I'd be much more surprised by a full fingerprint match. Wouldn't that imply a SHA-1 collision?
[0] http://www.asheesh.org/note/debian/short-key-ids-are-bad-new...
232 karma · joined May 1, 2013
I'd be much more surprised by a full fingerprint match. Wouldn't that imply a SHA-1 collision?
[0] http://www.asheesh.org/note/debian/short-key-ids-are-bad-new...
Perhaps the address should be an unguessable <GUID>@ngrok.org instead? Or do you validate SPF and only accept mail from your ISP?
(Maybe you already have solutions; I just found it interesting to consider abuse of the system.)
This actually sounds like a fun little linear algebra problem.
> Currently the verify operation continues after errors so all the problems with a certificate chain can be seen. As a side effect the connection will never fail due to a server certificate verify failure.
https://www.openssl.org/docs/apps/s_client.html
https://www.mail-archive.com/openssl-users@openssl.org/msg71...
[1] https://www.documentcloud.org/documents/785152-166819124-mit...
You can find plenty of wikidrama at https://en.wikipedia.org/wiki/User_talk:Agent00f and https://en.wikipedia.org/wiki/Wikipedia:Requests_for_comment...
An active repeater would give you 1/r^2, though. For example, you could ping Voyager I for a 36-hour delay. However, that's likely not feasible at light-year distances, let alone the problem of getting the devices there. :)
That's 2.5 iPhone-years of computation, though. A speedy desktop could be 10 times as fast, and that's before we get to GPUs or multiple machines.
This means that, e.g., if you are "good friends" with Verisign, you can get them to issue a certificate for any Google property, and Chrome will happily accept it.
[1] https://src.chromium.org/viewvc/chrome/trunk/src/net/http/tr...
ssh> help
Commands:
-L[bind_address:]port:host:hostport Request local forward
-R[bind_address:]port:host:hostport Request remote forward
-D[bind_address:]port Request dynamic forward
-KR[bind_address:]port Cancel remote forward
(If you're not familiar with them, some of the other escape sequences are useful too. ~? lists them all.)[EDIT] Apparently, if you have a recent enough version, you can add a forward to the master with `ssh -O forward ...` [1]
[1] http://serverfault.com/questions/237688/adding-port-forwardi...
1: http://identity.mozilla.com/post/56526022621/what-is-an-iden...
[0]: https://en.wikipedia.org/wiki/Hardware_random_number_generat...
This doesn't really apply to the self-replication wave, but it is an argument against active SETI.
They aren't: http://www.asheesh.org/note/debian/short-key-ids-are-bad-new...