Live data from Hacker News

Viewing profile — nickf

nickf

HN member
Joined
Fri, Aug 15, 2008, 8:25 PM UTC
HN karma
314
Public activity
161 items

About nickf

Basic constraints. Long-time PKI-botherer.

If you want to email me, use: nick (-at-) nickf (-dot-) net

Recent public activity

  1. comment
    Comment #48553591

    Hanno - we may have communicated before some years ago, but am more than happy to offer any help I can (if some of our customers are/were affected, happy to reach out and see if th…

  2. comment
    Comment #48467833

    For any target of sufficient value that a government would do that, yes. Of course it doesn't happen anyway, because governments don't have some kind of secret access to CAs.

  3. comment
    Comment #48459918

    I would imagine, as a CA that issues only DV certs, they'd disallow issuance to various ccTLDs, and perhaps stop newAccount registrations with email addresses at those ccTLDs. That…

  4. comment
    Comment #48457763

    ZeroSSL aren't an EU-based alternative, unfortunately.

  5. comment
    Comment #48354532

    If a cert doesn't contain the requisite number of valid SCTs from logs that are specifically usable in the browser - it will not work.

  6. comment
    Comment #48300619

    You’re right of course, but Apple won’t do it - they’re happily running a two-tier system where Uber, eBay, Doordash can force spam notifications on you with impunity. All my setti…

  7. comment
    Comment #47358698

    While I sort-of see what you're trying to say, if you knew the groups and teams involved - you'd know there was no favouritism and a strong degree of separation between CA and root…

  8. comment
    Comment #47358679

    That's absolutely incorrect. While CABF sets the 'Baseline Requirements' that ultimately go into the WebTrust audit scheme that root programs use to accept roots into their trust s…

  9. comment
    Comment #47210511

    Your failure to see the problem doesn’t mean it doesn’t exist. 40x the size might not really be an issue for the hypothetical server you’ve suggested - but that isn’t the reality f…

  10. comment
    Comment #46961362

    Google dominate the space because they have an active, robust trust-store program that they manage well. Apple the same. Mozilla and Microsoft too (though to a lesser extent). If a…

  11. comment
    Comment #46958980

    Not really, no. There are a number of reasons for cert lifetimes being made shorter.

  12. comment
    Comment #46952944

    A public CA checks it one-time, when it's being issued. Most/all mTLS use-cases don't do any checking of the client cert in any capacity. Worse still, some APIs (mainly for finance…

  13. comment
    Comment #46952741

    Eh, it's pretty easy to impersonate if the values in the certificate aren't checked, and you could get one from any of a list of public CAs. If you're relying on a certificate for …

  14. comment
    Comment #46952659

    Publicly-trusted client authentication does nothing. It's not a thing that should exist, or is needed.

  15. comment
    Comment #46952644

    Client authentication with publicly-trusted (i.e. chaining to roots in one of the major 4 or 5 trust-store programs) is bad. It doesn't actually authenticate anything at all, and n…

  16. comment
    Comment #46952599

    You are correct, and the answer is - no-one using publicly-trusted TLS certs for client authentication is actually doing any authentication. At best, they're verifying the other pa…

  17. comment
    Comment #46662746

    It’ll be 5 years soon.

  18. comment
    Comment #46323903

    I was mostly just typing out what they had listed under 'products' on their pages. I'm aware of what Mozilla do, know folks there and that have been there. They've been roundly cri…

  19. comment
    Comment #46310057

    ...which is arguably the problem. Firefox. Thunderbird. That should be it. According to their own site, beyond that they have the browser app for mobile devices. A VPN service, an …

  20. comment
    Comment #46290814

    There are ways to do this as pointed out below - CNAME all your domains to one target domain and make the changes there. There’s also a new DCV method that only needs a single, sta…

  21. comment
    Comment #46287360

    It might never 'touch' the internet, but the certificates can be easily automated. They don't have to be reachable on the internet, they don't have to have access to modify DNS - b…

  22. comment
    Comment #46286299

    Not quite true - some CAs were not 'held hostage' - some agree with the changes and supported them. See the endorsers for SC-081.

  23. comment
    Comment #46286256

    Honestly don't recall discussing 17 days, but I could be wrong. 47 days was a 'compromise' in that it's a step-down over a few years rather than a single big-bang event dropping fr…

  24. comment
    Comment #46286250

    Can I ask - if you're using publicly-trusted TLS server certificates for client authentication...what are you actually authenticating? Just that someone has a certificate that can …

  25. comment
    Comment #46286183

    Sure, but in those examples - automation and short-lifetime certs are totally possible.