Live data from Hacker News

A world of hurt after GoDaddy, Apple, and Google misissue 1M certificates

arstechnica.com

141–143 of 143 posts

Re: A world of hurt after GoDaddy, Apple, and Google misissue 1M certificates

#141

Earlier quoted context omitted.

Is there a reason why certificates are being issued using the bare minimum required number of bits, instead of something higher like 128 or 256? Why even risk being at the very edge?

There are legends that some software doesn't like serial numbers that don't fit in 64-bits. As with most legends you'll tend to hear a third hand story that someone heard once from somebody who remembers someone else telling them. Since this came up on m.d.s.policy we have a very specific client to always keep in mind, Mozilla's Firefox, and that doesn't care, but perhaps something else does, or did, at some unspecif…

Thank yous all for teaching me about Brown M&Ms.

https://www.snopes.com/fact-check/brown-out/

Re: A world of hurt after GoDaddy, Apple, and Google misissue 1M certificates

#142
post #86

Earlier quoted context omitted.

Would two signatures on the same cert fit the bill? Two complete certs is twice as much data to transmit, making the TLS setup a bit heavier.

A typical webpage is something like 2MB A typical cert is 0.1% of that

Lots of things use TLS that is much smaller than a bloated webpage, for example REST APIs.

Re: A world of hurt after GoDaddy, Apple, and Google misissue 1M certificates

#143

Earlier quoted context omitted.

It's not a slippery slope argument, it's an applying the rules argument. The rules don't allow for a difference between more and less serious infractions, they just need to be followed to the letter.

"If you can't obey this silly requirement to use extra bits how can we trust you to do all the other things that we need done correctly?" is a slippery slope argument. The response is "We allocate testing resources proportionally to the seriousness of the consequences of failure to adhere to a requirement, as any good engineering project does." It's probably worth noting that the problem lasted three years and wasn't…

It's saying, you have an extremely important job for the functioning of the Internet, that everybody has to blindly trust you do right.

The moment we see a small sign that you don't do it right in some detail, then that trust is gone.

Consider all the details in the spec to be Van Halen's brown M&Ms (although that had no functional effect, and losing a bit of security does). They knew that if people did that right, then they could trust that they also read the details of the rest. If Google gets this wrong, we can't trust on that.

That's not a slippery slope argument. That'd say, if we allow this then you would then do worse things because we let it go. But that's not the argument.

Post reply on HN