HNHacker News
TopNewBestAskShowJobs

weddpros

953 karma · joined May 14, 2013

Currently working on https://SSLboard.com and https://quickS3.com

Socials:

- linkedin.com/in/christophe-hartwig-ba228a5

Interests: Cybersecurity, Entrepreneurship, DevOps, Digital Nomading

---

submissionscomments
weddpros··on SSL Configuration Generator
There are no TLS certs, it's x509 certs :) SSL certificate is still the name used by everybody though. For the protocol, TLS is correct (apart from SSLv3 which is very deprecated).
weddpros··on My dad could still be alive, but he's not
I understand, I know it's a problem in France too, even in hospitals. Or Firefighters being called only to be attacked...

However that exists already, without a way to track the rescue team sent to you...

weddpros··on My dad could still be alive, but he's not
I'm certainly not suggesting that. Read on.

An emergency dispatcher could send a Text message back with a link to a private, case-limited, web page with an ETA + a map + the ambulance location in real time.

See? no "real-time public broadcast of all the addresses a medical event has occurred at".

weddpros··on My dad could still be alive, but he's not
Not desired by whom? I think transparency is desired by citizens/customers. Do you think there are (good) reasons why obscurity is preferred?
weddpros··on My dad could still be alive, but he's not
My sincere condolences to the author. Wishing you strength and peace.

I once saw a man have a heart attack on the beach, less than a 5 minutes drive from a fire-station and rescue team. A helicopter arrived after 45 minutes, and the man was deceased already. That was in Martinique, french Caribbean.

There's a need for an app to let patients track the ambulance. It's been possible for 10+ years, as seen with Uber. It seems existing products have focused on tracking only for the purpose of managing a fleet, missing the focus on patients needs.

weddpros··on £220 'for a cut-up sock' — Apples's new iPhone Pocket ridiculed online
$1465: That's what a nylon+paper bag from Issey Miyake costs. Then the price of this cut-up sock makes sense: it's not an iPhone accessory, it's a luxury fashion item.

https://www.ssense.com/en-th/women/product/issey-miyake/whit...

weddpros··on Ask HN: What Are You Working On? (Nov 2025)
It's the percentage of TLS servers that serve PQ cryptography among all servers in the domain that serve TLS
weddpros··on Ask HN: What Are You Working On? (Nov 2025)
Last week I launched https://qcready.com which measures your Post-Quantum Cryptography readiness.

- no sign up, free

- checks PQC usage among all the servers in a domain

- uses Certificate Transparency to find all your TLS endpoints

- tells you how far you are from PQC readiness

weddpros··on Tips for stroke-surviving software engineers
I hope your dad gets better soon. It takes patience, it's a very gradual process, over months if not years.
weddpros··on Tips for stroke-surviving software engineers
Thank you!

I'll modestly add that my sight was getting better and wasn't really an obstacle. It started with an activity of carbon ink large format B&W art prints for other photographers... then I became one too.

The "irony" didn't appear to me at that time, someone had to tell me it was ironic!

weddpros··on Tips for stroke-surviving software engineers
I haven't had management roles, but I'm now an entrepreneur...
weddpros··on Tips for stroke-surviving software engineers
It's very rare. I was a migraine sufferer, but this is how that time it was different:

- I was under severe stress at work - I woke up with aura, realised it when looking at the mirror, I had only one eye - visual symptoms (aura) didn't go away after 1 hour. That's the limit where you MUST seek medical advice - having "a migraine" that day raised my stress level... because work... - symptoms persisted... and after getting better over a year, what was left became permanent (blind spot where the migraine started in my field of vision)

DO NOT take triptans during the aura. DO NOT take any vasoconstrictors during aura, since it's a phase where blood flow is restricted. That could have caused my stroke.

When a migraine hits, I take aspirin, stop all stressors, ALL stressors, try to calm down (I've used anxiolytics occasionally), breathe and rest. I'm often off for 2 days. It happens about once a year.

Again, migrainous infarcts are VERY rare. You'll be fine, just let the aura pass, and know to seek medical attention if it doesn't.

weddpros··on Tips for stroke-surviving software engineers
I got unemployment assistance, I'm french and lived in France at that time. Be it family, savings or social security, I didn't take a year of vacation. I was trying to pivot to another activity which is difficult in itself, more so after a stroke.

Also before you tell me how good social security is in France :-) you must know my doctor likely caused or amplified the stroke by giving me the wrong treatment at the wrong time, and by not telling me to go to the hospital before 3 full days... and then they let me out. I returned urgently the week after, when a neuro-surgeon freaked out.

weddpros··on Tips for stroke-surviving software engineers
Hi! I hope your dad gets better soon. My vision got better over 3 months, then more slowly over a year. I keep a "small" blind spot in my field of view (where I can hide my hand). I didn't need more management of this condition but rest.

I remember the first months, trees felt exhausting to look at because of their complexity, and I couldn't watch an action movie because it felt too intense.

weddpros··on Tips for stroke-surviving software engineers
Today it's Go-TS-react-node-K8s-mongo-PG-RabbitMQ

Well, I said "I'll never do IT again"... and when I say never, it usually happens in the end ;-)

weddpros··on Tips for stroke-surviving software engineers
Suffered a stroke in 2004 (migrainous infarction). Became half blind. Rested for a good year. Became a photographer for 8 years, then switched back again to software development. From then on, the limits were: WFH only, limit stress, run away from job if things go bad again. Nap if brain feels exhausted. Sleep, more and better. 20 years later (53yo), I'd say I'm doing great! Also fitness helps remind me to take care of the body...
weddpros··on You did this with an AI and you do not understand what you're doing here
You know what was an actual issue, that any AI would have correctly identified as an issue, but HackerOne dismissed? the 1.1.1.1 rogue certificate that later made the news...
weddpros··on Reshaped is now open source
Really neat! It seems backspace in autocomplete is broken: it does NOOP (OSX Safari & Chrome)
weddpros··on Ask HN: How are you preparing for upcoming short-lived SSL renewals?
I built https://SSLboard.com to manage your certificates at any scale and see what’s deployed, where and how. It’s using Certificate Transparency to inventory your certificates so it requires minimal input but provides a complete audit of deployed certificates.

Automation isn't enough: qualys.com (famous for SSLLabs.com) is currently serving an expired certificate (expired 8 days ago). They know their job very well, but without a tool to thoroughly and systematically inventory your certificates, you'll miss it.

weddpros··on Addressing the unauthorized issuance of multiple TLS certificates for 1.1.1.1
My HackerOne dismissal reads

"Although your finding might appear to be a security vulnerability, after reviewing your submission it appears this behavior does not pose a concrete and exploitable risk to the platform in and on itself. If you're able to demonstrate any impact please let us know, and provide an accompanying working exploit."

I was disappointed, and as far as I'm concerned, HackerOne is 2/2 dismissals.

weddpros··on Altered states of consciousness induced by breathwork accompanied by music
We'll have AGI the day an AI mocks us for trying to censor it
weddpros··on Proposal: AI Content Disclosure Header
Actually you're 100% correct.

Feels weird to me that encoding is part of MIME, but language isn't, although I understand why.

weddpros··on Proposal: AI Content Disclosure Header
Maybe we should avoid training AI with AI-generated content: that's a use case I would defend.

Still I believe MIME would be the right place to say something about the Media, rather than the Transport protocol.

On a lighter note: we should consider second order consequences. The EU commission will demand its own EU-AI-Disclosure header be send to EU citizens, and will require consent from the user before showing him AI generated stuff. UK will require age validation before showing AI stuff to protect the children's brains. France will use the header to compute a new tax on AI generated content, due by all online platform who want to show AI generated content to french citizens.

That's a Pandora box I wouldn't even talk about, much less open...

weddpros··on Show HN: Anchor Relay – A faster, easier way to get Let's Encrypt certificates
Sure! yet automation only solves one problem (until it doesn't). Inventory and control/accountability is still needed at scale, and automation doesn't provide it.
weddpros··on Show HN: Anchor Relay – A faster, easier way to get Let's Encrypt certificates
You could see expiring certificates as a chance to examine your security regularly: protocols and ciphers change, bugs are fixed, vulnerabilities are discovered and fixed.

Setup and forget is never good for security. From what I see with sslboard.com (I'm the founder), all hosts serving old expired certificates also have bad TLS versions and ciphers (RC4, DES) and vulnerabilities.

weddpros··on Show HN: Anchor Relay – A faster, easier way to get Let's Encrypt certificates
I think it's more a matter of scale. If you need SSL certificates for hundreds of appliances and you want to manage it, rather than hack it, that's the product you need.
weddpros··on Show HN: Anchor Relay – A faster, easier way to get Let's Encrypt certificates
There's a scale beyond which the real challenge isn't issuing a certificate.

I see organisations with thousands of SSL certificates, and their struggle is real. Even reputable companies with huge teams have their certificates expire or served badly. Some serve expired certificates for years!

Plus, enterprise alternatives are extremely costly and rigid.

weddpros··on Show HN: Anchor Relay – A faster, easier way to get Let's Encrypt certificates
Seeing how people are worried about third parties issuing certificates, I encourage using a tool to monitor CT Logs. It really makes the fog of war disappear around your certificates.

https://crt.sh for point in time checks, https://sslboard.com for comprehensive oversight (disclosure: I'm the founder)

weddpros··on SSL and Domain Monitor Feedback Requested – What do you think of this app?
It's down
weddpros··on CertMate – SSL Certificate Management System
The CT Log scanning infrastructure is cloud based (rather bare metal actually), the application db, service, and Host scanning can be on-prem. An exceptional enterprise customer could convince me to offer a 100% on-prem solution
← PreviousPage 2 of 20Next →