HN user

devrand

741 karma
Posts0
Comments182
View on HN
No posts found.

It seems like you can also finance it interest free through Apple themselves without being locked to a carrier.

This article links to a Forbes article that states it was a leak of a Saleforce instance that contained contact information about small and medium businesses.

This PCWorld article seems to be taking that to mean that every single gmail account (2.5B) is at risk with nothing to support that claim.

Puget Systems has similar publications covering their experience building client systems, though not always in the same level of detail. They also have PugetBench to benchmark systems in real-world applications/workflows.

It was dead long before Google was involved. Pebble filed for insolvency back in 2016 with Fitbit acquiring much of the assets. It was dead at this point. 5 years later Google bought Fitbit.

I presume it's in a company's interest as L-1 visas cannot be transferred so you're tethered to them.

At least in the short term they probably would. Why not take the basically free money?

Longer term, yeah they'll probably just make their own search engine.

I highly doubt Google would give Mozilla anything. The only reason I think they would would be to appease Chrome monopoly concerns, but I don't think Chrome is even at risk of that. It's not the default browser on any platform other than ChromeOS and some Android devices.

Presumably these deals with Google will be nullified, but can the various browsers just make new deals with someone else? Can Microsoft just just swoop in and make a deal with Apple/Mozilla/Samsung? Mozilla is going to be desperate to find a new partner...

It sounds like they intended to use it as the primary e-mail domain for himself and family. They claimed that they had already switched to using it.

However, the total window of time here is small. They registered the domain in late November 2023 and this UDRP was filed in late February 2024. It also sounds like initial contact to try to acquire the domain occurred in early December 2023... so only a couple days after it was registered.

I think they generally give a lot of weight to someone who registered the domain well ahead of the said company registering their mark. Though you might run into trouble if you started using the domain in bad-faith against that company (ex. impersonating them).

In your example, you had that domain well in advance, it's your self-identified pseudonym that predates said mark, and it's actively being used to host your personal website. That seems like a pretty strong defense.

That's one option. Alternatively, they could just delegate the _acme-challenge with a CNAME.

If clientportal.somebank.com is actually run by somesaas.com, they can define CNAME _acme-challenge.clientportal.somebank.com --> [some_key].domainvalidations.somesaas.com

When the SaaS vendor needs to request a new cert, they set the appropriate TXT record on [some_key].domainvalidations.somesaas.com.

I think they're suggesting that 1 year certificates are still at the point where people can just manually rotate them as they expire. If you keep reducing the lifespan, to say 90 days, that starts to tip the scale. You'll be spending too much human time manually rotating certificates that it will make financial sense to just automate the process.

If the process is automated then revocation can be automatically handled as well (so long as ARI gains traction).

"Never had to deal with 3rd party SaaS vendors certificate pinning requiring service tickets to change"

I think this tends to fall into "probably shouldn't have been using Web PKI". I can't immediately think of a reason why you'd need a publicly trusted certificate if you're pinning a specific public key.. at that point who cares who signed it?

I do agree that there are real costs with rotating certificates that ultimately may make it impossible for an organization to complete that work in the revocation window. That is very much an area that needs further automation developed and more importantly, for it to actually be adopted. I believe that's what ACME Renewal Information is attempting to address.

"but in those cases the business users are ok with an outage to remediate a real security issue"

Ideally yes, but that might be the same point you find out the certificate was used in some critical system (let's say Air Traffic Control like a previous CA tried to claim). They still may very well not be okay with the revocation despite the security issue. _Those_ are the people that need to stop using these certificates and there's really no way to weed them out until a revocation actually needs to occur.

"Digicert screwed up their system implementation and made their customers suffer."

And those customers are right to be mad at DigiCert. They probably don't have a legal basis to challenge as the subscriber agreement explicitly permits immediate revocation without prior notice, but they can certainly take their business elsewhere.

"It's also disheartening to see browsers in the CA consortium ignore the CA resolutions as well. Like how everyone voted for 2 year certs and Apple did their own thing anyways. Any punishment for Apple come? So why pick on the others?"

Admittedly I'm not very familiar with the various root programs and the obligations they have with CAs, but it doesn't seem unreasonable that root programs would be free to impose stricter requirements then the BRs.

Though I do find it two-faced for Apple to vote for Ballot 193 only to then impose a stricter requirement. At the very least they should have abstained.

Respect to them for actually abiding by the BRs. Most CAs just shrug [1] and [2] say [3] it's [4] too [5] complicated [6], or just lie and claim planes will start crashing [7]. It's really disheartening that publicly trusted CAs just ignore their contractual obligations however they see fit.

Ideally these companies should have response plans in place to prioritize certificate rotation. They can use this as a fire drill for what would happen if there were a key compromise.

Alternatively, if companies cannot handle the rotation, then they likely should re-evaluate if WebPKI is even appropriate for their use-case.

[1] https://bugzilla.mozilla.org/show_bug.cgi?id=1885568

[2] https://bugzilla.mozilla.org/show_bug.cgi?id=1898848

[3] https://bugzilla.mozilla.org/show_bug.cgi?id=1910237

[4] https://bugzilla.mozilla.org/show_bug.cgi?id=1896053

[5] https://bugzilla.mozilla.org/show_bug.cgi?id=1896553

[6] https://bugzilla.mozilla.org/show_bug.cgi?id=1877388

[7] https://bugzilla.mozilla.org/show_bug.cgi?id=1903066#c48

They’re saying that once you’ve sold certs to governments, distrusting that root will deny people access to government resources. They’re merely using “.gov” as a proxy for “some government”.

Also roots can be TLD constrained, typically to ccTLD(s).

I agree, despite the fact that I use OTA TV. I would prefer to just get an internet stream, but I need to pay like $70/mo+ to get the content (plus a ton that I don't want), and it still has ads.

I would be willing to pay a reasonable price to access a live CBS/NBC/ABC/Fox stream, but no one (legitimately) offers that. So OTA it is.

It seems pretty clear to me:

How precisely does Hetzner calculate the hourly billing?

The beginning of the hourly billing starts as soon as the product becomes available to you.

So for a dedicated server you start paying once the server has been commissioned to you. You stop paying once you return it.

I use this pattern but I'm starting to move away from it. Some things just don't work (ex. linking accounts between companies) and it also throws customer service agents into a panic when they see their own company name in the e-mail address.

I'm also not sure it gets me that much. I do get to see how was compromised or sold my data, but most of that just goes to spam anyway. I also usually find out about the compromises from other sources anyway.