HNHacker News
TopNewBestAskShowJobs

tomputer

315 karma · joined March 12, 2015

submissionscomments
tomputer··on Coinbase is launching support for the USDC stablecoin
If there is a need for electronic cash backed by USD and controlled by a central party, why use crypto/blockchain at all? To solve that problem a central database on a controlled network could do just fine?
tomputer··on Elastic files for an IPO
I edited my post. Missed those tabs. Thanks!
tomputer··on Elastic files for an IPO
Slightly off topic: this quote from the SEC filing document:

"Immediately prior to the completion of this offering, we intend to change our corporate form from a Dutch private company with limited liability (besloten vennootschap met beperkte aansprakelijkheid) into a Dutch public limited company (naamloze vennootschap) and change our corporate name from Elastic B.V. to Elastic N.V."

As far as I know, Elasticsearch has no headquarters or offices in The Netherlands. I assume the company is only registered in The Netherlands for tax avoidance.

If my assumption is true, despite that I like their products, this makes me a little sad.

EDIT: my bad. I missed the tab Europe and Asia. They do seem to have an office in Amsterdam.

tomputer··on Liquid water 'lake' revealed on Mars
What if there is a cure for cancer but it’s living/growing on Mars?
tomputer··on 1.1.1.1: Fast, privacy-first consumer DNS service
It is explained on the bottom of the page:

Who’s behind this?

1.1.1.1 is a partnership between Cloudflare and APNIC.

Cloudflare runs one of the world’s largest, fastest networks. APNIC is a non-profit organization managing IP address allocation for the Asia Pacific and Oceania regions.

Cloudflare had the network. APNIC had the IP address (1.1.1.1). Both of us were motivated by a mission to help build a better Internet. You can read more about each organization’s motivations on our respective posts: Cloudflare Blog / APNIC Blog.

tomputer··on 1.1.1.1: Fast, privacy-first consumer DNS service
Thanks for the clarification. I did know it was possible when setting up CA's for VPN servers, they can use certificates with DNS and/or IP as identifiers. Somehow I never thought about certificates for public IP addresses.
tomputer··on 1.1.1.1: Fast, privacy-first consumer DNS service
Today I learned that it is possible to request a certificate for an IP address.
tomputer··on Show HN: CertStream – See SSL certs as they're issued in real time
That is mostly true, unless it's malicious Certificate Authority which may, on behalf of a governments request, ignore the CAA record on purpose to generate a certificate.

This is where a TLSA record would help to prevent malicious certificates. At least, if the client (browser) validates TLSA records.

tomputer··on Glibc getaddrinfo stack-based buffer overflow
On Debian there is also the tool checkrestart available, it is part of the debian-goodies package. This might be useful if a reboot is (currently) not possible.

  apt-get install debian-goodies
Then you can run:

  checkrestart
And it will list services which require a restart. For example:

  service sudo restart
  service ssh restart
  service cron restart
  service ...
On Debian 8 (Jessie) i had to restart the systemd services as well:

  systemctl daemon-reexec 
  systemctl restart systemd-journald
  systemctl restart systemd-logind
tomputer··on Gmail Will Warn If Message Is Not Authenticated/Encrypted
Interesting. I'm wondering if they also warn Gmail users if a mailserver has TLS enabled with a self-signed certificate. Because i think many mailservers actually support TLS but do ignore certificate verification, because of the self-signed certificates.
tomputer··on SHA-1 Deprecation: No Browser Left Behind
I wonder how they manage the SHA-1 fallback? Guess it might be a proxy which decides it, based on the user-agent.
tomputer··on IKEv2 in iOS 9 and OS X El Capitan
I think MOBIKE [1][2] should solve this, roaming between different networks.

[1] https://wiki.strongswan.org/projects/strongswan/wiki/MobIke

[2] https://tools.ietf.org/html/rfc4555

tomputer··on IKEv2 in iOS 9 and OS X El Capitan
If you have the possibility to use a dedicated (virtual) server to setup a IPsec/IKEv2 VPN server, have a look at pfSense[1]. It is easy to manage through the webinterface, especially when using IPsec with certificate authentication for road warriors. The current pfSense stable release uses strongSwan 5.3.2 for IPsec VPN's.

Documentation for installing and setting up strongSwan from source is available on their own wiki[2]. There are also packages available for some Linux distributions.

This site/blog[3] explains very well how to install and setup strongSwan with certificate authentication. But most of the examples are probably also on the strongSwan wiki.

[1] https://www.pfsense.org/

[2] https://wiki.strongswan.org/projects/strongswan/wiki

[3] https://www.zeitgeist.se/2013/11/22/strongswan-howto-create-...

tomputer··on IKEv2 in iOS 9 and OS X El Capitan
It is interesting because currently the built-in Apple VPN client in both, OS X and iOS, does not support IKEv2. Well, iOS 8 has support for it but not through the GUI. OS X only supports L2TP/IPsec and Cisco IPsec (both IKEv1). Cisco IPsec is just plain IPsec, using IKE(v1) to establish the tunnel.
tomputer··on SSL tools we wish we'd known about earlier
Another useful site:

https://ssldecoder.org/

Source for self-hosting:

https://github.com/RaymiiOrg/ssl-decoder

← PreviousPage 3 of 3