Live data from Hacker News

HTTPS on Stack Overflow: The End of a Long Road

nickcraver.com

151–160 of 183 posts

Re: HTTPS on Stack Overflow: The End of a Long Road

#151
post #84

Earlier quoted context omitted.

I'm not sure I understand the question. If you own something.com then you automatically own any possible subdomains.

The Let's Encrypt process is about validating control of the content on a domain, not about OWNERSHIP of the domain. To get a cert, you just have to be able to update a file at a Let's Encrypt specified location on the domain. This is only proving that you are in control of the website for that specific domain, not that you are in control of the DNS for the entire domain and all subdomains. Of course if I own a domai…

But the ACME protocol, the automation underpinning Let's Encrypt, supports validation via a DNS challenge (adding a specific TXT record to the domain). Would it not be possible to issue wildcards if-and-only-if a DNS challenge succeeds?

Re: HTTPS on Stack Overflow: The End of a Long Road

#152
post #45

Earlier quoted context omitted.

Some people don't spy on their customers and don't have these kinds of information available for analyses They're admittedly few though and their moral high ground is debatable considering that there are self hosted FOSS alternatives around nowadays

Are you implying that analyzing server logs to gather aggregate user agent statistics is "spying on [your] customers?" Because that is untrue.

Aside from my personal opinion (which largely agrees with you), there are jurisdictions where a specific IP address is considered enough to make it (and the rest of the data) personal information, requiring a justification, information (or even consent), and other processes to protect privacy.

That's why Google Analytics has an option to remove the last three digits of an IP.

Re: HTTPS on Stack Overflow: The End of a Long Road

#153
post #45

Earlier quoted context omitted.

Some people don't spy on their customers and don't have these kinds of information available for analyses They're admittedly few though and their moral high ground is debatable considering that there are self hosted FOSS alternatives around nowadays

Calling aggregate anonymous analytics "spying on your customers" is absurd nonsense.

Analytics on the web are neither aggregate nor anonymous.

Re: HTTPS on Stack Overflow: The End of a Long Road

#154

Earlier quoted context omitted.

Certainly doable but this should not be done.

There are many enterprise "solutions" that basically do this "out of the box". Yeah it shouldn't be done and a lot of employees are likely unaware that IT can see all of their SSL traffic but it's a big business.

HTTPS or not, certainly nothing is private here, but that's expected for this sort of place.

Re: HTTPS on Stack Overflow: The End of a Long Road

#155

Earlier quoted context omitted.

For every answered question, there are probably 20 unanswered ones. Almost none of my embedded programming questions got answered. Edit: my estimate is wildly off. It's basically the opposite of what I said.

12,095,709 questions have an answer, 7,506,004 of those have an accepted answer, and 1,813,270 aren't yet answered. I'd say your 1:20 ratio is just a little bit off :)

Just out of curiosity, do those 7.5+ million accepted answers include those closed as duplicates? Because by far my biggest complaint is finding the exact question I have was closed as a duplicate and links to a question that is useless at answering my question.

Re: HTTPS on Stack Overflow: The End of a Long Road

#157
post #45

Earlier quoted context omitted.

I know it's hindsight and all that, but why didn't you check your website analytics first? Seems a fairly massive assumption that should have taken 10 seconds to check.

Some people don't spy on their customers and don't have these kinds of information available for analyses They're admittedly few though and their moral high ground is debatable considering that there are self hosted FOSS alternatives around nowadays

Well you can use qualsys labs tool to check your ssl and all the main search engines have said they will start flagging sites that use unsafe HTTPS or show the warning page before letting you proceed

Re: HTTPS on Stack Overflow: The End of a Long Road

#158

Earlier quoted context omitted.

The Let's Encrypt process is about validating control of the content on a domain, not about OWNERSHIP of the domain. To get a cert, you just have to be able to update a file at a Let's Encrypt specified location on the domain. This is only proving that you are in control of the website for that specific domain, not that you are in control of the DNS for the entire domain and all subdomains. Of course if I own a domai…

But the ACME protocol, the automation underpinning Let's Encrypt, supports validation via a DNS challenge (adding a specific TXT record to the domain). Would it not be possible to issue wildcards if-and-only-if a DNS challenge succeeds?

I think you're right.

Re: HTTPS on Stack Overflow: The End of a Long Road

#159

Earlier quoted context omitted.

Do they realize their employees can use 4G to access SE?

Not if they're forced to check their phones in. I have friends working in the defence industry for whom this is something they have to deal with.

Well sites doing TS work you can sort of understand that

I knew someone who worked for the scientific civil eservice and they where not allowed to have a phone with a camera.

I have also been for an interview at a site (HMGC) where you have to hand in all electronics at reception - this was an avowed role btw so I am not breaking any laws the organisation even has job adverts on the local buses

Re: HTTPS on Stack Overflow: The End of a Long Road

#160

Earlier quoted context omitted.

You should try this link from home: https://stackoverflow.com/jobs

Many banks have very strict IT policies on posting things on internet, and they have valid business reasons for that. Not saying you meant that, but it's not like they're some dark, silly workplaces that people should get away from asap.

> Many banks have very strict IT policies on posting things on internet

Yes, they do. And I really love it. Because it means that MY bank eats their lunch, because the bank I work for actually UNDERSTANDS how to use technology, while still keeping (very!) strict controls.

Post reply on HN