Viewing profile — yup_sto
yup_sto
HN member- Joined
- Sun, Sep 08, 2024, 4:10 AM UTC
- HN karma
- 5
- Public activity
- 12 items
- HN profile
- View on Hacker News ↗
About yup_sto
No profile information was provided.
Recent public activity
- comment
-
comment
Comment #42325067
You're likely right here, combining two trust systems does add complexity without solving the core problem. While browsers requiring CT was a great step forward, it's surprisingly …
-
comment
Comment #42324750
I know this is an oversimplification, but if the main issue is the single point of failure (centralized trust), wouldn’t a potential solution be to layer independent verification m…
-
comment
Comment #42322291
Baader-Meinhof strikes again - checked this out in the morning and just caught your Citibike tweet. You're on a roll today!
-
comment
Comment #41481917
[dead]
-
comment
Comment #41481575
[dead]
-
comment
Comment #41478883
Ahhhh, that tracks, cheers mate.
-
comment
Comment #41478812
Exhaustive/Robust is the way for sure. Minimizing storage was a priority for me since it's just a small side-project/automation. I've looked for information on what the hell the `f…
-
comment
Comment #41478741
I also noticed you are ingesting/storing flowers-to-the-world.com certs, not sure what stage of optimization you are at but blacklisting/ignoring these certs in my ingestion pipeli…
-
comment
Comment #41478660
Awesome, I will keep my eye on this for sure, I've spent the past few months tinkering with ingesting CT logs for bug bounty automation. Curious if you're running your own CertStre…
-
comment
Comment #41478255
Have you considered adding a monitoring feature where a user can enter a domain to be monitored and then be notified if a "similar" domain comes across the ingestion pipeline. This…
-
comment
Comment #41478199
I'd imagine it's a combination of - CT log monitoring ( https://github.com/CaliDog/CertStream-Server ) - Mass-Scanning across ipv4 on 80/443 at the least? - Brute-forcing subdomain…