HNHacker News
TopNewBestAskShowJobs

gchambert

3 karma · joined March 24, 2017

submissionscomments
gchambert··on Ask HN: Intercepting HTTPS – How can we trust anything?
It's not 100% related but certificate pinning (HKPK) is only enforced for CA trusted by browser. It is ignored if the leaf certificate is signed by a user-imported CA (or deployed by enterprise policies). Maybe the same applies for SCT?
gchambert··on Ask HN: Why is skype for business such a shit show?
Teams is still a joke. Everything is sooooo sloooooow in it. At least Skype can run on y computer without the fans covering my voice.
gchambert··on Stay Away from Cloudflare (2017)
Yes of course. The dynamic part of your site will still need protection, though. And if you offload static assets to a third-party, you'll have smaller pipes for non-static data, thus you are less likely to handle a DDoS. So you'll still need someone to protect your non-static data.
gchambert··on Stay Away from Cloudflare (2017)
> Another option, if you're running at a larger scale, is to purchase mitigation appliances and just set up your own mitigation infrastructure. This will not be cheap and require some serious connectivity, but beyond a certain point it'll be more cost-effective.

How many companies reach this level? 99% of companies will have to rely on a CDN provider for this.

> You'll want to avoid anything HTTP-specific (as it will be prone to the same privacy issues as CloudFlare), and opt for layer 3/4 mitigation only.

Of course your CDN provider will be more effective if it can inspect unencrypted traffic. So, again, either you are at the level of traffic of a big IaaS provider, or like 99% of CDN customers you choose between letting your provider inspect your traffic or not be protected against app-level DDoS.

> Even something relatively simple like ModSecurity will cover a wide array of problems.

Everything is a question of measure. How much is "a wide array of problems"? How much is "some serious connectivity"?

A middle-ground would be using a CDN to protect against L3/L4 volumetric attacks, without TLS interception. And using ModSecurity or another WAF against application-level attacks. But the result will probably not be as good as applicative protection at CDN level, and will cost you more (you pay for the CDN, for your own WAF infrastructure, and for your 24/7 team ready to write new protection rules when a new attack occur).

gchambert··on Using Google Analytics without GDPR consent
Processing PII doesn't need consent if it's necessary to provide the service. Keeping logs fits in this category: to run a website, you need the ability to debug problems, analyze frauds and attacks. Moreover, you have the responsibility to protect your users, hence be able to analyze attacks, and block malicious IP addresses. And lots of countries have laws that make it mandatory to keep these logs in case police needs them (e.g. France, 1 year mandatory retention).

To make this processing legal, then GDPR demands that you inform your users, minimize the amount of PII, anonymize as soon as possible, and most of all not use this PII for other purposes.

gchambert··on Using Google Analytics without GDPR consent
What is forbidden by GDPR isn't specifically cookie or IP, but but any tracking mechanism which allows to identify an individual uniquely with some amount of certainty, and without prior consent.

What he is doing is illegal.

gchambert··on Please don't use Hacker News for political or ideological battle
Who still believes in 2020 that technology isn't political? Have you never heard of the impact of Facebook or Twitter on our societies? Cambridge Analytica, anyone? It lead to Brexit & Trump...

Any technology changes society, thus has a political impact. Trying to hide it is ideological. Does HN promote this ideology only? Or does it welcome various points of view?