Live data from Hacker News

Viewing profile — rmhrisk

rmhrisk

HN member
Joined
Thu, Nov 29, 2012, 9:25 PM UTC
HN karma
121
Public activity
54 items

About rmhrisk

[ my public key: https://keybase.io/rmhrisk; my proof: https://keybase.io/rmhrisk/sigs/QgT79a4qutJ477eR5cf2ZdpYH6kJ3Jv2i8lOyeuZ1rg ]

Recent public activity

  1. comment
    Comment #39281815

    If a root/admin user installs a root there is no prompt, if a user does, it is scoped to the individual user profile and a prompt is displayed. No prompt as root would be meaningfu…

  2. comment
    Comment #31001955

    With the recent GCP Cloud Certificate Manager release the global propagation time is minutes. (I should note I was a PM for this feature)

  3. comment
    Comment #31001804

    No, GCP has had arguably a superior TLS story for years. For example they do managed TLS for their workloads like AWS but they operate their own CA rather than outsourcing to Digic…

  4. comment
    Comment #31001645

    There is no origin limitation. It works on premise or cross cloud.

  5. story
  6. comment
    Comment #15069871

    We hear you, while I can't speak to future products and features I can say we understand there is room to improve the SSL provisioning and lifecycle management story in our product…

  7. story
  8. story
  9. story
  10. story
  11. comment
    Comment #13497544

    That is effectively how both the Mozilla and Microsoft programs root store programs works.

  12. comment
    Comment #13496646

    Some PKI-related services can not, due to user agent behaviors and, do SSL, for example, consider OCSP; if to fetch an OCSP request you need to do an SSL connection and the library…

  13. comment
    Comment #13496634

    Disclosure: I am the author of that post and Product Manager for this project as well as other related work like Certificate Transparency and Key Transparency. While I can not say …

  14. comment
    Comment #13496622

    https://www.amazontrust.com

  15. comment
    Comment #13495865

    Google has announced an effort to move all CAs to Certificate Transparency, here is a Threatpost piece on the topic - https://threatpost.com/google-to-make-certificate-transparen..…

  16. comment
    Comment #13495807

    It's actually quite common, another example is Amazon who operates its own root for its SSL certificate needs. Additionally, there is minimal risk profile differences to an unconst…

  17. comment
    Comment #13495782

    There are numerous, Microsoft has its own subordinate CA that they operate for their own certificates. Amazon has its own root CA https://www.amazontrust.com/repository/ . There ar…

  18. comment
    Comment #13386629

    This article from TechCrunch does a good job explaining Key Transparency - https://techcrunch.com/2017/01/12/googles-key-transparency-p...

  19. comment
    Comment #13385815

    No. First, like CT you want an ecosystem of logs. Second, you have caching and in-band exchanges as means to mitigate some of that.

  20. comment
    Comment #13385648

    To understand the technical approach to the solution this is a good resource - https://github.com/google/key-transparency/blob/master/docs/... This is also useful for understanding…

  21. comment
    Comment #13385569

    One of the differences between Key Transparency and other solutions is the role of certifying and logging have been separated. In other words, being in the directory does not mean …

  22. comment
    Comment #13385548

    Is this something more than a public key server? Unlike a simple public key server, this provides privacy protecting elements. The project utilizes Zero Knowlege Proofs (ZKP) to li…

  23. story
  24. story
  25. story