Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
toddgardner
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
1.
▲
by
toddgardner
21d ago
Yikes, not a good look when everyone needs to be automating certificate renewal.
2.
▲
by
toddgardner
3mo ago
OP Here. What you fail to grasp is that there are multiple sizes of IT organizations on this planet. The vast majority of them have less than 10 total admins. For them, they could not build and maintain an internal PKI thats as secure or as
3.
▲
by
toddgardner
6mo ago
Nice rewrite. The SAN support is the right call, a lot of older generators trip on that. One thing worth knowing if you're using this for internal services: generating the cert is the easy part. Getting the CA cert into the trust store
4.
▲
by
toddgardner
6mo ago
I am talking to so many mid-sized IT shops that still have lots of legacy on-prem windows systems or specialty software where Certbot or ACME renewals is hard. This sort of thing gets dismissed as "just use certbot" in threads lik
5.
▲
by
toddgardner
7mo ago
If you never want this to happen again to your systems, we’re building a tool that bakes monitoring and validation into automatic cert renewals. < https://www.certkit.io/ >
6.
▲
by
toddgardner
9mo ago
> What is the problem with stale certificates if a domain changes hands? The previous owners have valid certificates for up to 398 days. If they are a malicious party cable of doing a man-in-the-middle attack, they can present a valid ce
7.
▲
by
toddgardner
9mo ago
For all the folks worried about how hard automation is going to be, this is what my team and I have been working on for the past year: https://www.certkit.io/certificate-management You CNAME the acme challenge DNS to us, we
8.
▲
by
toddgardner
9mo ago
It's not really a stupid problem, its the BygoneSSL problem: https://www.certkit.io/blog/bygonessl-and-the-certificate-th...
9.
▲
by
toddgardner
9mo ago
Man, I agree. The whole thing sucks so much. We started building a centralized way to do this internally last year to get better visibility into renewals and expirations: We're doing a beta of it for some other groups now. https:/
10.
▲
by
toddgardner
9mo ago
It's more complicated than that. Apple (along with Google and Mozilla) basically held the CA's hostage. They started unilaterally reducing lifetimes. It was happening whether the CAB approved it or not. The vote was more about whe
11.
▲
by
toddgardner
9mo ago
If you want to learn more about Certificate Transparency Logs, how to pull and search them, we just did a 3 part series about how we did this at CertKit: https://www.certkit.io/blog/searching-ct-logs
12.
▲
Perfect Forward Secrecy Made Private Keys Boring
(certkit.io)
2 points
by
toddgardner
9mo ago
|
0 comments
13.
▲
by
toddgardner
10mo ago
Does anyone read articles before commenting? lol
14.
▲
by
toddgardner
10mo ago
Yea totally. this is a balance. Very few times should you manage the actual hardware yourself. But often a cloud is overly complex for what you need. 10 years ago we left MS Azure and started leasing dedicated hardware in OVH. Our costs wer
15.
▲
by
toddgardner
10mo ago
I tend to sell to a wide variety of customers. They tend not to give a crap if a cloud provider is down, its still our problem to make it right.
16.
▲
by
toddgardner
10mo ago
Yea agreed. I don't build my own CDNs. But I don't choose cloudflare either, because its too complicated and I don't need that. So I choose the simplest possible thing with as little complexity as possible (for me, that was B
17.
▲
by
toddgardner
10mo ago
wow, yea. that's foolish. Fixing.
18.
▲
by
toddgardner
10mo ago
How you approach this is very different depending on the size of organization. We're a small shop (3), but we deliver big services to lots of people. We do this by owning everything we can, and using simple vendors for what we can'
19.
▲
by
toddgardner
10mo ago
An alternative to multiple providers is to use commoditized providers. By using simple infrastructure rather than cloud platforms, I can redploy my infrastructure using ansible with another provider in hours rather than re-building my platf
20.
▲
Build vs. Buy: What This Week's Outages Should Teach You
(toddhgardner.com)
49 points
by
toddgardner
10mo ago
|
43 comments
21.
▲
The 47-Day Certificate Ultimatum: How Browsers Broke the CA Cartel
(certkit.io)
12 points
by
toddgardner
1y ago
|
2 comments
22.
▲
by
toddgardner
1y ago
For twenty years, Certificate Authorities ran the perfect protection racket. Then SHA-1 got shattered, Apple went rogue, and certificates went from lasting 3 years to 47 days. This is the story of how browsers broke the CA cartel, and why y
23.
▲
Fixing Cumulative Layout Shift Problems on DavidWalshBlog
(davidwalsh.name)
2 points
by
toddgardner
3y ago
|
0 comments
24.
▲
by
toddgardner
3y ago
Hey Hackernews! Todd the author here. Thanks for reading and sharing.
25.
▲
by
toddgardner
3y ago
We (request metrics, author) are also using clickhouse. But we go beyond analytics to integrate performance, security, api monitoring, and errors under a single interface. We think of it as “client side observability”.
26.
▲
by
toddgardner
3y ago
Request Metrics, obviously! https://requestmetrics.com
27.
▲
by
toddgardner
3y ago
Put Request Metrics on your list to credit the post :)
28.
▲
by
toddgardner
3y ago
Author here. Clearly Request Metrics should make it on your list ;)
29.
▲
by
toddgardner
5y ago
Request Metrics is not an advertiser, does not track individuals, and complies with the EFF dnt policy. Ad block lists are way too aggressive--all it takes is some random person to put you on the list and it's hard to get off of it.
30.
▲
by
toddgardner
6y ago
We wrote this in response to a HN request in our previous audit of Google Search: https://news.ycombinator.com/item?id=24482344
More ›