Live data from Hacker News

Universal SSL

blog.cloudflare.com

101–110 of 250 posts

Re: Universal SSL

#101

Earlier quoted context omitted.

No, I don't think that exists at least in the CA/B Baseline. You have to have consent, obviously, but that's obtained when you sign up for CloudFlare.

Consent yes, though I can't fully parse "procedures established by". What procedures are meant here? https://cabforum.org/wp-content/uploads/Baseline_Requirement... "The CA MUST ensure that the certificate is issued with the consent of, and according to procedures established by, the owner of each Domain Name" EDIT: Here are the established authorization procedures: "11.1.1 Authorization by Domain Name Registrant For…

[deleted]

Re: Universal SSL

#102

Earlier quoted context omitted.

No, I don't think that exists at least in the CA/B Baseline. You have to have consent, obviously, but that's obtained when you sign up for CloudFlare.

Consent yes, though I can't fully parse "procedures established by". What procedures are meant here? https://cabforum.org/wp-content/uploads/Baseline_Requirement... "The CA MUST ensure that the certificate is issued with the consent of, and according to procedures established by, the owner of each Domain Name" EDIT: Here are the established authorization procedures: "11.1.1 Authorization by Domain Name Registrant For…

> Having the Applicant demonstrate practical control over the FQDN by making an agreed-upon change to information found on an online Web page identified by a uniform resource identifier containing the FQDN

CloudFlare arguably has the consent of the domain holder (gray area but probably in CF's favor) and can pass the required validation.

I do partially agree that the domain holder (CloudFlare's customer) should have been sent an opt-in email, but I think the positives outweigh the negatives.

Re: Universal SSL

#103
post #78

First, let me say that the aggressive approach to actually making encryption happen that CloudFlare has been pushing recently is very commendable. The hard part about finally retiring the old plaintext protocols we currently are stuck with is critical mass - nobody sees the point when plaintext seems to "work just fine". The various steps CloudFlare has taken to encourage SSL will go a long way towards reversing that…

It seems to me that CloudFlare is positioning themselves as another Google or Facebook, where a key feature of their business is that they get to track the web history of a large portion of internet users. CloudFlare's business model is not offering a free service and figure out how to make money. It's getting people to pay us money and those people are our actual customers who run web sites: https://www.cloudflare.c…

[deleted]

Re: Universal SSL

#105
post #78

First, let me say that the aggressive approach to actually making encryption happen that CloudFlare has been pushing recently is very commendable. The hard part about finally retiring the old plaintext protocols we currently are stuck with is critical mass - nobody sees the point when plaintext seems to "work just fine". The various steps CloudFlare has taken to encourage SSL will go a long way towards reversing that…

It seems to me that CloudFlare is positioning themselves as another Google or Facebook, where a key feature of their business is that they get to track the web history of a large portion of internet users. CloudFlare's business model is not offering a free service and figure out how to make money. It's getting people to pay us money and those people are our actual customers who run web sites: https://www.cloudflare.c…

Do they have a Zero Knowledge policy or anything close to it, though? It doesn't matter if they don't make money from it, if they still collect all the data.

I don't know how a service that's meant to cache data is supposed to be "zero knowledge", but hopefully they can do something about that - until it's too late and authorities already have a 1,000 requests lined up for their data.

Re: Universal SSL

#106
Enabled this, but when visiting website over https have error. "You attempted to reach YYYY, but instead you actually reached a server identifying itself as ssl2000.cloudflare.com. This may be caused by a misconfiguration on the server or by something more serious. An attacker on your network could be trying to get you to visit a fake (and potentially harmful) version of YYYY." Looks like things are still in progress and does not work out of the box. Will see what will be in a day or couple.

Re: Universal SSL

#107
post #106

Enabled this, but when visiting website over https have error. "You attempted to reach YYYY, but instead you actually reached a server identifying itself as ssl2000.cloudflare.com. This may be caused by a misconfiguration on the server or by something more serious. An attacker on your network could be trying to get you to visit a fake (and potentially harmful) version of YYYY." Looks like things are still in progress…

We are in the process of issuing 2 million certs. Your cert hasn't been issued yet so you are hitting a sort of 'default cert'. Once that error goes away you are set.

Re: Universal SSL

#108
As I've said on Twitter, I'm excited to see this happen. Not because I think this will help against the NSA, FBI, et al. who are armed with NSLs and FISA letters, but because I believe (hope?) it will set a trend towards making security free for defenders and prohibitively expensive for attackers.

Re: Universal SSL

#109
Will users be able to download their private keys for the provisioned cert?

If not, would CloudFlare ever consider provisioning free SSL certs for non-CloudFlare customers (i.e. let us uploade our crt file and you have your CAs sign it)? We desperately need an alternative to StartCom, since many devs don't trust them[1]. I've suggested AOL in another thread[2], but so far I can't find anyone who works there to talk to.

EDIT: To be clear, I'm very happy for this release and thanks to CloudFlare for stepping up.

[1] - https://bugzilla.mozilla.org/show_bug.cgi?id=1041087#c13

[2] - https://news.ycombinator.com/item?id=8374685

Re: Universal SSL

#110
post #16

CloudFlare now has the most sophisticated MITM attack in the world, where they tell you what they are doing and make you sign up for it. Does CloudFlare have a direct pipe to the NSA already, or is that only going to happen next week?

Your tinfoil's got a hole in it there buddy! But also https://www.cloudflare.com/transparency

Could probs do with being a bit closer to realtime but it's more transparent than most hosts/ISPs

Post reply on HN