Earlier quoted context omitted.
If all you have to do to beat these claims is throw money at the problem, then why haven't the other (better funded) search engines done that?
Clogged arteries, i.e. layers upon layers of risk-averse and clueless management. Top management paralysed by what the stock market may think of their ideas. You could also ask why Bing has been forever underperforming despite all the cash Microsoft has throw at it so far?
Search.chatgpt.com domain and SSL cert have been created
111–120 of 126 posts
Re: Search.chatgpt.com domain and SSL cert have been created
#112I know about things like https://crt.sh but how could you be notified about something like this? Is there some service that allows you to be alerted whenever a new certificate is generated for a domain?
Re: Search.chatgpt.com domain and SSL cert have been created
#113Earlier quoted context omitted.
Because if your one wildcard cert gets compromised somehow, the attacker can now impersonate every subdomain of yours. Consider what happens if there's an old test box called daves-test-box.example.com that has a copy of the wildcard cert valid for *.example.com. Dave quits and never updates his box. Eventually an unpatched CVE gets used to steal the cert. Now the attacker can phish or MitM your users of www.example.…
No one is saying wildcard certificates should be mandatory. An old test box shouldn't have a wildcard certificate for sure. Yours is not an argument against wildcard certificates! Yes, like, everything else ever, wildcard certificates can be misused.
They were proposed here as an alternative to domain-restricted sub-CAs, but GP and me have given counterexamples as to why they're not (or at least not without downsides).
Re: Search.chatgpt.com domain and SSL cert have been created
#114Imagine being an innocent developer trying to spin up some internal dev tooling and accidentally landing on the front page of HN to be misinterpreted as an attack against google which could affect both stock
Re: Search.chatgpt.com domain and SSL cert have been created
#115Earlier quoted context omitted.
Because if your one wildcard cert gets compromised somehow, the attacker can now impersonate every subdomain of yours. Consider what happens if there's an old test box called daves-test-box.example.com that has a copy of the wildcard cert valid for *.example.com. Dave quits and never updates his box. Eventually an unpatched CVE gets used to steal the cert. Now the attacker can phish or MitM your users of www.example.…
It depends on the system design. If I have an organization like Google, with many employees, *.google.com would be a horrible cert. That's not every organization. I maintain many groups of /related/ servers (including dynamic ones which appear and disappear at whim). There, a wildcard makes a lot of sense. If I have https://[username].[domain]/ , https://[git project].[domain]/, https://[client].[domain]/ or similar,…
Recommending encouraging non-wildcard certs is the optimal strategy. Only thing I would add, is recommending default to non-wildcard and evaluate deviations case by case.
Re: Search.chatgpt.com domain and SSL cert have been created
#116Earlier quoted context omitted.
Because if your one wildcard cert gets compromised somehow, the attacker can now impersonate every subdomain of yours. Consider what happens if there's an old test box called daves-test-box.example.com that has a copy of the wildcard cert valid for *.example.com. Dave quits and never updates his box. Eventually an unpatched CVE gets used to steal the cert. Now the attacker can phish or MitM your users of www.example.…
No one is saying wildcard certificates should be mandatory. An old test box shouldn't have a wildcard certificate for sure. Yours is not an argument against wildcard certificates! Yes, like, everything else ever, wildcard certificates can be misused.
> No one is saying wildcard certificates should be mandatory.
Nor am I saying they shouldn't ever be used.
You may interpret it differently, but to me:
> Why? As I understand it, the domain owner can assign the name you “trust” to any server already. Might as well trust all names by that domain owner.
Essentially means "default to a wildcard." My example is absolutely a good reason why you should not default to a wildcard. There are situations where they make good sense. I use them myself. It's a terrible idea to use them everywhere and always, which is usually what ends up happening when wildcard certs are the default approach.
Re: Search.chatgpt.com domain and SSL cert have been created
#117Re: Search.chatgpt.com domain and SSL cert have been created
#118Re: Search.chatgpt.com domain and SSL cert have been created
#119Search chatgpt ah but you repeat yourself, we already use LLMs to replace this antiquated notion of loading webpage snippets and pointing me in 5 different directions. I'd say "just chatgpt it"? is closer to being in the lexicon and this url just doesn't roll off the tongue >"here let me search.chatgpt that for you" There I was hoping sama-gpt5-chatbot had some creativity chops for naming new things but they must hav…
> >"here let me search.chatgpt that for you" Why would you say it like that though? You don't set "let me google.com that for you" In the same way you don't say "let me chat.openai it for you", likely search.chatgpt.com will just become the new default interface to chatgpt, and "to chatgpt" something will mean to look it up on search.chatgpt.com
Re: Search.chatgpt.com domain and SSL cert have been created
#120Earlier quoted context omitted.
Clogged arteries, i.e. layers upon layers of risk-averse and clueless management. Top management paralysed by what the stock market may think of their ideas. You could also ask why Bing has been forever underperforming despite all the cash Microsoft has throw at it so far?
I'm talking about the copyright claims. If Bing and Google stand down when people request their sites to be removed, how would OpenAI have the resources to push against that?