HNHacker News
TopNewBestAskShowJobs

nickf

314 karma · joined August 15, 2008

Basic constraints. Long-time PKI-botherer.

If you want to email me, use: nick (-at-) nickf (-dot-) net

submissionscomments
nickf··on Factoring "short-sleeve" RSA keys with polynomials
Hanno - we may have communicated before some years ago, but am more than happy to offer any help I can (if some of our customers are/were affected, happy to reach out and see if they can give you more answers as to which products). nick (at) sectigo (dot) com
nickf··on Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
For any target of sufficient value that a government would do that, yes. Of course it doesn't happen anyway, because governments don't have some kind of secret access to CAs.
nickf··on Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
I would imagine, as a CA that issues only DV certs, they'd disallow issuance to various ccTLDs, and perhaps stop newAccount registrations with email addresses at those ccTLDs. That's about as much as they could do - IP-blocking by region is ineffective and crude at best.
nickf··on Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
ZeroSSL aren't an EU-based alternative, unfortunately.
nickf··on Parallel Reconstruction of Lawful TLS Wiretapping
If a cert doesn't contain the requisite number of valid SCTs from logs that are specifically usable in the browser - it will not work.
nickf··on What Apple and Google are doing to push notifications
You’re right of course, but Apple won’t do it - they’re happily running a two-tier system where Uber, eBay, Doordash can force spam notifications on you with impunity. All my settings for marketing are off - eBay still sends me notifications about coupons (and additionally there’s no way to actually contact them to complain, of course). Doordash won’t let me get delivery notifications without marketing notifications.

Apple could fully enforce their policies and fix this in a heartbeat, but they won’t.

nickf··on WebPKI and You
While I sort-of see what you're trying to say, if you knew the groups and teams involved - you'd know there was no favouritism and a strong degree of separation between CA and root programs.

The root programs who have their own CAs are also cloud providers, who arguably have a legitimate need for the CA. Or in Apple's case they have their own CA, but don't issue externally. They keep CA and root program separate.

nickf··on WebPKI and You
That's absolutely incorrect. While CABF sets the 'Baseline Requirements' that ultimately go into the WebTrust audit scheme that root programs use to accept roots into their trust stores...browsers can and do set their own rules.

The reduction of TLS cert lifetime to a max of 398 days was an Apple policy.

nickf··on Robust and efficient quantum-safe HTTPS
Your failure to see the problem doesn’t mean it doesn’t exist. 40x the size might not really be an issue for the hypothetical server you’ve suggested - but that isn’t the reality for the world. Many devices do HTTPS and TLS. Not to mention the issue is more with the clients. CT logs would get a lot harder to run (and they’re already not so easy).
nickf··on Upcoming changes to Let's Encrypt and how they affect XMPP server operators
Google dominate the space because they have an active, robust trust-store program that they manage well. Apple the same. Mozilla and Microsoft too (though to a lesser extent).

If any ecosystem - such as XMPP - wishes to, they could start their own root-program, but many simply copy what Chrome or Mozilla do and then are surprised when things change.

nickf··on Upcoming changes to Let's Encrypt and how they affect XMPP server operators
Not really, no. There are a number of reasons for cert lifetimes being made shorter.
nickf··on Upcoming changes to Let's Encrypt and how they affect XMPP server operators
A public CA checks it one-time, when it's being issued. Most/all mTLS use-cases don't do any checking of the client cert in any capacity. Worse still, some APIs (mainly for finance companies) require things like OV and EV, but of course they couldn't check the Subject DN if they wanted to.

If it's for auth, issue it yourself and don't rely on a third-party like a public CA.

nickf··on Upcoming changes to Let's Encrypt and how they affect XMPP server operators
Eh, it's pretty easy to impersonate if the values in the certificate aren't checked, and you could get one from any of a list of public CAs.

If you're relying on a certificate for authentication - issue it yourself.

nickf··on Upcoming changes to Let's Encrypt and how they affect XMPP server operators
Publicly-trusted client authentication does nothing. It's not a thing that should exist, or is needed.
nickf··on Upcoming changes to Let's Encrypt and how they affect XMPP server operators
Client authentication with publicly-trusted (i.e. chaining to roots in one of the major 4 or 5 trust-store programs) is bad. It doesn't actually authenticate anything at all, and never has.

No-one that uses it is authenticating anything more than the other party has an internet connection and the ability, perhaps, to read. No part of the Subject DN or SAN is checked. It's just that it's 'easy' to rely on an existing trust-store rather than implement something secure using private PKI.

Some providers who 'require' public TLS certs for mTLS even specify specific products and CAs (OV, EV from specific CAs) not realising that both the CAs and the roots are going to rotate more frequently in future.

nickf··on Upcoming changes to Let's Encrypt and how they affect XMPP server operators
You are correct, and the answer is - no-one using publicly-trusted TLS certs for client authentication is actually doing any authentication. At best, they're verifying the other party has an internet connection and perhaps the ability to read.

It was only ever used because other options are harder to implement.

nickf··on 6-Day and IP Address Certificates Are Generally Available
It’ll be 5 years soon.
nickf··on Mozilla's New CEO Confirms Firefox Will Become an "AI Browser"
I was mostly just typing out what they had listed under 'products' on their pages. I'm aware of what Mozilla do, know folks there and that have been there. They've been roundly criticised for adding 'products' of questionable value to their core userbase, rightly so in my opinion.
nickf··on Mozilla's New CEO Confirms Firefox Will Become an "AI Browser"
...which is arguably the problem. Firefox. Thunderbird. That should be it. According to their own site, beyond that they have the browser app for mobile devices. A VPN service, an email-forwarding service, and MDN. Hardly 'many products'.
nickf··on Upcoming Changes to Let's Encrypt Certificates
There are ways to do this as pointed out below - CNAME all your domains to one target domain and make the changes there. There’s also a new DCV method that only needs a single, static record. Expect CA support widely in the coming weeks and months. That might help?
nickf··on Upcoming Changes to Let's Encrypt Certificates
It might never 'touch' the internet, but the certificates can be easily automated. They don't have to be reachable on the internet, they don't have to have access to modify DNS - but if you want any machine in the world to trust it by default, then yes - there'll need to be some effort to get a certificate there (which is an attestation that you control that FQDN at a point-in-time).
nickf··on Upcoming Changes to Let's Encrypt Certificates
Not quite true - some CAs were not 'held hostage' - some agree with the changes and supported them. See the endorsers for SC-081.
nickf··on Upcoming Changes to Let's Encrypt Certificates
Honestly don't recall discussing 17 days, but I could be wrong. 47 days was a 'compromise' in that it's a step-down over a few years rather than a single big-bang event dropping from 397->90/47/less.
nickf··on Upcoming Changes to Let's Encrypt Certificates
Can I ask - if you're using publicly-trusted TLS server certificates for client authentication...what are you actually authenticating? Just that someone has a certificate that can be chained back to a trust-anchor in a common trust-store? (ie your authentication is that they have an internet connection and perhaps the ability to read).
nickf··on Upcoming Changes to Let's Encrypt Certificates
Sure, but in those examples - automation and short-lifetime certs are totally possible.
nickf··on Upcoming Changes to Let's Encrypt Certificates
Chrome root policy, and likely other root policies are moving toward 5-years rotation of the roots, and annual rotation of issuing CAs. Cross-signing works fine for root rotation in most cases, unless you use IIS, then it becomes a fun problem.
nickf··on Upcoming Changes to Let's Encrypt Certificates
Where did you get 17 days from?
nickf··on Upcoming Changes to Let's Encrypt Certificates
If it doesn’t run a web service, or isn’t publicly routable - why do you need it to work on billions of users browsers and devices around the world?
nickf··on Upcoming Changes to Let's Encrypt Certificates
You assume it’s just the certs being purchased - and not support, SLAs, other related products, management platforms, private PKI and more. If all you do is public TLS, sure, that might be an issue.
nickf··on Upcoming Changes to Let's Encrypt Certificates
Roots for all CAs are going to be rotating much more frequently now. Looking to be every 5 years.
Page 1 of 6Next →