Live data from Hacker News

Viewing profile — yup_sto

yup_sto

HN member
Joined
Sun, Sep 08, 2024, 4:10 AM UTC
HN karma
5
Public activity
12 items

About yup_sto

No profile information was provided.

Recent public activity

  1. comment
  2. comment
    Comment #42325067

    You're likely right here, combining two trust systems does add complexity without solving the core problem. While browsers requiring CT was a great step forward, it's surprisingly …

  3. comment
    Comment #42324750

    I know this is an oversimplification, but if the main issue is the single point of failure (centralized trust), wouldn’t a potential solution be to layer independent verification m…

  4. comment
    Comment #42322291

    Baader-Meinhof strikes again - checked this out in the morning and just caught your Citibike tweet. You're on a roll today!

  5. comment
  6. comment
  7. comment
    Comment #41478883

    Ahhhh, that tracks, cheers mate.

  8. comment
    Comment #41478812

    Exhaustive/Robust is the way for sure. Minimizing storage was a priority for me since it's just a small side-project/automation. I've looked for information on what the hell the `f…

  9. comment
    Comment #41478741

    I also noticed you are ingesting/storing flowers-to-the-world.com certs, not sure what stage of optimization you are at but blacklisting/ignoring these certs in my ingestion pipeli…

  10. comment
    Comment #41478660

    Awesome, I will keep my eye on this for sure, I've spent the past few months tinkering with ingesting CT logs for bug bounty automation. Curious if you're running your own CertStre…

  11. comment
    Comment #41478255

    Have you considered adding a monitoring feature where a user can enter a domain to be monitored and then be notified if a "similar" domain comes across the ingestion pipeline. This…

  12. comment
    Comment #41478199

    I'd imagine it's a combination of - CT log monitoring ( https://github.com/CaliDog/CertStream-Server ) - Mass-Scanning across ipv4 on 80/443 at the least? - Brute-forcing subdomain…