cert is
13.
▲
by
phasmantistes
10mo ago
"CT Logs" are Certificate Transparency Logs, which are cryptographically provable append-only data structures hosted by trusted operators. Every certificate issued is publicly logged in two or more CT Logs, so that browsers can en
14.
▲
by
phasmantistes
10mo ago
Please don't suggest pinning a publicly-trusted intermediate. The CA may change which intermediate they're using at any time for any reason with no warning, and then the app which pinned that intermediate is hosed.
15.
▲
by
phasmantistes
10mo ago
(Disclaimer: I am tech lead of Let's Encrypt software engineering) I'm also concerned about LE being a single point of failure for the internet! I really wish there were other free and open CAs out there. Our goal is to encrypt th
16.
▲
by
phasmantistes
1y ago
That's not leverage that a CA can use. If half the internet suddenly displays TLS warning interstitials, it doesn't make people mad at the CA, and it doesn't make people mad at their browser: it just _trains them to ignore su
17.
▲
by
phasmantistes
1y ago
The "tlsclient" profile will not be TLSClientAuth-only: it will have both the TLSServerAuth and TLSClientAuth profiles, like the default profile does today. It will exist solely for the purpose of helping people transition off of
18.
▲
by
phasmantistes
2y ago
This is exactly why the LE IP certs will be limited to 6 days: this exact attack is possible today against any IP address cert, and such certs in general are allowed to have lifetimes up to 398 days. LE isn't comfortable with that situ
19.
▲
by
phasmantistes
2y ago
For what it's worth, the person you're replying to is the founder and executive director of Let's Encrypt, the non-profit free and open CA which decidedly isn't a money-printing machine.
20.
▲
by
phasmantistes
2y ago
CAs need to know every certificate they've issued so that a) if they receive a request to revoke that certificate, they can actually do so; and b) if they need to revoke all of their certs (e.g. due to discovering a validation proces
21.
▲
by
phasmantistes
2y ago
Not all subscribers provide email addresses through which they could be informed of a revocation.
22.
▲
by
phasmantistes
2y ago
Nothing will change for you, and nothing will break. The point of this post is to give a maximum-lead-time heads-up to the folks who _do_ need to care (the folks writing revocation-checking code in clients) so that later, more specific anno
23.
▲
by
phasmantistes
2y ago
I believe they are using "certbot" to mean "Let's Encrypt", in which case their advice is sound -- if you truly have to pin a key, pin your own end-entity cert's key, not the CA's key.
24.
▲
by
phasmantistes
2y ago
It's specifically to discourage intermediate key pinning. If folks want to pin their own end-entity public key (and always re-use the same key when renewing their cert), go for it -- dealing with compromise of their own key is their
25.
▲
by
phasmantistes
3y ago
I'm super excited about Sunlight. The CT ecosystem is really fragile right now, with current log implemetations being expensive to operate and very difficult to operate correctly, as evidenced by the recent failures of multiple logs[1]
26.
▲
by
phasmantistes
3y ago
I'm super excited about Sunlight. The CT ecosystem is really fragile right now, with current log implemetations being expensive to operate and very difficult to operate correctly, as evidenced by the recent failures of multiple logs[1]
27.
▲
by
phasmantistes
3y ago
Fundamentally, the whole issue with eIDAS comes down to one thing: you cannot mandate trust. If it's mandated, it isn't trust. It's something else. By mandating that browsers "trust" certain CAs, they're breaki
28.
▲
by
phasmantistes
3y ago
Unfortunately this isn't how it works in practice. Changes to server certificates happen all the time -- every 60 days or so, if you're getting certs from Let's Encrypt. Browsers can't tell their users every time a certi
29.
▲
by
phasmantistes
3y ago
I don't think "classified" is the right word, but they haven't been published. They were leaked to various third parties, who got them to Mozilla / EFF / the other folks writing letters of protest today. Those
30.
▲
by
phasmantistes
4y ago
It's because it's not just a Let's Encrypt end-of-year message: it's an ISRG (Internet Security Research Group) end-of-year message. ISRG runs multiple projects, including both Let's Encrypt and Prossimo. Prossimo i
More ›