Live data from Hacker News

Search.chatgpt.com domain and SSL cert have been created

search.chatgpt.com

111–120 of 126 posts

Re: Search.chatgpt.com domain and SSL cert have been created

#111

Earlier quoted context omitted.

If all you have to do to beat these claims is throw money at the problem, then why haven't the other (better funded) search engines done that?

Clogged arteries, i.e. layers upon layers of risk-averse and clueless management. Top management paralysed by what the stock market may think of their ideas. You could also ask why Bing has been forever underperforming despite all the cash Microsoft has throw at it so far?

I'm talking about the copyright claims. If Bing and Google stand down when people request their sites to be removed, how would OpenAI have the resources to push against that?

Re: Search.chatgpt.com domain and SSL cert have been created

#112
post #7

I know about things like https://crt.sh but how could you be notified about something like this? Is there some service that allows you to be alerted whenever a new certificate is generated for a domain?

There is free service called Certstream [0]. It does not provide notifications, you need to ingest the stream, look for the patterns of interest to you and handle notifications by yourself. But it's fairly easy and the service is commonly used by security teams.

[0] https://certstream.calidog.io/

Re: Search.chatgpt.com domain and SSL cert have been created

#113
post #102

Earlier quoted context omitted.

Because if your one wildcard cert gets compromised somehow, the attacker can now impersonate every subdomain of yours. Consider what happens if there's an old test box called daves-test-box.example.com that has a copy of the wildcard cert valid for *.example.com. Dave quits and never updates his box. Eventually an unpatched CVE gets used to steal the cert. Now the attacker can phish or MitM your users of www.example.…

No one is saying wildcard certificates should be mandatory. An old test box shouldn't have a wildcard certificate for sure. Yours is not an argument against wildcard certificates! Yes, like, everything else ever, wildcard certificates can be misused.

Nobody is proposing to make them mandatory.

They were proposed here as an alternative to domain-restricted sub-CAs, but GP and me have given counterexamples as to why they're not (or at least not without downsides).

Re: Search.chatgpt.com domain and SSL cert have been created

#114
post #52

Imagine being an innocent developer trying to spin up some internal dev tooling and accidentally landing on the front page of HN to be misinterpreted as an attack against google which could affect both stock

Sama & Lex Fridman literally talked about disrupting search in their latest podcast.

Re: Search.chatgpt.com domain and SSL cert have been created

#115
post #97

Earlier quoted context omitted.

Because if your one wildcard cert gets compromised somehow, the attacker can now impersonate every subdomain of yours. Consider what happens if there's an old test box called daves-test-box.example.com that has a copy of the wildcard cert valid for *.example.com. Dave quits and never updates his box. Eventually an unpatched CVE gets used to steal the cert. Now the attacker can phish or MitM your users of www.example.…

It depends on the system design. If I have an organization like Google, with many employees, *.google.com would be a horrible cert. That's not every organization. I maintain many groups of /related/ servers (including dynamic ones which appear and disappear at whim). There, a wildcard makes a lot of sense. If I have https://[username].[domain]/ , https://[git project].[domain]/, https://[client].[domain]/ or similar,…

Yes, I could not agree more. I've been in both the dynamic servers and the dizzying array situations and those are absolutely good reasons to use a wildcard. I worked for a company that white-labelled services so every customer had a vanity subdomain, and managing certs because an utter nightmare until we finally just bought a wildcard.

Recommending encouraging non-wildcard certs is the optimal strategy. Only thing I would add, is recommending default to non-wildcard and evaluate deviations case by case.

Re: Search.chatgpt.com domain and SSL cert have been created

#116
post #102

Earlier quoted context omitted.

Because if your one wildcard cert gets compromised somehow, the attacker can now impersonate every subdomain of yours. Consider what happens if there's an old test box called daves-test-box.example.com that has a copy of the wildcard cert valid for *.example.com. Dave quits and never updates his box. Eventually an unpatched CVE gets used to steal the cert. Now the attacker can phish or MitM your users of www.example.…

No one is saying wildcard certificates should be mandatory. An old test box shouldn't have a wildcard certificate for sure. Yours is not an argument against wildcard certificates! Yes, like, everything else ever, wildcard certificates can be misused.

You're arguing against a strawman (an argument that nobody is making).

> No one is saying wildcard certificates should be mandatory.

Nor am I saying they shouldn't ever be used.

You may interpret it differently, but to me:

> Why? As I understand it, the domain owner can assign the name you “trust” to any server already. Might as well trust all names by that domain owner.

Essentially means "default to a wildcard." My example is absolutely a good reason why you should not default to a wildcard. There are situations where they make good sense. I use them myself. It's a terrible idea to use them everywhere and always, which is usually what ends up happening when wildcard certs are the default approach.

Re: Search.chatgpt.com domain and SSL cert have been created

#118
post #91

Earlier quoted context omitted.

Lmao what so you think the LLM is trained on? And the data set is frozen in the past because LLMs are polluting the web with generated garbage.

that's the point.

Well if you were being sardonic it was completely lost.

Re: Search.chatgpt.com domain and SSL cert have been created

#119

Search chatgpt ah but you repeat yourself, we already use LLMs to replace this antiquated notion of loading webpage snippets and pointing me in 5 different directions. I'd say "just chatgpt it"? is closer to being in the lexicon and this url just doesn't roll off the tongue >"here let me search.chatgpt that for you" There I was hoping sama-gpt5-chatbot had some creativity chops for naming new things but they must hav…

> >"here let me search.chatgpt that for you" Why would you say it like that though? You don't set "let me google.com that for you" In the same way you don't say "let me chat.openai it for you", likely search.chatgpt.com will just become the new default interface to chatgpt, and "to chatgpt" something will mean to look it up on search.chatgpt.com

Today's chatGPT and today's (not OpenAI) web search are very different creatures and experiences. Are you saying that today's chatGPT experience will be abandoned and replaced with a web search experience? That seems terribly unlikely to me.

Re: Search.chatgpt.com domain and SSL cert have been created

#120

Earlier quoted context omitted.

Clogged arteries, i.e. layers upon layers of risk-averse and clueless management. Top management paralysed by what the stock market may think of their ideas. You could also ask why Bing has been forever underperforming despite all the cash Microsoft has throw at it so far?

I'm talking about the copyright claims. If Bing and Google stand down when people request their sites to be removed, how would OpenAI have the resources to push against that?

Logic need not apply. Lawyers will be paid to work around that.
Post reply on HN