Live data from Hacker News

Viewing profile — Scott_Helme_

Scott_Helme_

HN member
Joined
Sun, Aug 30, 2015, 9:56 PM UTC
HN karma
213
Public activity
82 items

About Scott_Helme_

Security Researcher, Entrepreneur and International Speaker.

Find me at:

https://scotthelme.co.uk https://report-uri.com

Recent public activity

  1. comment
    Comment #48656750

    No, it was more broad than just SE domains, but trying to detect whether a site is suitable for passkeys support automatically is quite the challenge. Some don't allow themselves t…

  2. comment
    Comment #48642277

    I'm not entirely sure that it does, which bit of passkeys are you concerned most with?

  3. comment
    Comment #48642272

    This is fixed now: https://whynopasskeys.com/country/se

  4. story
  5. comment
    Comment #48195900

    Interesting, could you link me to some of those sites so I can investigate?

  6. comment
    Comment #48194466

    I can kind of see it, but you can also just use an authenticator from any manufacturer, or have multiple types that you use? I'm just curious what I'm overlooking.

  7. comment
    Comment #48193237

    What's the concern with using passkeys?

  8. comment
    Comment #46608854

    I did try to make it clear in the article. We're powering 2 x EVs, have two adults working from home full time, I have a server rack under the stairs, and we have a hot tub outside…

  9. comment
    Comment #46608831

    Absolutely — tariff choice, storage, and automation make a huge difference. The article isn’t claiming this setup is universally optimal, just showing what’s possible when those pi…

  10. comment
    Comment #46608789

    We had an expensive solar install due to restrictions around our roof, so the solar would typically have been cheaper. Another consideration is that battery installations in the UK…

  11. comment
    Comment #46608702

    The only restriction placed on you is the export rate, which is provided to you by the DNO here in the UK. We had a limit of 3.8kW placed, which is programmed in to the batteries b…

  12. comment
    Comment #46608585

    Nah, there's no Bitcoin mining, honest!

  13. comment
    Comment #46608561

    How did you know about my laser?!

  14. comment
    Comment #28248433

    Thanks! Sometimes the simple tricks are the best ones :)

  15. comment
    Comment #28248428

    There is no reason to differentiate between free certificates and paid certificates. The process works in exactly the same way for either.

  16. comment
    Comment #28248401

    They're all 3 certificates long (leaf/intermediate/root) apart from Let's Encrypt which, due to their cross-signature, are 4 certificates long for ECC.

  17. comment
    Comment #28245749

    If you were to use the same private key for the 4 certificates then you could seamlessly switch between whichever leaf certificate you wanted to serve to the client. I'm not aware …

  18. comment
    Comment #28245730

    Let's Encrypt can issue from an ECC chain, I've tweeted[1] the details on how to enable your account for that. [1] https://twitter.com/Scott_Helme/status/1392101598852222976

  19. comment
    Comment #28245666

    If you get a 1 year certificate then yeah, but otherwise no. The requirement to re-validate the DNS record comes not from the CA or the use of ACME, but the Baseline Requirements[1…

  20. comment
    Comment #20690879

    That's not what I asked, that's a straw man. Browser vendors have tested the efficacy of the current EV indicator, resulting in the current action. If you feel that testing an alte…

  21. comment
    Comment #20689234

    But, didn't browser vendors do that and that's why the EV indicator is being moved to a less prominent location?..

  22. comment
    Comment #20684863

    As the organisations that stand to benefit financially from selling these indicators, perhaps it's CAs that should invest in the research? CAs seem to constantly point at the brows…

  23. story
  24. comment
    Comment #17604248

    The only way you could do that is on a hosted platform where they do maintenance for you. There's no way a server would last online for decades without being patched, it would have…

  25. comment
    Comment #17604237

    I expected less to be honest. The adult entertainment industry has been on a huge drive to encryption recently. It makes sense if you think about the content they serve, I guess pe…