Sorry, but are you familiar with fpm? All of what you mention is supported with fpm (you can have multiple post install files added...etc).
HN user
yourabi
http://yousefourabi.com
Just an engineer building things.
Snitch: SSL auditing and alerting - https://snitch.io
FPM pretty much solves this https://github.com/jordansissel/fpm
I might be overlooking something obvious but I don't see an address in your profile (and I'd prefer not to guess). You can reach me at gmail (same user).
Thanks! Do you have first hand experience?
Gracenote: Emeryville, CA (SF Bay Area) - Full time, No remote - on-site only, relocation possible, no visa sponsorship possible.
Interested in working on crawlers and distributed systems? Interested in functional languages like Clojure and Scala? Gracenote is hiring a senior software engineer.
Gracenote is the top provider of entertainment information, creating industry-leading databases of TV, movie, and music metadata for entertainment guides and applications. Our technology serves billions of requests daily to hundreds of millions of devices around the world.
You’ll be working a set of crawlers responsible for discovering, acquiring and storing data and applications that make use of that data.
If interested email me at this username at gracenote. No 3rd parties, no recruiters please.
Responsibilities: - Write well-designed, well-tested code that performs well
- Design, implement, and own new systems – from design to operations
- Occasional on-call operations / support - Reduce technical debt in existing systems (refactoring, testing…etc)
- Proactively look for ways to make our software more scalable, reliable and fun
- Help change the way we think about solving problems
Requirements: - Strong background in Java, Ruby, Python or another OO language (our current stack)
- Solid understanding of the full web technology stack
- Familiarity with a variety of (relational and non-relational) databases/data stores
- Experience with AWS (or another infrastructure platform)
Pluses: - Experience with web crawling, scraping
- Experience with Clojure, Scala, Hive, or Go
- Experience with functional programming, functional architectures
- Experience with data processing architectures with Kafka, Storm, or Spark.
- Experience with ZooKeeper, etcd or similar
- Experience with Chef
- GitHub repo / Open Source
Gracenote: Emeryville, CA (SF Bay Area) - Full time, No remote, relocation possible, no visa sponsorship possible.
Interested in working on crawlers and distributed systems? Interested in functional languages like Clojure and Scala? Gracenote is hiring a senior software engineer.
Gracenote is the top provider of entertainment information, creating industry-leading databases of TV, movie, and music metadata for entertainment guides and applications. Our technology serves billions of requests daily to hundreds of millions of devices around the world. You’ll be working a set of crawlers responsible for discovering, acquiring and storing data and applications that make use of that data.
If interested email me at this username at gracenote. No 3rd parties, no recruiters please.
Responsibilities: - Write well-designed, well-tested code that performs well
- Design, implement, and own new systems – from design to operations
- Occasional on-call operations / support - Reduce technical debt in existing systems (refactoring, testing…etc)
- Proactively look for ways to make our software more scalable, reliable and fun
- Help change the way we think about solving problems
Requirements: - Strong background in Java, Ruby, Python or another OO language (our current stack)
- Solid understanding of the full web technology stack
- Familiarity with a variety of (relational and non-relational) databases/data stores
- Experience with AWS (or another infrastructure platform)
Pluses: - Experience with web crawling, scraping
- Experience with Clojure, Scala, Hive, or Go
- Experience with functional programming, functional architectures
- Experience with data processing architectures with Kafka, Storm, or Spark.
- Experience with ZooKeeper, etcd or similar
- Experience with Chef
- GitHub repo / Open Source
Using Go for the backend of https://snitch.io
1. Use Godeps to vendor your deps 2. Use Logrus for logging 3. Figure out a deployment script early one. I have a Rake script that uses chef-api to lookup current production nodes, cross compiles locally and scp's the resulting binary out and restarts the process
Gracenote: Emeryville, CA (SF Bay Area) - Full time, No remote, relocation possible, NO visa sponsorship possible.
Gracenote is the top provider of entertainment information, creating industry-leading databases of TV, movie, and music metadata for entertainment guides and applications. Our technology serves billions of requests daily to hundreds of millions of devices around the world.
Interested in working on crawlers and distributed systems? Interested in functional languages like Clojure and Scala? Gracenote is hiring for several positions (junior and senior).
You’ll be working a set of crawlers responsible for discovering, acquiring and storing data and applications that make use of that data.
If interested email me at this username at company. No 3rd parties, no recruiters please.
Responsibilities:
- Write well-designed, well-tested code that performs well
- Design, implement, and own new systems – from design to operations
- Occasional on-call operations / support
- Reduce technical debt in existing systems (refactoring, testing…etc)
- Proactively look for ways to make our software more scalable, reliable and fun
- Help change the way we think about solving problems
Requirements:
- Strong background in Java, Ruby, Python or another OO language
- Solid understanding of the full web technology stack
- Familiarity with a variety of (relational and non-relational) databases/data stores
- Experience with AWS (or another infrastructure platform)
Pluses:
- Experience with web crawling, scraping
- Experience with Clojure, Scala, Hive, or Go
- Experience with functional programming, functional architectures
- Experience with data processing architectures with Kafka, Storm, or Spark.
- Experience with ZooKeeper, etcd or similar
- Experience with Chef
- GitHub repo / Open Source
Gracenote: Emeryville, CA (SF Bay Area) - Full time, No remote, relocation possible, visa sponsorship possible.
Interested in working on crawlers and distributed systems? Interested in functional languages like Clojure and Scala? Gracenote is hiring for several positions (junior and senior).
Gracenote is the top provider of entertainment information, creating industry-leading databases of TV, movie, and music metadata for entertainment guides and applications. Our technology serves billions of requests daily to hundreds of millions of devices around the world.
You’ll be working a set of crawlers responsible for discovering, acquiring and storing data and applications that make use of that data.
If interested email me at this username at gmail. No 3rd parties, no recruiters please.
Responsibilities:
- Write well-designed, well-tested code that performs well
- Design, implement, and own new systems – from design to operations
- Occasional on-call operations / support
- Reduce technical debt in existing systems (refactoring, testing…etc)
- Proactively look for ways to make our software more scalable, reliable and fun
- Help change the way we think about solving problems
Requirements:
- Strong background in Java, Ruby, Python or another OO language
- Solid understanding of the full web technology stack
- Familiarity with a variety of (relational and non-relational) databases/data stores
- Experience with AWS (or another infrastructure platform)
Pluses:
- Experience with web crawling, scraping
- Experience with Clojure, Scala, Hive, or Go
- Experience with functional programming, functional architectures
- Experience with data processing architectures with Kafka, Storm, or Spark.
- Experience with ZooKeeper, etcd or similar
- Experience with Chef
- GitHub repo / Open Source
You can donate to the FreeBSD Foundation here: https://www.freebsdfoundation.org/donate/
Help fund an open-source OS that is foundational in a lot of infrastructure and get a nice tax write-off!
Disclosure: I'm the founder of snitch.io - a fully automated ssl monitoring service that launched last month.
This is interesting. I suspect it will appeal to a certain type of person / use-case - similar to LogStash vs Paper trail / Logggly. (I use Paper Trail and love it - check it out.)
However, I'm not really worried about it since many people want automated monitoring, auditing, and alerting that "just works" without having to roll their own client - and then monitor that client.
Doing this at scale is hard. Doing it with frequency/interval guarantees is even harder. I've put considerable effort into a scalable architecture and self-monitoring.
I wish Ivan the best of luck. On a related note if you want to learn about SSL/TLS I highly recommend Ivan's book "Bulletproof SSL and TLS". It is great.
Snitch is already doing a few things SSL Labs isn't doing (supporting custom ports, and IMAPS) and over time the differences in our services will become more and more apparent. I'm very excited about my product roadmap :-)
This is still a pain point for many people and there are many unsolved problems that I'm having a lot of fun working on.
Happy to answer any questions - shoot me an email. This username at currylabs.com
Not really inconsistently. Firefox, Safari and IE all do this. Firefox, for example, will wait up to 10 seconds for an OCSP response (https://wiki.mozilla.org/CA:ImprovingRevocation)
That article cites Adam Langley - a respected engineer at Google who has worked on Chrome and parts of Go. Chrome is wildly lax with certificate revocation. Don't believe me? Browse to https://revoked.grc.com from Chrome. It is true that if someone can MITM they can block CRL/OCSP requests...but browsers (including Chrome) made the choice of 'soft-failing' and thus making it an attack vector. OCSP stapling and the proposed "OCSP Must-Staple" (https://tools.ietf.org/html/draft-hallambaker-muststaple-00) solve this problem. With all due respect to Adam, it seems a little peculiar to say revocation checks don't work when they're broken by design in the browser he worked/works on.
Chrome is the only browser that skips revocation checks for DV certificates but it still does OCSP for EV certs. Chrome has the concept of CRLsets - but these have been shown to only capture a very small portion (<1%) of revoked certificates.
Firefox has the option to hard-fail if the OCSP request isn't verified. This should be the default behavior, but the fear is that too few people understand this and would migrate to another browser if SSL secured sites randomly failed to load sometimes. Note: this is vastly preferable, in my opinion, to loading a site with a certificate of unknown status.
Hi!
The screenshots show you what the app looks like. And to your point all accounts come with a free 14-day trial.
I may eventually add a free "one-off" audit - but the value in a service like Snitch is that something is constantly monitoring and alerting.
Happy to answer any other questions - you can email me anytime. This username at gmail or currylabs.com
You should never send a private key. Private keys are private. That is a poorly written tutorial - written by someone that may not understand PKI.
You generate the CSR and send that.
It is rarely that clean-cut which is why these are not defaults in server configs.
If you're hosting an API that has older / embedded clients you may HAVE to support SSLv3 during a migration plan...etc
Yep - getting this right is hard.
Couple of points about the article.
Browsers verify SSL certificates for revocation (OCSP). This is an ongoing service that has a direct impact on latency - so SSL is an ongoing service very much like DNS. However, most people don't realize this.
Also you send in a CSR - certificate signing request - not CRT (which is usually short-hand for certificate).
Also it gets worse - A recent OpenSSL vulnerability would still allow SSLv3 even if it was configured with "no-ssl3": https://www.openssl.org/news/secadv_20141015.txt
This is why I built https://snitch.io - security and SSL secured sites in particular are moving targets and not "fire and forget". You really need an external process monitoring and auditing your secured site.
This is why I built https://snitch.io - security and SSL secured sites in particular are moving targets and not "fire and forget".
Snitch already generates an alert if a site doesn't use TLS v1.2 - I'll be watching this announcement closely and adding alerts as needed.
Hi. You don't use SSL for the signup / login form :-(
I use ZooKeeper in production for snitch.io.
There are some interesting new alternatives such as etcd / serf/consul - but at the time ZooKeeper had the best track record (under Jepsen analysis). Things might have changed since then.
Aphyr has done a bunch of analysis of these systems part of his Jepsen tool: http://aphyr.com/tags/jepsen and http://aphyr.com/posts/291-call-me-maybe-zookeepe
If you are going to use ZooKeeper I strongly suggest looking at both Apache Curator and Netflix Exhibitor (they are complimentary).
The examples bundled with ZK don't handle all errors/edge cases...
Curator is a library of common patterns available to use mostly out of the box.
Exhibitor is a ZooKeeper "aware" supervisor system: https://github.com/Netflix/exhibitor
Also always remember your ensemble should have an odd number of nodes (3,5,7)
Thanks for the clarification.
I was wondering if you were also going to mention that you are VoodooAlerts' founder?
I, personally, think it is poor form to advertise features that don't exist while pretending to be a customer of VoodooAlerts.
I wish you the best of luck with VoodooAlerts!
This looks interesting - I'll take a closer look.
You might want to check out the logrus package - which I'm using and pretty happy with. https://github.com/sirupsen/logrus
Logrus lets you add structured k,v fields so you do have to mess around with fmt and also has hooks to support things like sending logs to syslog or remote exception handling services.
Thank you for visiting Snitch.io. Unfortunately, your statements are still not correct.
I signed up for a free account on VA and put in a site with a revoked SSL certificate. It has not generated an alert. It has been over 12 hours. It is still prompting me to insert the JS on my site, by the way.
As to your second point. Snitch isn't simple alerting.
It runs a full range of tests on an SSL certificate: checking for expiration, checking for revocation, checking that all of the intermediate certificates have not been revoked, checking the certificate is valid for the domain (including SNI), checking that the certificate isn't signed with a weak algorithm such as SHA-1 that Chrome is about deprecate, checking that the certificate has not been changed (incorrect server config, malicious intent...)
Snitch is not targeted at people who just need to know if their site is up or down.
If you are are a business and users browsing to your site get a big red warning in their browser because your SSL certificate is expired/revoked/weak/misconfigured - that is a problem and you lose money. That is what Snitch is addressing.
There are some pretty crucial and obvious differences between these two products.
Does DigiCert provide any guarantees on how often they monitor your certificates? Do they offer any alert mechanisms other than email? Do they let you monitor certificates that are on your critical path but not necessarily ones you own (partners...etc)
You also mention cost..but since you are not paying them you are not their customer - you are their product.
Snitch is clearly aligned with customers since our goal is to help you succeed at securing your site. Our goal is to make it easy for you (site owner) to do the right thing and provide a good experience to your customers.
Sorry, but that is not factually correct.
These are very different services.
Voodooalerts requires you to place JS on your page. Because of this I am sure they cannot run the full suite of audits that Snitch does.
Thank you for the kind words, msane.
Thank you for that feedback! It is very valuable to hear that I didn't message this effectively - I'll work on improving that.
I'd love to chat more out-of-band - would you mind emailing me (this username at currylabs.com or gmail.com)
Thanks for the feedback!
That is definitely on the roadmap and will go out soon.
Thanks for the feedback.
We're constantly improving and rolling out new features. We're confident that over your question will become less of a question :-)
Thank you for the feedback!
Definitely something we'll consider. Email me if I can help out in any way! hn username at currylab.com / gmail.com
Thank you for the feedback - interesting to hear that your midsize business generated 416 certs.
We do more than you can do by scripting OpenSSL. For example: as far as I know OpenSSL won't warn you if your certificate is signed using SHA1 - one of new several features we're about to push out.
More generally scripting OpenSSL requires knowledge, time and infrastructure many people aren't able or willing to invest (what is monitoring the monitor...)