HN user

Scott_Helme_

213 karma

Security Researcher, Entrepreneur and International Speaker.

Find me at:

https://scotthelme.co.uk https://report-uri.com

Posts6
Comments76
View on HN

Absolutely — tariff choice, storage, and automation make a huge difference.

The article isn’t claiming this setup is universally optimal, just showing what’s possible when those pieces are combined and used deliberately.

We had an expensive solar install due to restrictions around our roof, so the solar would typically have been cheaper.

Another consideration is that battery installations in the UK are charged at 20% VAT, but if they're installed as part of a solar installation, they're charged at 0% VAT. So even if your main interest is in getting the batteries, a small solar install might make sense because of the savings.

If you were to use the same private key for the 4 certificates then you could seamlessly switch between whichever leaf certificate you wanted to serve to the client. I'm not aware of the ability to send multiple leaf certificates to a client for consideration though.

If you get a 1 year certificate then yeah, but otherwise no. The requirement to re-validate the DNS record comes not from the CA or the use of ACME, but the Baseline Requirements[1] §4.2.1, to prove you are still in control of the domain on a somewhat regular basis to obtain new certificates. Every 3 months is more frequent than is required, but there is still a regular (398 day) DCV requirement.

[1] https://cabforum.org/wp-content/uploads/CA-Browser-Forum-BR-...

That's not what I asked, that's a straw man.

Browser vendors have tested the efficacy of the current EV indicator, resulting in the current action.

If you feel that testing an alternative indicator consistent with other platforms is a good idea, then perhaps that's where the CAs should start their research.

As the organisations that stand to benefit financially from selling these indicators, perhaps it's CAs that should invest in the research? CAs seem to constantly point at the browsers as the party responsible for doing that research, but I don't see why.

Why No HTTPS? 8 years ago

The only way you could do that is on a hosted platform where they do maintenance for you. There's no way a server would last online for decades without being patched, it would have been hosed countless times over by now.

Installing certs is just as regular as installing patches, do it every 6 months if you like, but certainly not every 10+ years!!

Why No HTTPS? 8 years ago

I expected less to be honest. The adult entertainment industry has been on a huge drive to encryption recently. It makes sense if you think about the content they serve, I guess people want more privacy there!

Why No HTTPS? 8 years ago

My guess would be that maybe sites have different infrastructure in different regions and maybe they aren't completely aligned on their progress. I really don't know why you'd intentionally have it like that.

Why No HTTPS? 8 years ago

"Please put yourself in the shoes of someone actually operating a site." - I run 8 sites right now and one of them is processing 10,000,000,000+ requests a month. I speak from a position of experience on this topic.

"Every single issue mentioned in that post only affects end-users. Not a single issue for the operator" - so don't care about the user and the risks we expose them to, only ourselves? This isn't really an approach I'm happy taking.

Why No HTTPS? 8 years ago

Which is insanely difficult to do at scale and would take a considerable amount of time and resources. Not to mention being really obvious! I'm happy with making things crazy hard for the bad actors out there.

Why No HTTPS? 8 years ago

Our accuracy rate is currently around 99.6% so we're doing pretty well but of course I don't think it can ever be 100% either.

The biggest thing we've come across so far is geo-sensitive handling of requests. Some sites will redirect you to HTTPS or not based on where you are making the request from! This of course means you might see HTTPS and we see HTTP.

I think it's still fair to include those sites in this case because they aren't serving all traffic securely.