HNHacker News
TopNewBestAskShowJobs

hg35h4

110 karma · joined September 12, 2020

submissionscomments
hg35h4··on DigiCert Revocation Incident (CNAME Domain Validation)
"I can't immediately think of a reason why you'd need a publicly trusted certificate if you're pinning a specific public key"

Inter-finance systems mostly, some government. Sometimes they pin the CA issuer, sometimes IP based although with dynamic cloud IPs that is disappearing, sometimes inside a VPN, and other times just the cert issues themselves. Same service handing public users while making bidirectional API calls to other interfaces that are more locked down.

Not everyone is a monolithic copy and paste Wordpress hosting site, a new cloud native cash rich startup, or a massive Google/Amazon/Microsoft with huge teams to orchestrate everything using their own architecture and systems they developed themselves. Private PKI? Even more orchestration layers for enrollment especially in places with BYOD.

There is no point to low expiry certs anyways. If a server is hacked, the primary concern is what data were they able to exfiltrate and for how long - not that a keypair was maybe stolen to be used in a very complicated and unlikely attack to intercept some of the same data they already stole.

Your ATC comment seems to continue your theme that everyone should run a private PKI instead. Airports are full of interconnections between themselves, other airports, airlines, ground crews, satellite relays, and weather monitoring systems. So then all these parties need to do all the same actions as the public PKI - root key signing , cert issue logging, secure interface for issuing certs, develop a trust across all parties and make them install your root in all their systems ..... or, just use the public PKI services which already does that. You are just reinventing the wheel and probably will get it wrong. Maybe for some strictly backend systems, or things like server out of band management it works well, but not anything involving multiple companies.

The CAs work with large and complex business understand these complexes and voted for 2 year duration. The owners of the browsers just wanted to further their own cloud bottom lines.

hg35h4··on DigiCert Revocation Incident (CNAME Domain Validation)
"Alternatively, if companies cannot handle the rotation, then they likely should re-evaluate if WebPKI is even appropriate for their use-case."

I hate hearing this awful take, as if every IT organization has the same neat and tidy systems deployed as they do. Never had to deal with 3rd party SaaS vendors certificate pinning requiring service tickets to change, don't have any hardware devices or appliance based software images each with their own web interface to update certs...

Yes companies should have a plan to do their minimum yearly certificate rotates. Yes those companies should have a security plan to rotate affected certificate issues, but in those cases the business users are ok with an outage to remediate a real security issue.

But what happened here is that Digicert invalided the entire domain's worth of certs. All those service.companyname.com certs or duplicates under that domain validation were affected in bulk. In some companies there could be thousands of certs under that domain. Digicert screwed up their system implementation and made their customers suffer.

"It's really disheartening that publicly trusted CAs just ignore their contractual obligations however they see fit."

It's also disheartening to see browsers in the CA consortium ignore the CA resolutions as well. Like how everyone voted for 2 year certs and Apple did their own thing anyways. Any punishment for Apple come? So why pick on the others?

hg35h4··on Drug Decriminalization Policies Work – With Properly Funded Treatment Services
It's not working - https://www.washingtonpost.com/world/2023/07/07/portugal-dru...

The entire Jacobin article only focused on if less addicts die it is a "working" policy, but it resulted in significantly more people now hooked on drugs in those decriminalized places than before. How is that a positive that more individuals are now subject to a destroyed life?

Also ignores the destruction of the community and the increased violence they face since the police can no longer arrest these individuals and they have become much more brazen. In my city where it certainly isn't decriminalized the police refused to arrest people camped out smoking meth in train stations to the point that many people refused to take transit. Numerous times I had to walk through a cloud of meth smoke to get out of the station because there was zero repercussions for open drug use. Open fencing, people getting robbed, stepping on needles, and random attacks.

By almost all metrics hard drug decriminalization is a failure.

hg35h4··on B.C. woman buried in Amazon packages she did not ask for and does not want
Accessing the walkway to the front door and knocking on the front door is not trespassing, even if there is signs posted. Wandering off the path, going around the back, looking in windows is trespassing - but accessing the front door to deliver, ask for directions, or invite someone to tea is not. You can be asked to leave which then could be turned into trespassing. Decent write up about it - https://www.radford.edu/content/cj-bulletin/home/june--2017-...
hg35h4··on YouTube is testing a more aggressive approach against ad blockers
Still not free-riding when you consider the data they are collecting from viewers even with ad-blockers. People still have accounts to save channels/videos, lots of people or households have Android phones that makes it stupidly easy to link to people, places and purchases. There is significantly more value they still gain from it even if youtube itself operates at a loss.

Maybe if they weren't allowed to collect so much information, or had to pay back the users they are collecting data on could I see the point that ad-blocking is free-riding.

hg35h4··on Canada plans brain drain of H-1B visa holders, with no-job, no-worries permits
You are only looking at one small part. Total immigration affecting housing & jobs are regular immigrants + temporary foreign workers + students (who often also work and have had most work restrictions removed). Each group also has their own path to citizenship. Our government is unfortunately targeting >500,000 per year even though housing cannot catch up. When people have kids they take almost 20 years to need their own space, direct adult immigration like this takes a housing unit away from an already tight market.
hg35h4··on The future of web software is HTML over WebSockets
Everything about this sounds terrible for mobile, lossy or even medium latency connections. Non-blocking background updates are unnoticeable, but imagine your website being jammed like a stuck video every time you click or scroll?

He describes a "please wait buffering" future of web software. No thanks.

hg35h4··on Facebook takes down main page of Myanmar military
Doesn't work since big tech all works together to crush dissent and anything that goes against their business model.

Look at how attacked any right wing site is - they go after their ISPs, their CDNs, their DNS registrars, their hosting companies.

The Internet has got to the point that you cannot even operate a business if it goes against the "values" of big tech, or they chop all your arms off.

hg35h4··on Changes to sharing and viewing news on Facebook in Australia
Traditional media companies vs big tech oligarchs.

Not sure which I dislike more. Liars and thieves the lot of them. Can they both lose for our sakes?

hg35h4··on Tesla Recalls Cars with EMMC Failures, Calls Part a ‘Wear Item’
Good thing they aren't making rockets with this stuff. Or if they are they have controls to take over. Oh wait....
hg35h4··on Migrate Everything from Linux to BSD
It was a fine simple solution until DoH. In some internal environments the internal traffic volume can be much higher than the few services that might be publicly exposed.

Sure lots of ways you could do it - get a fat edge firewall to hairpin the traffic + support Internet access but you end up paying a lot more for all the threat licenses on the oversized edge. Could add many more tiers, maybe more translations or overlays... but why bother with a lot more complexity or especially more cost just because someone saw a threat in another country and are trying to solve a problem that does not apply to most.

Further more there can be internal only host names that are now getting probed and exposed externally. Exfiltration to a US company in the name of "security"

hg35h4··on Migrate Everything from Linux to BSD
It's horrible for environments with split horizon DNS. It presumes that the only network that should exist are home users consuming public Internet cloud services.

For privacy it's a discussion of do I trust my obnoxious non-US ISP or a US based .com with seeing all my browsing habits based on DNS queries. At least I could have legal recourse with my ISP in my own country, and there is slightly better privacy laws.

hg35h4··on J vs. K by Example

   ]D=.~. S=.
I thought I was looking at a sendmail config file at first!
hg35h4··on Google Cloud lost $5.6B in 2020
> I have a GSuite legacy account for my personal domain name. Most of my family is on it. It was free.

Oh boy they've been really trying to push people off GSuite legacy hard. I started missing incoming emails, testing would show a server error about a high email flow for maybe a dozen per day. Zero support, and they erased my posts on their support board. You can't change the primary domain as free, you can't use any email diag tools, you can't do anything.

I ended up moving to Zoho. Sure it's not free, but it's not outrageous for personal/family use. Decent migration tools as well. It really started a hard de-Googlification. I nix any chatter about using Google at work now as well.

hg35h4··on Google Cloud lost $5.6B in 2020
AWS was similar for years. Huge losses, now they are profitable.

The big difference with Google Cloud is that they have a long history of jacking up pricing at random. Wake up one morning and find that the solution you just spent months building will bankrupt your business under the new pricing regime.

hg35h4··on Element (Matrix chat app) suspended from the Google Play Store
Stallman was right all along. The Google and Apple play to lock down your devices in order to "keep you safe" was not about malware or data privacy, it's about keeping away what THEY classify as thoughtcrime. It's about keeping you under their shoe. Now feed them your data or else!
hg35h4··on Twitter Bots Are a Major Source of Climate Disinformation
You exactly described Big Green and Big Oil propaganda - to influence public opinion. Your definition explicitly mentions "facts" so therefore Big Green fits too.

Also Big Green likes to half-truth about how ethical or clean green is. Here's for cobalt, but not the only problem: https://www.washingtonpost.com/graphics/business/batteries/c...

hg35h4··on Twitter Bots Are a Major Source of Climate Disinformation
Your propaganda is defined by anything you don't agree with trying to persuade you. Big green isn't propaganda, only big oil right?
hg35h4··on China wants to build an open source ecosystem to rival GitHub
China wants to have easy access to simply copy out of private repos rather than hack developers.
hg35h4··on What killed Haskell, could kill Rust, too
I must have angered fad language of the year fans :)
hg35h4··on What killed Haskell, could kill Rust, too
Actually what kills it is Yet Another F... Language. Most new languages are barely better then anything that already exists. After the initial cheerleaders that started the project moved on, the company realizes it's hard to find coders for the niche fad language of the period.