HNHacker News
TopNewBestAskShowJobs

pinjiz

116 karma · joined November 28, 2014

submissionscomments
pinjiz··on Let's Encrypt's New Root and Intermediate Certificates
Yes, that is correct!

It makes sense to use ECDSA for leaf certificates, because the TLS server can then handle more clients compared to a RSA based certificate of the same strength (the private key operation is much cheaper with ECDSA and is needed for every TLS handshake). The client of course, needs a few more cycles to verify the signature, but that is not noticeable most of the time.

IMHO it does not really make sense to use a ECDSA root certificate unless you have a very constrained environment, where every byte counts. The root certificate will never be transferred to the client during a TLS handshake - so the size benefit is minimal (the intermediate certificate will be a bit smaller, because ECDSA signatures are smaller). But the signature validation will take more cycles on the client in every TLS handshake.

Other than that it is a good thing that Let's Encrypt now has an ECDSA root. When researchers might find a problem with RSA in the future, we have an alternative ready to use.

pinjiz··on Humans Not Invited
I just got it by chance, there seems to be a XSS vulnerability and some way to post things. Didn't expect so many alert windows to appear and not sure what else it was doing.
pinjiz··on How to run your own mail server (2017)
The key to get high delivery rates to GMail and Office 365 is to setup DMARC. When you have a proper DMARC configuration (and at least SPF) your delivery problems will suddenly go away.

Hosting your own mail server is not rocket science, but you need to have solid sysadmin skills and a good understanding of email as a whole.

If anyone is interested in doing this: Start simple with only Postfix and Dovecot, don't use a database for username/mailbox configuration as most tutorials suggest (start with text files instead). You can also start with OpenSMTPD and Dovecot if you think that Postfix is too complicated.

And if your setup is finally running, make sure to setup proper monitoring (e.g. make sure your mail server is running and answering SMTP connections). You can use free tools like uptimerobot.com for that and get notified before you loose mail.

pinjiz··on All extensions disabled due to expiration of intermediate signing cert
> 429 Too Many Requests

Mozilla's discourse forum is now offline :)

pinjiz··on All extensions disabled due to expiration of intermediate signing cert
OCSP stapling together with OCSP Must Staple is the way to go here. All major browsers support these.

Firefox still does normal OCSP requests, Chromes does not. So if you are a Chrome user, to my understanding, there is now way to know if the server certificate was revoked or not, other than OCSP stapling together with OCSP Must Staple. Additionally, both Chrome and Firefox ship a list of revoked certificates, but it may not be updated quickly enough and as far as i can tell it mostly contains roots and intermediates.

pinjiz··on All extensions disabled due to expiration of intermediate signing cert
This is not true. In Let's Encrypt/ACME for example, you can simply obtain authorizations for all the domains a certificate is valid for and request revocation [1]. The only thing you still need to revoke the certificate, is the certificate itself. The certificate can be obtained from CT logs.

[1] https://tools.ietf.org/html/rfc8555#section-7.6

pinjiz··on Should you be concerned about LastPass uploading your passwords to its server?
Password managers like LastPass and 1Password have a significant advantage over offline database tools like KeePass: You can easily share individual passwords with your co-workers in a somewhat secure way.

KeePass for instance lacks the ability to do just that. You can either a) share the entire database or b) use multiple databases with different passwords. However, a) is not secure as your co-workers get access to passwords they do not need and b) is very inconvenient.

LastPass (or 1Password, Bitwarden) makes sharing individual passwords within your team very easy, convenient and secure enough. You can create shared folders and define permissions to access those by certain members of your team, and most importantly, deny access to other members. Is there any offline based password manager that allows you to do that (and is usable by the average Joe)?

pinjiz··on Five years of IPv6: whither the next five?
In Germany, only Deutsche Telekom (and resellers such as Congstar) supports IPv6 on mobile (for both prepaid and postpaid). And it works great, even when tethering.

Since you're from the UK, I suppose you are a Vodafone customer and therefore roaming in the Vodafone network in Germany (which does not support IPv6 yet).

On some networks/devices you might have to enable IPv6 explicitly, by setting the APN to IPv4/IPv6.

In Singapore, Singtel seems to be the only provider that supports IPv6. Unfortunately only for postpaid plans.

pinjiz··on Call this phone to become a part of William Binney's social graph at the NSA
> The mobile phone with the number +49 174 276 6483 On display in a vitrine in the exhibition Global Control and Censorship at ZKM | Center for Art and Media Karlsruhe, October 4, 2015 – May 1, 2016

> It's turned on and connected to the network. No-one (human) will pick up if you decide to make the call.

http://hop3.de/mobiltelefon_en.html

pinjiz··on Launching a weather balloon, a camera and a Raspberry Pi to the stratosphere
In Germany, you need a permit from the authorities (in this case: Regierungspräsidium Freiburg, cost: 30€) and you have to register a weather ballon launch at the German flight control (Deutsche Flugsicherung, cost: free).
pinjiz··on Launching a weather balloon, a camera and a Raspberry Pi to the stratosphere
Author here, the payload hung about 20 meters ( ~60 feet) above ground, we tried to climb up those trees but couldn't make it up to more than 5 meters. We also lent a ladder, but realized that even a 15 meter ladder is not enough to reach the payload. It's also very dangerous without climbing experience and without any climbing equipment to climb up such trees.

It was the only option for us to cut those trees down, since the wood workers of the town were just a few kilometers away from us. They directly processed the trees to firewood, which they were intended for. :)

pinjiz··on Today is Debian 8 release day
Help testing the final images: https://wiki.debian.org/Teams/DebianCD/ReleaseTesting/Jessie
pinjiz··on Show HN: Free, instant, secure, disposable chat rooms built in Go
Why was this comment downvoted? The NSA has built custom hardware to crack 1024 bit DH in a few days[1], so the site owner really should regenerate the DH parameters and use 2048 bits.

It would also be nice to disable 3DES ciphers and only allow ciphers with forward secrecy.

[1] http://blog.erratasec.com/2013/09/tor-is-still-dhe-1024-nsa-...

pinjiz··on Show HN: Free, instant, secure, disposable chat rooms built in Go
This site uses insecure 1024 bit Diffie-Hellman parameters for Diffie-Hellman key exchange! Please fix!
pinjiz··on Email Encryption Software Relies on One Guy, Who Is Going Broke
Just donated 50€, hopefully the goal of 120.000€ will be exceeded!