Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
yup_sto
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
yup_sto
2y ago
You're likely right here, combining two trust systems does add complexity without solving the core problem. While browsers requiring CT was a great step forward, it's surprisingly under-utilized by orgs. I wonder if this is due to
2.
▲
by
yup_sto
2y ago
I know this is an oversimplification, but if the main issue is the single point of failure (centralized trust), wouldn’t a potential solution be to layer independent verification mechanisms on top of the current system? For example, a secon
3.
▲
by
yup_sto
2y ago
Baader-Meinhof strikes again - checked this out in the morning and just caught your Citibike tweet. You're on a roll today!
4.
▲
by
yup_sto
2y ago
Ahhhh, that tracks, cheers mate.
5.
▲
by
yup_sto
2y ago
Exhaustive/Robust is the way for sure. Minimizing storage was a priority for me since it's just a small side-project/automation. I've looked for information on what the hell the `flowers-to-the-world` entries are that po
6.
▲
by
yup_sto
2y ago
I also noticed you are ingesting/storing flowers-to-the-world.com certs, not sure what stage of optimization you are at but blacklisting/ignoring these certs in my ingestion pipeline helped with avoiding storing unnecessary data I
7.
▲
by
yup_sto
2y ago
Awesome, I will keep my eye on this for sure, I've spent the past few months tinkering with ingesting CT logs for bug bounty automation. Curious if you're running your own CertStream server, or just continuously polling known CT l
8.
▲
by
yup_sto
2y ago
Have you considered adding a monitoring feature where a user can enter a domain to be monitored and then be notified if a "similar" domain comes across the ingestion pipeline. This would be useful for early detection of potential
9.
▲
by
yup_sto
2y ago
I'd imagine it's a combination of - CT log monitoring ( https://github.com/CaliDog/CertStream-Server ) - Mass-Scanning across ipv4 on 80/443 at the least? - Brute-forcing subdomains on wildcards with large