HNHacker News
TopNewBestAskShowJobs

weddpros

953 karma · joined May 14, 2013

Currently working on https://SSLboard.com and https://quickS3.com

Socials:

- linkedin.com/in/christophe-hartwig-ba228a5

Interests: Cybersecurity, Entrepreneurship, DevOps, Digital Nomading

---

submissionscomments
weddpros··on Grok 4.5
Just in case you missed this article https://www.washingtonpost.com/technology/interactive/2026/0... I hope we'll get updated stats on newer models eventually.
weddpros··on Think of the children: How to force real ID for all internet traffic (2023)
It amazes me how compartmented the mind of the West is: the "protector of Democracy" is barely conscient of its own lies... There is no democracy, barely an illusion of one.
weddpros··on Do agents.md files help coding agents?
If adding something to the context doesn't help, it's only proves you're not adding the right stuff.

I'm adding pointers to specification documents, and it saves me from the /new dumb coding agent that sees your code base for the first time and knows nothing about architecture, concepts, code organisation, etc...

I'm using no cookie cutter directives though (except maybe "do not attempt to deploy, we're using CI CD to deploy" to avoid an automatic "wrangler deploy" to Cloudflare)

weddpros··on Show HN: Send Cloudflare Worker build events to Pushover
I really wanted to be notified of my Cloudflare builds in Pushover, since that's what I use for all my indie web apps events.

You can deploy it in minutes on your Cloudflare account.

- create an App in https://Pushover.net - click the Deploy on Cloudflare button on the Github Readme - configure the two Pushover secrets (User key and App token) in the form

Enjoy.

weddpros··on Show HN: Throwaway – open-source disposable email checker and API
I've added support for an adhoc list in addition to the list I'm getting from the disposables... so now it's recognised as a throwaway address.
weddpros··on Show HN: Throwaway – open-source disposable email checker and API
Well it's blocking the second one. You can't win them all.
weddpros··on Show HN: Throwaway – open-source disposable email checker and API
As I've said in another comment, I'm offering a free cyber security assessment tool online and 22% of people use a disposable address, meaning they remain anonymous yet they have me scan the internet for vulnerabilities. They're not protecting themselves from me, they're protecting themselves from the consequences of their actions.

You could have asked me what reasonable use cases exist.

There are extremely valid use cases for anonymity in B2C, most likely none in B2B.

weddpros··on Show HN: Throwaway – open-source disposable email checker and API
Let me explain: I'm operating a free cyber security service and 22% of users use a disposable emails. 22% of emails bouncing is not a TINY inconvenience. Hackers using my service incognito isn't a TINY inconvenience. If you're hiding your identity, I can't offer a safer internet to everyone.

I respect your disgust, and I feel the same towards your entitlement and presumptions.

I'll fix the percentage, it's 0.01%.

weddpros··on Show HN: Throwaway – open-source disposable email checker and API
I'm now using https://github.com/disposable/disposable which should be a pretty decent option
weddpros··on Show HN: Throwaway – open-source disposable email checker and API
Hi thank you! Can you share what domain it is? I'll add it to a regression test and make sure I find a more recent source of domains! I had found one, but it contained microsoft.com and google.com so...
weddpros··on Vera: a programming language designed for machines to write
It feels wrong to dump identifiers to save tokens: now they're devoid of semantics, and can't be grep'ed or mapped to concepts. CPUs are good with numbers, but LLMs are good with words.
weddpros··on Will you heed my warnings now?
TLS can already be setup to avoid store-now-decrypt-later PQC issues. That's available today, and should be implemented. Use https://sslboard.com to inventory all your external TLS infrastructure and check for PQC readiness (creator here).
weddpros··on Cybersecurity looks like proof of work now
Maybe code quality shouldn't be considered cybersecurity in the first place?

When things are tagged "cybersecurity", compliance/budget/manager/dashboard/education/certification are the usual response...

I don't think it would be an appropriate response for code quality issues, and it would likely escape the hands of the very people who can fix code quality issues, ie. developers.

weddpros··on German implementation of eIDAS will require an Apple/Google account to function
eIDAS tends to hear "our European Sovereignty" when they hear Self-Sovereign.

You can't have a government issue a Self-Sovereign identity to you, it's an oxymoron. They can only issue credentials. But then they'd feel like they're losing control, so they pervert it. Now they call it SSI but it's just digital credentials.

The very title says it all: German implementation of eIDAS will require Google or Apple ID. That's not self-sovereign identity.

And that's why I find it lame.

weddpros··on German implementation of eIDAS will require an Apple/Google account to function
I agree, and that government ID isn't your identity, it's just a piece of it.

I'm not arguing against government ID, I'm saying identity doesn't have to be that piece of paper, or that Google ID.

Analogy: if google ID is your primary key in your User table, then you're cooked. Instead use a uuid for the PK, and add Google ID as just another id. But the identity is the PK.

weddpros··on German implementation of eIDAS will require an Apple/Google account to function
Self Sovereign Identity (aka SSI) is the only way out of those identity sovereignty issues. It shouldn't be acceptable that your identity depends on anything or anyone. It should just be your identity.

A paper or certificate can prove an entity trusts your identity to be <firstname, lastname, etc...> but that shouldn't be your identity.

You just are. Not your google Id, not your Apple Id either of course.

Governments are lame.

weddpros··on Europe's $24T Breakup with Visa and Mastercard Has Begun
Hosted on Amazon and Digital Ocean from what I can tell
weddpros··on Ezs3.net to share S3 access in your team
Hi! thanks for your feedback. Indeed the site fails to tell you what ezS3 does: it's not an alternative to Minio, it's not an S3 storage implementation. S3 is made for machines, ezS3.net "proxies" it for humans: it's a web-based S3 browser, and adds RBAC and sharing.
weddpros··on SEC obtains final consent judgments against former FTX and Alameda executives
Trump could do it... to piss off SBF himself (second biggest donor to Biden/democrats behind Soros)
weddpros··on The Good Hallucinations
https://github.com/sslboard/SSLBoard-desktop for an OSS project I’m working on with those principles
weddpros··on 2026 Predictions Scorecard
And the record is N=35=7x5, that's 6 bits not 35 bits as the author is saying... Maybe he'd revise his prediction on QC if he knew?
weddpros··on The Dangers of SSL Certificates
I'm working on something that could help: linking sslboard with software that's making issuance and distribution of certs easier, ie. a proper CLM. It's not cloud based for security reasons. In that context, we know your wildcard certs because we issue them, and we could know where they are if we distribute them... Please get in touch with me (chris@sslboard.com) if you're interested in early access and having a word in the development of the product!
weddpros··on The Dangers of SSL Certificates
one-address-to-N-servers is perfect if the N servers don't all terminate TLS. If not, it becomes impossible to actually test what certificates are actually served. I've seen this fail before (TLS tests flip/flop between good/bad between checks).

As for wildcard certs, I agree there are use cases where we really need them like dynamic subdomains {customer}.status.com

Can you share how they make ACME client configuration easier?

weddpros··on The Dangers of SSL Certificates
If you're using a cert on multiple IPs, or IPv4+v6, SSLBoard will monitor all IPs. It's not foolproof, but it covers most common practices. btw wildcard certs don't have a good reputation (blast radius)...
weddpros··on The Dangers of SSL Certificates
Indeed, SSLBoard is scanning CT logs. You can add/import host names though, to allow monitoring of wildcard certs. Same if you're using ports that are not 443, you have to add these to the list of hostnames that are checked.

It's not as convenient, but it's the best SSLBoard can do...

weddpros··on The Dangers of SSL Certificates
The scalable way (up to thousands of certificates) is https://sslboard.com. Give it one apex domain, it will find all your in-use certificates, then set alerts (email or webhook). Fully external monitoring and inventory.
weddpros··on If AI replaces workers, should it also pay taxes?
Unsurprisingly it’s a European article. Europe will tax AI to death like it does with everything it can’t find a way to compete in. And it can’t compete in much…
weddpros··on The Typeframe PX-88 Portable Computing System
I dearly remember seeing a PX-8 in the hands of a person (was it by a pool?) and thinking "it would be so nice if work could look like that". It must have been Byte magazine?

I was a kid in France, now I'm working remotely from Bangkok: dreams come true after all.

weddpros··on Ask HN: What Are You Working On? (December 2025)
Making a phishing domain detection tool through Certificate Transparency real time scanning.

https://catchPhi.sh/

I intend to make it "too cheap to pass", because we should all be able to monitor Certificate Transparency.

Email me if you want to be a design partner!

weddpros··on SSL Configuration Generator
That's good! I'll use TLS when OpenSSL gets renamed :-D (I own many SSL domains and projects)
Page 1 of 20Next →