Live data from Hacker News

Universal SSL

blog.cloudflare.com

11–20 of 250 posts

Re: Universal SSL

#11

This is excellent news - one question though - what would a user on XP see when he accesses one of these sites?

If Windows XP and Internet Explorer then they'll get a SSL error if visiting via HTTPS. Won't have a problem over HTTP.

Just a normal SSL error, or would they be able to see another site?

I had an issue like this with SNI where a client reported being able to see another site that was on the same IP. The issue was that she was using IE on Windows XP, and SNI didn't work.

Re: Universal SSL

#12
My website that is behind Cloudflare on the free plan, has suddenly started giving me an error in Google Chrome. The error is as follows:

     You cannot visit mysite.com right now because the website uses HSTS.  Network errors and attacks are usually temporary, so this page will probably work later.
The website has been running for over a year with no problems behind Cloudflare, so I'm assuming this new rollout is the cause. Anybody got any idea how long this will last?

Edit: Chrome 38.0.2125.77 on OS X 10.9.4

Re: Universal SSL

#13

Great initiative, minor drawbacks such as up to 20% of the traffic wouldn't apply due to their use of SNI: "Globally, more than 80% of requests come from modern browsers, and that percentage is growing quickly." EDIT: Mixed content on that page (within the embedded map at https://cloudflare.github.io/sni-visualization/ )

If your target audience is in the west, it's more like 5-10%, and the problem there is going away. XP and Android 2.x are dropping off pretty quickly.

Re: Universal SSL

#14

This'll be amazing for phishers and spear phishers - just use CloudFlare, and every user you're targeting will have the green padlock.

Tor will be amazing for child pornography and terrorists!

Come on, vertex-four, every single thing in the universe you do can be turned upside down. TV == violence, telephone == annoying calls, etc.

Please have a faith in humanity and give us some optimism. I'm sure SSL can be used for good as well!

Re: Universal SSL

#16
CloudFlare now has the most sophisticated MITM attack in the world, where they tell you what they are doing and make you sign up for it.

Does CloudFlare have a direct pipe to the NSA already, or is that only going to happen next week?

Re: Universal SSL

#17
post #4

This is great, but just two concerns. CloudFlare just generated itself certs for how many domains? And you don't really have a secure connection but the browser will report that you do.

CloudFlare doesn't act as the RA, they serve a validation file for the CA's bot to see before issuance.

Re: Universal SSL

#18
post #4

This is great, but just two concerns. CloudFlare just generated itself certs for how many domains? And you don't really have a secure connection but the browser will report that you do.

It sure reads as they genereated 2mio+ certs - that's probably why they thank GlobalSign and Comodo in the blog post.

I'm not sure how I should feel, if company x (where I am a registered but non-paying customer in their free tier) gets a cert in my name withouth asking before.

Re: Universal SSL

#19
Does cloudflare have the ability to issue certificates that are trusted by major browsers?

Or will the cloudflare issued certificates simply give users an untrusted CA warning?

Re: Universal SSL

#20
How can they automatically provision a certificate? Do they run or partner with a CA that doesn't require validation by the actual domain owner?

Edit: If so, then what little trust still existed in the HTTPS PKI CA space just went out the window.

Post reply on HN