HNHacker News
TopNewBestAskShowJobs

QuicksilverJohn

21 karma · joined April 21, 2010

submissionscomments
QuicksilverJohn··on Handshake: Decentralizing DNS to Improve the Security of the Internet
Yep. And it's also a DNS registrar.
QuicksilverJohn··on Handshake: Decentralizing DNS to Improve the Security of the Internet
It's actually pretty difficult to enumerate all trusted CAs (or even just what organizations are running CAs). Certificate Transparency certainly helps there, but it's not fully required, and doesn't solve all problems.

The DigiNotar attack (from 2011) was mainly chosen because it's well known and easy to convey. It wasn't even that technically effectively because Chrome had Google's keys pinned, so it was immediately blocked and reported (like you would get with CT today). But, only in Chrome.

More recent examples of mississuance, like tricking Comodo's OCR-based validation [0] or spoofing DNS to hijack Let's Encrypt issuance [1].

CA's are always going to be vulnerable to these sorts of attacks, and they have such a broad attack surface and so much systemic trust (i.e power) that can cause unbounded damages with any error.

[0] https://bugzilla.mozilla.org/show_bug.cgi?id=1311713 [1] https://www.wired.com/2017/04/hackers-hijacked-banks-entire-...

QuicksilverJohn··on Handshake: Decentralizing DNS to Improve the Security of the Internet
Basically, only the root record parsing is done in JS and then passed to unbound for resolution. Though it is possible to run a pure JS resolver, it's not really recommended.

There's also a more portable authoritative & recursive [resolver in C](https://github.com/handshake-org/hnsd).

Plus, the whole protocol for node communication and name resolution & proofs is so simple, that it's pretty easy to reimplement in any language.

QuicksilverJohn··on The Day When Computers Can Break All Encryption Is Coming
The problem with this method is that it requires a side channel. This is the real beauty of public key cryptography, you can negotiate a secure channel over an open channel. (*Authentication sold separately)
QuicksilverJohn··on Source: Google Hangouts for consumers will be shutting down sometime in 2020
No, Hangouts works great for this outside of the US. I use it in New Zealand all the time.
QuicksilverJohn··on “MP3 is dead” missed the real, much better story
1) https://play.google.com/store/apps/details?id=mobi.beyondpod
QuicksilverJohn··on Comparison of SSL Labs TLS Scores with Different Go Versions
https://tip.golang.org/src/crypto/tls/cipher_suites.go#L75
QuicksilverJohn··on Ask HN: What is a monad?
Actually, this made a lot more sense to me. (I guess I really am a math major!)