HN user

tomwas54

1,350 karma
Posts73
Comments10
View on HN
noyb.eu 22d ago

US Supreme Court Just Blew Up EU-US Data Transfers

tomwas54
263pts194
blog.dbuglife.com 4mo ago

Reverse Engineering Action's Cheap Fichero Labelprinter

tomwas54
2pts1
modal.cx 4mo ago

Towards a Sovereign Mobile Stack

tomwas54
4pts0
berthub.eu 6mo ago

AWS and Microsoft are selling more than cloud services

tomwas54
6pts0
noyb.eu 7mo ago

EU-US Data Transfers: Time to prepare for more trouble to come

tomwas54
16pts2
berthub.eu 7mo ago

Hello Europe, Joe Biden is gone

tomwas54
10pts4
noyb.eu 11mo ago

Court decides "Pay or Okay" on DerStandard.at is illegal

tomwas54
47pts35
berthub.eu 2y ago

How sovereign do you want to be?

tomwas54
9pts0
educatedguesswork.org 2y ago

A Hard Look at Certificate Transparency, Part II: CT in Reality

tomwas54
3pts0
www.postfix.org 2y ago

SMTP Smuggling Mitigations in Postfix

tomwas54
5pts0
emilymstark.com 2y ago

E2EE on the Web: Isolating Plaintext

tomwas54
2pts0
blog.benjojo.co.uk 3y ago

Driver adventures for a 1999 webcam

tomwas54
429pts74
educatedguesswork.org 3y ago

Architectural Options for Messaging Interoperability

tomwas54
3pts0
www.nytimes.com 3y ago

How the Netherlands Is Taming Big Tech

tomwas54
3pts1
emilymstark.com 3y ago

What's the right UX for an expired certificate?

tomwas54
55pts101
thevaluable.dev 3y ago

Diving Deeper in Vim Regular Expressions

tomwas54
2pts0
arstechnica.com 3y ago

Hours of inaction from Amazon cost cryptocurrency holders $235,000

tomwas54
1pts0
educatedguesswork.org 3y ago

On the Security and Privacy Properties of Public WiFi

tomwas54
2pts0
ubuntu.com 3y ago

Systemd Support Lands in WSL

tomwas54
2pts0
swarm.ptsecurity.com 3y ago

Discovering Domains via a Time-Correlation Attack on Certificate Transparency

tomwas54
2pts0
thevaluable.dev 3y ago

File Management Tools for Your Favorite Shell

tomwas54
2pts0
emilymstark.com 3y ago

Certificate Transparency is not a replacement for key pinning

tomwas54
2pts0
educatedguesswork.org 4y ago

Understanding the Web Security Model, Part VI: Browser Architecture

tomwas54
2pts0
educatedguesswork.org 4y ago

Understanding Online Identity

tomwas54
3pts0
educatedguesswork.org 4y ago

Notes on Multiple Encryption and Content Filtering

tomwas54
2pts0
educatedguesswork.org 4y ago

Understanding the Web Security Model, Part V: Side Channels

tomwas54
4pts1
blog.assetnote.io 4y ago

Cloudflare Pages, part 2: The two privescs

tomwas54
1pts1
educatedguesswork.org 4y ago

Understanding the Web Security Model, Part IV: Cross-Origin Resource Sharing

tomwas54
1pts0
educatedguesswork.org 4y ago

End-to-End Encryption and Messaging Interoperability

tomwas54
19pts5
educatedguesswork.org 4y ago

End-to-End Encryption and Messaging Interoperability

tomwas54
33pts0

For ~40 minutes, it was also impossible to SSH into any Compute Engine instance that uses OS Login for authentication, but it seems to have been resolved in the last few minutes.

Ubuntu 18.04, the newest LTS, recently backported OpenSSL 1.1.1 to its stable package repository.

Because of this my personal webserver, running nginx on Ubuntu 18.04, started offering TLS 1.3 without any manual action on my part, because the server is configured to auto-apply updates from these repositories.

No, it doesn't. As mentioned in the article, the attacker successfully requested a TLS certificate for the hostname, which was possible because he could pass a CA's domain validation.

I'm not entirely sure, but I think HPKP could have prevented this for returning customers, because Fox-IT would have been able to pin the key of their own certificate. Then the new certificate used by the attacker would have been rejected by the customer's browser.