HNHacker News
TopNewBestAskShowJobs

dadrian

676 karma · joined June 3, 2013

https://dadrian.io

@davidcadrian

@dadrian@a2mi.social

@dadrian.io

Must read: 'tptacek, 'jblow, 'JumpCrisscross, 'idlewords, 'hwayne, 'luu, 'gdb, 'antics

submissionscomments
dadrian··on What the heck is AEAD again?
I dunno why you say it isn't useful. It is inherently plaintext, but still worth authenticating. If you just used an AEAD but didn't put e.g. the session identifier or connection ID or sequence number in the AD, it would be entirely unauthenticated, but the decryption of, say, the message body would still succeed.
dadrian··on TLS certificate lifetimes will officially reduce to 47 days
The root problem is certificate lifetimes are too long relative to the speed at which domains change, and the speed at which the PKI needs to change.
dadrian··on Ask HN: Has anyone quit their startup (VC-backed) over cofounder disagreements?
Yeah, but this also offers a clear exit opportunity (during the raise), and limits the "blast radius" to time-since-last-raise, rather than progress against the first four years of the company.
dadrian··on Ask HN: Has anyone quit their startup (VC-backed) over cofounder disagreements?
If you can't do 10 up front, you can usually reset founder vesting back every funding round to slow it down. This is fairly common.
dadrian··on A startup doesn't need to be a unicorn
You need to be a unicorn or you need to only take angel checks. This is not complicated.
dadrian··on Certification Authority/Browser Forum adopts new security standards
There is literally a code-signing working group in the CA/BF. However, the browsers don't really participate in it, since it's irrelevant to browsers. This is the entire point of moving to dedicated hierarchies per use-case---each PKI (web, code signing, etc) can evolve independently.
dadrian··on Certification Authority/Browser Forum adopts new security standards
ARI is outside the scope of the CABF
dadrian··on The Burnout Machine
What Big Tech companies are demanding 80 hours a week?
dadrian··on Chaos in the Cloudflare Lisbon Office
Maybe, but they've taken something that was effectively risk-free and added risk for absolutely no reason.
dadrian··on Chaos in the Cloudflare Lisbon Office
If they actually integrate this into randomness on their TLS servers, the only risk is that the system for getting the entropy from the lamps and waves somehow screws up, fails to parse an HTTP request or something, and accidentally seeds the whole system with no entropy. Whereas doing literally nothing and just letting Linux boot correctly on metal would be perfectly secure.
dadrian··on HTTP/3 is everywhere but nowhere
Yes, but head-of-line blocking is a different thing than round trips.
dadrian··on HTTP/3 is everywhere but nowhere
HTTP/2 already reduces roundtrips.
dadrian··on HTTP/3 is everywhere but nowhere
It's not clear to me that HTTP/3 is relevant to anyone who isn't already using it. It's most useful for large-scale hosting providers and video. And these people have already adopted it, and don't necessarily use out-of-the-box web servers for their infrastructure.
dadrian··on How to distrust a CA without any certificate errors
No, eIDAS 2.0 was an attempt to address the fact that the EU is not one market in ecommerce, because EU citizens don't like making cross-border orders. The approach to solving this was to attach identity information to sites, ala EV certificates. The idea for this model came from the trust model for digital document signatures in PDFs.

There are already plenty of CAs across the pond.

dadrian··on How to distrust a CA without any certificate errors
The main limitation is the incredibly opaque and brittle nature of putting keys in DNS.

We've spent a decade and a half slowly making the Web PKI more agile and more transparent by reducing key lifetimes, expanding automation support, and integrating certificate transparency.

None of that exists for DNS, largely by design.

dadrian··on How to distrust a CA without any certificate errors
The Tor service model is equivalent to if every site used a self-signed certificate, which doesn't scale.

The more feasible CA-free architecture is to have the browser operator perform domain validation and counter-sign every sites key, but that has other downsides and is arguably even less distributed.

dadrian··on How to distrust a CA without any certificate errors
Mozilla’s list is built to reflect the needs of Firefox users, which are not the same as the needs of most non-browser programs. The availability/compatibility vs security tradeoff is not the same.
dadrian··on How to distrust a CA without any certificate errors
What actual risk are you worried about here? Mozilla changed their data policy, therefore the root store might do what...?
dadrian··on How to distrust a CA without any certificate errors
Non-browser clients shouldn't be expected to crib browser trust decisions. Also, the (presumably?) default behavior for a non-browser client consuming a browser root store, but is unaware of the constraint behavior, is to not enforce the constraint. So they would effectively continue to trust the CA until it is fully removed, which is probably the correct decision anyway.
dadrian··on Microsoft begins turning off uBlock Origin and other extensions in Edge
You can install uBlock Origin Lite [1], and get literally the same blocklists but with better security properties.

[1]: https://chromewebstore.google.com/detail/ublock-origin-lite/...

dadrian··on Why Quantum Cryptanalysis is Bollocks [pdf]
https://podcasts.apple.com/us/podcast/root-causes-408-takeaw...
dadrian··on Why Quantum Cryptanalysis is Bollocks [pdf]
I'm with you, but the government (at least in the US and UK) should definitely be spending more time figuring out how to patch reliably, and little less on PQC.
dadrian··on Leaking the email of any YouTube user for $10k
I'd also add that the legality of law enforcement exploiting a server-side bug is much more of a gray area (or actually illegal), whereas there is a standard process for law enforcement or the intelligence community to get a court order that enables them to exploit devices that belong to a specific target (phone, laptop, etc).
dadrian··on Musk-led group makes $97B bid for control of OpenAI
pg has not moderated Hacker News, nor been operationally involved in YC, for over a decade.
dadrian··on U.S. Government Disclosed 39 Zero-Day Vulnerabilities in 2023, First-Ever Report
If Government A and Government B are not equally "good" for the world, then the world is _not_ better off if everyone disclosed, since the main users of CNE are LE/IC.
dadrian··on U.S. Government Disclosed 39 Zero-Day Vulnerabilities in 2023, First-Ever Report
That organization exists, and it is called the FBI.
dadrian··on New speculative attacks on Apple CPUs
It is not required by window.open semantics, you can absolutely implement site isolation even in the presence of COOP unsafe-none
dadrian··on YC Graveyard: 821 inactive Y Combinator startups
A real false start on that baseball metaphor.
dadrian··on A Brazilian CA trusted only by Microsoft has issued a certificate for google.com
The next version of Chrome introduces a whole UI for this at chrome://certificate-manager.
dadrian··on How to get the whole planet to send abuse complaints to your best friends
Multi-perspective issuance corroboration is required starting in March of 2025 for CAs following the CAB/F Baseline Requirements

https://cabforum.org/working-groups/server/baseline-requirem...

← PreviousPage 3 of 8Next →