Viewing profile — rmhrisk
rmhrisk
HN member- Joined
- Thu, Nov 29, 2012, 9:25 PM UTC
- HN karma
- 121
- Public activity
- 54 items
- HN profile
- View on Hacker News ↗
About rmhrisk
Recent public activity
-
comment
Comment #39281815
If a root/admin user installs a root there is no prompt, if a user does, it is scoped to the individual user profile and a prompt is displayed. No prompt as root would be meaningfu…
-
comment
Comment #31001955
With the recent GCP Cloud Certificate Manager release the global propagation time is minutes. (I should note I was a PM for this feature)
-
comment
Comment #31001804
No, GCP has had arguably a superior TLS story for years. For example they do managed TLS for their workloads like AWS but they operate their own CA rather than outsourcing to Digic…
-
comment
Comment #31001645
There is no origin limitation. It works on premise or cross cloud.
- story
-
comment
Comment #15069871
We hear you, while I can't speak to future products and features I can say we understand there is room to improve the SSL provisioning and lifecycle management story in our product…
- story
- story
- story
- story
-
comment
Comment #13497544
That is effectively how both the Mozilla and Microsoft programs root store programs works.
-
comment
Comment #13496646
Some PKI-related services can not, due to user agent behaviors and, do SSL, for example, consider OCSP; if to fetch an OCSP request you need to do an SSL connection and the library…
-
comment
Comment #13496634
Disclosure: I am the author of that post and Product Manager for this project as well as other related work like Certificate Transparency and Key Transparency. While I can not say …
-
comment
Comment #13496622
https://www.amazontrust.com
-
comment
Comment #13495865
Google has announced an effort to move all CAs to Certificate Transparency, here is a Threatpost piece on the topic - https://threatpost.com/google-to-make-certificate-transparen..…
-
comment
Comment #13495807
It's actually quite common, another example is Amazon who operates its own root for its SSL certificate needs. Additionally, there is minimal risk profile differences to an unconst…
-
comment
Comment #13495782
There are numerous, Microsoft has its own subordinate CA that they operate for their own certificates. Amazon has its own root CA https://www.amazontrust.com/repository/ . There ar…
-
comment
Comment #13386629
This article from TechCrunch does a good job explaining Key Transparency - https://techcrunch.com/2017/01/12/googles-key-transparency-p...
-
comment
Comment #13385815
No. First, like CT you want an ecosystem of logs. Second, you have caching and in-band exchanges as means to mitigate some of that.
-
comment
Comment #13385648
To understand the technical approach to the solution this is a good resource - https://github.com/google/key-transparency/blob/master/docs/... This is also useful for understanding…
-
comment
Comment #13385569
One of the differences between Key Transparency and other solutions is the role of certifying and logging have been separated. In other words, being in the directory does not mean …
-
comment
Comment #13385548
Is this something more than a public key server? Unlike a simple public key server, this provides privacy protecting elements. The project utilizes Zero Knowlege Proofs (ZKP) to li…
- story
- story
- story