Viewing profile — nickf
nickf
HN member- Joined
- Fri, Aug 15, 2008, 8:25 PM UTC
- HN karma
- 314
- Public activity
- 161 items
- HN profile
- View on Hacker News ↗
About nickf
If you want to email me, use: nick (-at-) nickf (-dot-) net
Recent public activity
-
comment
Comment #48553591
Hanno - we may have communicated before some years ago, but am more than happy to offer any help I can (if some of our customers are/were affected, happy to reach out and see if th…
-
comment
Comment #48467833
For any target of sufficient value that a government would do that, yes. Of course it doesn't happen anyway, because governments don't have some kind of secret access to CAs.
-
comment
Comment #48459918
I would imagine, as a CA that issues only DV certs, they'd disallow issuance to various ccTLDs, and perhaps stop newAccount registrations with email addresses at those ccTLDs. That…
-
comment
Comment #48457763
ZeroSSL aren't an EU-based alternative, unfortunately.
-
comment
Comment #48354532
If a cert doesn't contain the requisite number of valid SCTs from logs that are specifically usable in the browser - it will not work.
-
comment
Comment #48300619
You’re right of course, but Apple won’t do it - they’re happily running a two-tier system where Uber, eBay, Doordash can force spam notifications on you with impunity. All my setti…
-
comment
Comment #47358698
While I sort-of see what you're trying to say, if you knew the groups and teams involved - you'd know there was no favouritism and a strong degree of separation between CA and root…
-
comment
Comment #47358679
That's absolutely incorrect. While CABF sets the 'Baseline Requirements' that ultimately go into the WebTrust audit scheme that root programs use to accept roots into their trust s…
-
comment
Comment #47210511
Your failure to see the problem doesn’t mean it doesn’t exist. 40x the size might not really be an issue for the hypothetical server you’ve suggested - but that isn’t the reality f…
-
comment
Comment #46961362
Google dominate the space because they have an active, robust trust-store program that they manage well. Apple the same. Mozilla and Microsoft too (though to a lesser extent). If a…
-
comment
Comment #46958980
Not really, no. There are a number of reasons for cert lifetimes being made shorter.
-
comment
Comment #46952944
A public CA checks it one-time, when it's being issued. Most/all mTLS use-cases don't do any checking of the client cert in any capacity. Worse still, some APIs (mainly for finance…
-
comment
Comment #46952741
Eh, it's pretty easy to impersonate if the values in the certificate aren't checked, and you could get one from any of a list of public CAs. If you're relying on a certificate for …
-
comment
Comment #46952659
Publicly-trusted client authentication does nothing. It's not a thing that should exist, or is needed.
-
comment
Comment #46952644
Client authentication with publicly-trusted (i.e. chaining to roots in one of the major 4 or 5 trust-store programs) is bad. It doesn't actually authenticate anything at all, and n…
-
comment
Comment #46952599
You are correct, and the answer is - no-one using publicly-trusted TLS certs for client authentication is actually doing any authentication. At best, they're verifying the other pa…
-
comment
Comment #46662746
It’ll be 5 years soon.
-
comment
Comment #46323903
I was mostly just typing out what they had listed under 'products' on their pages. I'm aware of what Mozilla do, know folks there and that have been there. They've been roundly cri…
-
comment
Comment #46310057
...which is arguably the problem. Firefox. Thunderbird. That should be it. According to their own site, beyond that they have the browser app for mobile devices. A VPN service, an …
-
comment
Comment #46290814
There are ways to do this as pointed out below - CNAME all your domains to one target domain and make the changes there. There’s also a new DCV method that only needs a single, sta…
-
comment
Comment #46287360
It might never 'touch' the internet, but the certificates can be easily automated. They don't have to be reachable on the internet, they don't have to have access to modify DNS - b…
-
comment
Comment #46286299
Not quite true - some CAs were not 'held hostage' - some agree with the changes and supported them. See the endorsers for SC-081.
-
comment
Comment #46286256
Honestly don't recall discussing 17 days, but I could be wrong. 47 days was a 'compromise' in that it's a step-down over a few years rather than a single big-bang event dropping fr…
-
comment
Comment #46286250
Can I ask - if you're using publicly-trusted TLS server certificates for client authentication...what are you actually authenticating? Just that someone has a certificate that can …
-
comment
Comment #46286183
Sure, but in those examples - automation and short-lifetime certs are totally possible.