HNHacker News
TopNewBestAskShowJobs

Ayesh

3,618 karma · joined March 16, 2017

Reach out at https://aye.sh :)
submissionscomments
Ayesh··on The Browser's Main Thread Is Expensive
Such an excellently written articles with really nice interactive visualizations!
Ayesh··on Tell HN: Cloudflare silently injects its analytics when you switch nameservers
If a registrar requires you to use their own nameservers, then they are no longer comparable to other registries.
Ayesh··on PHP's Oddities
PHP has quite a lot of oddities such as how loose comparisons (`==`) are made, numeric-strings, and type coercion. But the two oddities mentioned in the article are not that "odd" with a bit of context.

- PHP has `SplFixedArray`[^1] that work similar to the standard arrays you expect from other languages. SPL extension is always available in PHP 5.3+, it is not even possible to compile PHP without it anymore. There is no specific type for list-arrays and associative arrays, but there is an `array_is_list` function to quickly check it.

- For typed properties, if a property is not typed, it is effectively considered `mixed $var = null`. If the property is typed, and has no default value, then it is considered uninitialized, and not allowed to access.

[^1]: https://www.php.net/manual/en/class.splfixedarray.php

Ayesh··on DNS-Persist-01: A New Model for DNS-Based Challenge Validation
I think the previous post is talking about a search that will find the sibling domain names that have obtained certificates with the same account ID. That is a strong indication that those domains are in the same certificate renewal pipeline, most likely on the same physical/virtual server.
Ayesh··on DNS-Persist-01: A New Model for DNS-Based Challenge Validation
I'm surprised the ballot passed, unanimously even! I get that storing the DNS credentials in the certificate renewal pipeline is risky, but many DNS providers have granular API access controls, so it is already possible to limit the surface area in case the keys get leaked. Plus, you can revoke the keys easily.

The ACME account credentials are also accessible by the same renewal pipelines that has the DNS API credentials, so this does not provide any new isolation.

~It's also not quite clear how to revoke this challenge, and how domain expiration deal with this. The DNS record contents should have been at least the HMAC of the account key, the FQDN, and something that will invalidate if the domain is transferred somewhere else. The leaf DNSSEC key would have been perfect, but DNSSEC key rotation is also quite broken, so it wouldn't play nice.~

Is there a way to limit the challenge types with CAA records? You can limit it by an account number, and I believe that is the most tight control you have so far.

---

Edit: thanks to the replies to this comment, I learned that this would provide invalidation simply by removing the DNS record, and that the DNS records are checked at renewal time with a much shorter validation TTL.

Ayesh··on Google Public CA is down
Yes, and it's not that long ago, or I aged really quickly.

For code signing certificates and EV certificates, (and OV certificates, if they are even alive), this is still the case.

Ayesh··on Upcoming changes to Let's Encrypt and how they affect XMPP server operators
LetsEncrypt doesn't see your private key when you obtain the certificate. So no, it's not _really_ a juicy target.
Ayesh··on Notepad++ hijacked by state-sponsored actors
If you update via Winget, you are probably safe.

Winget downloads the installer from GitHub: https://github.com/microsoft/winget-pkgs/blob/master/manifes...

Ayesh··on Pricing Changes for GitHub Actions
Microsoft had a very fair shot at redeeming themselves, but with how Teams, GitHub and all the AI crap they push into GitHub and Windows, it's clear they have not changed one bit.
Ayesh··on Valve: HDMI Forum Continues to Block HDMI 2.1 for Linux
I know that HN replies must carry some substance, unlike majority of Reddit comments. But I wanted to say that this comment read line a poem to me.
Ayesh··on So you want to speak at software conferences?
Local meetups are very easy to get selected into, and they often have two or three speakers lined up, with a balance of speakers they know and are experienced, and new speakers.

Most of the time, the organizers are squeezed to find a speaker, so you are pretty much guaranteed to be offered a slot if you just ask the host.

Ayesh··on So you want to speak at software conferences?
I imagine it'll go against your talk getting into the shortlist.

But there are some conferences that ask and respect your preference whether you'd like the video recording to have your face or just the audio. But I have yet to see a conference that go as far as asking the audience to not take photos of the presenter, so it's pretty much moot if you do not want your photos published at all.

Ayesh··on 10 Years of Let's Encrypt
To prove a very important point, that EV certificates are broken, someone obtained a "Stripe Inc." EV certificate by registering a company in a different state.

https://arstechnica.com/information-technology/2017/12/nope-...

(The original site is no more, but this Arstechnica article has screenshots and a good summary)

Ayesh··on 10 Years of Let's Encrypt
Considering how many ACME clients are available today with all sorts of convenient features, and that many web servers nowadays have ACME support built in (Caddy, Apache mod_md, and recent Nginx), I believe that people who don't automate ACME certificates are the people who get paid hourly and want to keep doing the same boring tasks to get paid.
Ayesh··on 10 Years of Let's Encrypt
https://github.com/letsencrypt/boulder

You can find a docker-compose.yml file to get some idea.

Appears to be using MariaDB.

They shut down OCSP responders and expiry email reminders, so there really is no need to have a database apart from rate limits, auth data, and caching.

For Certificate Transparency, they are submitted to Google and CloudFlare run trees but I don't think LetsEncrypt run their own logs.

Ayesh··on 10 Years of Let's Encrypt
As someone else mentioned, it's a non-profit, so I guess it's not technically possible to get acquired.

But I personally believe that the people behind LetsEncrypt genuinely care about the mission and will never sell out for their personal benefit.

If there was a list of organizations that bring the most impactful things to tech per each dollar received in donations and per each employee, ISRG will be up there at the top.

Ayesh··on 10 Years of Let's Encrypt
It's been a long time so this is my fading memory, but CAs used to generate a private key on their end and let you download both private key and the certificate containing the public key. The non-technical person who paid big money for the certificate then emails the zip file to the developer. That's when StartTLS wasn't that big back then either.

Just comically bad way to obtain certs.

Ayesh··on Fifteen Years
This must be how winning in life feels like. I wish your family good health.
Ayesh··on PHP 8.5
the MySQL extension was dropped in PHP 7.0.
Ayesh··on How two photographers transformed RAW photo support on Mac
iOS shoots HEIF natively I think.

Raw photos probably are shot in DNG. DNG "images" are popular for raw images because theyb can be losslessly converted from to the camera raw formats like the Nikon's, and DNG is open source and royalty free.

Ayesh··on AWS deprecates two dozen services (most of which you've never heard of)
Thank you. The linked third party article is a terrible incomplete rehash.
Ayesh··on URLs are state containers
Canonical URLs come to the rescue.
Ayesh··on URLs are state containers
> Everything after the '?' character.

It only strips known tracking parameters b(like those utm_ query params). It does not remove all parameters; if that's the case, YouTube video links will stop working.

Ayesh··on Tags to make HTML work like you expect
It's a typical pattern in, say react, to have just this scaffolding in the HTML and let some frond end framework to build the UI.
Ayesh··on Replacing a $3000/mo Heroku bill with a $55/mo server
Yes, I'm just as curious as you on _why_ does a staging setup needs the same amount of resources as prod.

All of my staging setups are on a ~$15 Hetzner server, with a GitHub Action to `docker compose build && docker compose up -d` remotely, with an Apache service with a wildcard certificate and dynamic host names. We have 3..n staging setups, with each PR spinning up a new staging site just for that PR.

It's been working with us for years, for a team of 10 developers.

Ayesh··on Not all browsers perform revocation checking
It's not better.

Short lived certificates are definitely the better way forward.

24 hour certificates will add a significantly more load on CAs, a lot more than maintaining an OCSP responder.

Ayesh··on Not all browsers perform revocation checking
If the certificate was issued with must-staple flag, then the server can refuse to connect if the handshake did not include an OCSP response.

web servers can refresh OCSP responses in the background and cache valid responses to add some tolerance against temporarily downtimes in the OCSP server.

Ayesh··on Not all browsers perform revocation checking
I don't think so.

- Let's Encrypt: doesn't support it since May 7 this year

- Buy Pass: No longer offers free certificates, probably didn't have must-staple either

- Zero SSL, I didn't find any public links to check if they sign CSRs with it.

- Google Trust Services: Same as above

- Amazon Trust: Same as above, but it probably does.

Ayesh··on Not all browsers perform revocation checking
Firefox has a a toggle `Query OCSP responder servers to confirm the current validity of certificates`, which is turned off by default.

Edit: It seems to be enabled by default! I've been using Firefox for as long as I remember, and don't setup Firefox afresh frequently.

Ayesh··on Not all browsers perform revocation checking
I was a big fan of OCSP-stapling and must-staple. Both of which are slowly being discouraged; LetsEncrypt refuses to issue must-staple certificates since a few months ago, and I think they are shutting down OCSP servers, if not shut down already.

The idea with OCSP-stapling is that the webserver fetches the OCSP data, caches it for TTL ~24 hours, and staples it to the HTTPS handshake. That way, the browser does not need to query the issuer's OCSP servers, avoiding both performance and privacy concerns. Revoked certificates will continue to work for up to 24 hours, but that, IMO, is within an accepted range compared to CRL that can take a lot longer.

The downside is that the HTTPS handshakes now contain a bit more data, and we want to keep this as minimal as possible.

Page 1 of 32Next →