HNHacker News
TopNewBestAskShowJobs

mikemaccana

497 karma · joined May 5, 2011

This is an old openid account, created when openid was still a thing.
submissionscomments
mikemaccana··on Ask HN: DOs and DON'Ts of collaborating with an NGO as a startup
Charities often don't value work if it's provided to them for free. If you are providing any kind of discount, make sure you show the full price of your time on your invoices, then any discounts.
mikemaccana··on How to deploy your node app on Linux, 2016 edition
Totally agreed, there's certainly a place for tools that don't need DevOps skills, and many places - typically PaaS - that take care of this.

However many developers wish to have more control over their environment than what a PaaS provides, and a lot of the tools they'd use for that - Ansible, Docker, etc - require basic DevOps skills.

[replying from old account due to rate limit]

mikemaccana··on Why Are Digital-Privacy Apps So Hard to Use?
Probably worth noting that Telegram is not secure: http://security.stackexchange.com/questions/49782/is-telegra...
mikemaccana··on The Future of Node Is in Microsoft’s Fork
I'll be more direct at saying what the post can't say:

- Historically the V8 team simply did not care about node, and would introduce breaking changes that would come as a surprise to node core

- It's better now, and V8 folk are on one of the steering committees for node. Also Google Compute Engine team needs node to work so also brings in a real business case for the V8 team to care about node

- Chakra is also a pretty good contingency plan.

mikemaccana··on Trails – Modern MVC Web Framework for Node.js
So what's actually included? A comment here mentioned koa, and there's some kind of ORM, but the README has no information.
mikemaccana··on The Future of Node Is in Microsoft’s Fork
I was really slow on picking up Babel too. But I've been using Babel 5.x in production for six months without errors - main things were docs that referred to old versions of babel and babelify.

I needed to plug this in the package.json of my private modules:

    "browserify": {
        "transform": [
            "brfs",
            [
                "babelify",
                {
                    "presets": ["es2015"]
                }
            ]
        ]
    }
mikemaccana··on Install Win32 OpenSSH test release
> This "separate data from presentation" sounds like TCO-speak. Way too frequently referenced to be a genuine inspiration.

Huh? It's a very specific thing. When you run stuff on Powershell, you pipe it to 'select' or 'where' and pick fields, rather than running grep / sed / awk and inventing regexs to scrape stuff.

    ps | where {$_.StartTime -ge $1HourAgo}
Before accusing me of 'TCO speak' and being 'ungenuine' - for mentioning something that's a well known engineering concept, particularly in the Unix world (ever used TeX?), you could have done <1 minute of research.
mikemaccana··on Install Win32 OpenSSH test release
Asides from being an actual Windows app as you mentioned, it's also a current OpenSSH codebase.
mikemaccana··on Install Win32 OpenSSH test release
A half-bad Unix on top of Windows, with its own duplicate way of handling services, storage, users, permissions and everything else, is a pretty poor setup. Powershell (particularly the way it separates data from presentation) is one of the best shells on any OS. Being able to access it from Linux is a good thing.
mikemaccana··on Install Win32 OpenSSH test release
See https://github.com/PowerShell/Win32-OpenSSH/issues/57.

For some reason putty works but iTerm has the backspace issue. Putty user: what's your $TERM?

Ctrl H works as a workaround BTW.

mikemaccana··on Install Win32 OpenSSH test release
Yes. From my Mac:

    $ ssh mike@192.168.0.12
    mike@192.168.0.12's password:
    Microsoft Windows [Version 10.0.10586]
    (c) 2015 Microsoft Corporation. All rights reserved.

    C:\Users\Mike>powershell -File -

    PS C:\Users\Mike>
mikemaccana··on Install Win32 OpenSSH test release
See also https://github.com/PowerShell/Win32-OpenSSH/wiki/ssh.exe-exa... once you've got it running. To work around a bug, you'll currently need to run `powershell -File -`

It's still way too early to us as a daily driver - lots of small bugs - but nevertheless interesting.

mikemaccana··on The seventh row of the periodic table is now full
Here's the current full table (with the seventh row complete):

https://upload.wikimedia.org/wikipedia/commons/3/3d/Discover...

mikemaccana··on What web developers should know about SSL
libtls is part of libressl: http://www.libressl.org/

> LibreSSL is composed of four parts:

> The openssl(1) utility, which provides tools for managing keys, certificates, etc. > libcrypto: a library of cryptography fundamentals > libssl: a TLS library, backwards-compatible with OpenSSL > libtls: a new TLS library, designed to make it easier to write foolproof applications

mikemaccana··on What web developers should know about SSL
I should add: OCSP is the baseline requirements, ie. DV SSL certs will also need to support OCSP checking. See https://cabforum.org/wp-content/uploads/Baseline_Requirement...
mikemaccana··on What web developers should know about SSL
That's an excellent point - I've added it to the article and credited you.
mikemaccana··on What web developers should know about SSL
EV is a standard for identity verification, rather than a product.

Our product is 40-100x faster validation for EV. If you think DV is fine for your app, that's awesome. But if you're thinking about getting an EV cert, we do in an average of 5 hours what others do in 7-10 days.

mikemaccana··on What web developers should know about SSL
EV certificates require OCSP: Section 26-A of the issuing criteria requires CAs to support OCSP checking for all certificates issued after Dec. 31, 2010.

However as the other poster notes, OCSP stapling includes recent proof that the cert hasn't been revoked the initial handshake, removing additional round trips. See https://en.wikipedia.org/wiki/OCSP_stapling

mikemaccana··on What web developers should know about SSL
This is a perfect explanation. As a followup to @daok's feedback, I've amended the article to expand EV & provide a link!
mikemaccana··on What web developers should know about SSL
A less common question we get, that a lot of web devs are interested in is 'How do I mitigate against MITM attacks'.

- As a browser, by using a default OS and watching the root CA store. You can control the key stores on most devices except iOS pretty easily: https://certsimple.com/blog/control-the-ssl-cas-your-browser...

- As a server, setting up key pinning (https://en.wikipedia.org/wiki/HTTP_Public_Key_Pinning) which throws up a browser warning if someone accesses your site with a new key.

mikemaccana··on Why we don't sell domain validated SSL certificates
(replying from old openid account due to rate limit)

Let's Encrypt want to do EV too - they've also asked CertSimple for help previously to do it. it's significantly more work than automating DV again (which has already been done) are CertSimple are far ahead of the entire SSL industry when it comes to speedy EV validation.

Encrypting something with a public key, without knowing who that public key belongs to, largely defeats the purpose of encryption.

mikemaccana··on Why we don't sell domain validated SSL certificates
(replying from old openid account due to rate limit)

I have no idea about StartSSL, but some cheaper EV providers Comodo immediately ask you to use a lawyer or CPA to write professional opinion letters.

This allows the CA to do less work according to the EV guidelines, but massively slows down the validation process and may incur additional fees unless you have an in-house legal team or CPA.

mikemaccana··on Why we don't sell domain validated SSL certificates
(replying from old openid account due to rate limit)

No probs: I understand the cynicism: the SSL industry is dominated by sales and marketing giants that market snake oil like SGC and seal in search, I wouldn't trust any of them either.

There's not a lot of people who get UX and get crypto: I've got my name in RHEL and I've also built consumer facing web apps for Google and Microsoft. That's 17 years of pretty unique experience, and we launch new features every couple of weeks. If a CA tries to follow - and they will - bring it, we'll smoke them.

Your final point is accurate.

mikemaccana··on Why we don't sell domain validated SSL certificates
(Replying from openid account due to rate limit)

Yes, see my response to the price point above.

mikemaccana··on Why we don't sell domain validated SSL certificates
Replying from old openid account due to rate limit:

That's why the jurisdiction is shown in the address bar. However it'd be worth seeing how effective that is.

mikemaccana··on Why we don't sell domain validated SSL certificates
(replying from old openid account due to rate limit)

There's a specific person that's well known on HN that mentioned a pirate site had an EV cert at Edge conf, implying they shouldn't have been able to get one. They have a registered business, and a real address in London, and the EV cert simply assures that identity.

Most people in network ops have very little idea of EV,so I don't think naming individuals is productive.

See 'Do DV or EV SSL certificates mean this is a good company?' at https://certsimple.com/blog/are-ev-ssl-certificates-worth-it

mikemaccana··on SSL tools we wish we'd known about earlier
(Author here, replying with my old openid account due to rate limit.)

The 'freshness' is possible because it's a domain validated certificate - domain validated certificates are < 1 min, and normally cheap or free, as all you have to do to get a domain-validated cert is have an official sounding email address, publish a DNS text record, or some other way to show you have control of the domain. Domain validation doesn't require any investigation of the identity behind that domain, which is why they don't show the company name or the green bar. In Edge, domain validated certs show a hollow grey lock. [1]

EV certificates require checking the actual company - government registration, business status (eg, do you pay your taxes), does the person requesting the certificate have authority to take actions on behalf of the company, does the company have a verifiable physical address, and more [1]. They then show that company's identity in the certificate and browser - as the company name in a green bar.

Nearly everyone you speak to will quote a either a vague figure or 7-10 days to provide an EV cert.

CertSimple only does EV, and our average certificate issuance time is 5 hours. We've been doing them even faster than that recently - check the tweets on the front page of the site. A big part of that is that CertSimple checks a whole bunch of your company's information before you pay us any money. [2]

[1] https://certsimple.com/blog/dv-ssl-in-microsoft-edge

[2] https://certsimple.com/blog/are-ev-ssl-certificates-worth-it

[3] https://certsimple.com/blog/checking-orders-before-you-pay

mikemaccana··on Show HN: Fast and simple way to get EV SSL certificates
You're right. Edited.
mikemaccana··on Show HN: Fast and simple way to get EV SSL certificates
Mike from CertSimple here (using old openid account as my other one is replying too fast):

StartSSL don't do EV (edit: they do, just not for $60).

We only do EV, since we actually identifying companies is how SSL should have always been.

$60 is way too much to pay for non-EV, an automated process that doesn't check who you are. If you want a non-EV certificate, wait a couple of months and use https://letsencrypt.org

mikemaccana··on Show HN: Fast and simple way to get EV SSL certificates
Mike here using old openid account, as I'm replying too fast.

The CA handles the verification, hence the difference in price. Symantec/Verisign is the most expensive, Digicert is in the middle, Comodo and the Symantec budget brands are the cheapest.

As mentioned elsewhere, I do have code written against the Comodo API, and it would be a lot more profitable to use them. However I (and the tech companies I'm targeting, eg, Stripe, GitHub) use Digicert certs, mainly for reasons of verification speed but also business practice compared to competitors, eg, Comodo: https://blog.hboeck.de/archives/866-PrivDog-wants-to-protect...

Page 1 of 5Next →