HN user

charlesbarbier

61 karma
Posts0
Comments15
View on HN
No posts found.

It's sad because they can do good investigative journalism. They took the lead in the Panama Papers case, the hockey canada and Miller sex scandals, recent Indian and Chinese interference, and many more.

The problem might be that this doesn't even need investigation. It's too boring. Everything is said in the bill. They just lack technical literacy to realize the implication.

My guess is that the legislators are completely ignorant of the technical implication of weakening the entire chain and the media are just as ignorant.

It's actually quite defensible from their perspective. They justify it with reason they decided wire tapping was reasonable for the past decades. It's just that they don't understand the risk and implication.

I didn't express myself well but what I meant by force is that by building a standardized to automate way manage certificate, ACME imposed itself and became mandatory.

Previously, most CA had no programmatic way to order certificate, it was all done manually.

As far as I know, the only providers with that would let you automate certificate provisioning at the time where Comodo, GlobalSign and Digicert.

They all had their own quirky API. Just to give you an idea, we ended up selecting GlobalSign at Shopify a few years before LetsEncrypt, and it was this SOAP nightmare: https://www.globalsign.com/en/repository/GlobalSign_Client_A...

At first none of them were warm at the idea of providing an ACME endpoint. I'm assuming part of it is the cost of implementing it but they probably liked the stickiness of their custom APIs too tied to million dollars contracts.

Nowadays they all implement ACME. At some point, they where effectively forced to implement it to acquire new customers and keep their existing base around because nobody would accept poorly designed custom made protocol anymore.

Not sure if there is a point to "keep things in Europe" when it come to certificate authority.

- LetsEncrypt don't have the private key tied to your certificate - Any of the Certificate Authorities could potentially emit unauthorized certificate

Your only protection for all of these problems is HPKP. If you prefer to keep things in Europe, keep that pinned private key in Europe, but the rest doesn't matter.

That said, it's pretty nice that LetsEncrypt forced the ACME protocol on this industry. Not only it create redundancy with mostly interchangeable alternatives but before ACME, there was no way to fully automate certificate provisioning cleanly.

It was a red herring the entire time. At Shopify we made experiment regarding conversion between regular certs and EV before they stop being displayed and there was no significant difference. The users don't notice the absence of the fancier green lock.

As someone who live in Quebec this make sense to me and apparently the vast majority of the population. There is more opposition to vaccine mandate to access retail store than taxing the unvaccinated.

I don't think anybody would be surprise to hear that smokers pay a tobacco surcharge for their health insurance in the US.

High pressure from covid patient is causing healthcare system cost to skyrocket. You have the 10% of unvaccinated who are causing for 45% of that load increase.

In a system with universal healthcare system, where everyone pay for the system with taxation, surcharge have to happen with taxes. If a few decide to get vaccinated great but I don't think it's the point. Honestly, they haven't announced the specific but I doubt the tax will be high enough to account for the real healthcare cost of population vaccinated.

It wouldn't break encryption because you don't give away the private key when requesting a certificate from a CA.

It would definitively compromise the identity/trust part of it.

This article is quite interesting but I'm not too sure why the author felt the need for such a pedantic attitude toward the guy from the video. Its presumptuous without adding much to the discussion.

Why is this post get so many vote? I understand that this guy is famous for some of the stuff he did, but hey... hacker news is news for hacker, right? not news about hacker?