Hacker Newsnew | past | comments | ask | show | jobs | submit | mholt's commentslogin

They are not in control of the US president.

I'm pretty sure that the .org TLD can be shut off by the US at any point in time.

That’s not relevant though. These CAs will gladly give you a .se/.dk/.in/whatever cert as long as validation passes.

I hope so, but can we really be sure that .se or .de would still work in such a scenario? Is the TLD root management really split up vertically or is the (presumably US-based) TLD parent organization also the final authority for every country TLD?

It would be nice to at least have a very high level contingency plan because in worst case I won't be able to google it.


Not sure what the exact concern is here. So far, virtually all countries on Earth are still represented in DNS. Venezuela, Iran, Somalia, etc etc.

You can also read a lot of anti-Trump articles and comments on countless web-sites, some under .com and some under other top-domains. As lunatic as Trump is, he hasn’t shut that down.

“Is the TLD root management really split up vertically”

AFAIK, yes, it is.

But if the global DNS would somehow break down I guess you either have to find an alternative set of root servers. Or communicate outside of the regular Internet. Such an event surely would shock the global economy.


That's actually a really good point. Totally missed it.

Lets Encrypt do not control the US president.

You could argue that The Don in charge of the US is in control of letsencrypt


Yeah, it's a bit far fetched but after Cloudflare CEO basically threatening to cut off Italy I was wondering what would happen if US really invades Greenland.

A simple windows to linux migration is not enough. If certificates expire without a way to refresh you'd either need to manually touch every machine to swap root certificates or have some of other contingency plan.


Remember that there are lots of CAs, and quite many of them are based outside of the US. Those CAs currently do not offer ACME services for free, but there’s nothing stopping them from doing so.

I would say that the WebPKI system seems to be quite resilient, even in the face of strong geopolitical tension.


LE has 2 primary production data centers: https://letsencrypt.status.io/

But in general, one of the points of ACME is to eliminate dependence on a single provider, and prevent vendor lock-in. ACME clients should ideally support multiple ACME CAs.

For example, Caddy defaults to both LE and ZeroSSL. Users can additionally configure other CAs like Google Trust Services.

This document discusses several failure modes to consider: https://github.com/https-dev/docs/blob/master/acme-ops.md#if...


It's less about IP address transience, and more about IP address control. Rarely does the operator of a website or service control the IP address. It's to limit the CA's risk.

We've supported it for about a year!

Very nice, thank you guys!

It works, but as another comment mentioned there may be quirks with IP certs, specifically IPv6, that I hope will be fixed by v2.11.

Don't rockets also start with the same horizontal velocity though, since nothing canceled it out when it got off the launch pad?

It would be like jumping, and finding yourself ~250-400 meters away from where you lept by the time you landed.

That said, neat project, and way fun learning experience. Good job.


Discover (Card/Bank) also announced recently that they are stopping their dark web report service. I wonder if they just used Google, or if it's a coincidence...


I get the whole scarcity thing -- and I've even asked Andrew about this -- because if I'm willing to give him my money after saving up for it, but it sells out first, wouldn't he make more money if he took mine then?

But, I guess we just have to have an art budget with some money already set aside if we want to jump on opportunities when artists do this. I respect it, but yes it's a bit inconvenient.

PS. The full, uncropped shot is even more incredible IMO: https://cosmicbackground.io/cdn/shop/files/Overhead_black_li...


>wouldn't he make more money if he took mine then?

Marketing is far more complex then you're giving it credit for. Take the Factorio game, they don't have sales ever so the best time to buy the game is now. This both keeps people that buy things on sale even if they don't like it from getting it, and keeps other people that may wait for a sale and forget about it from not buying it now.

The same is true for limited numbers. Some people may want it and put it in the cart, but never actually buy it because there is no strong binary motivator. This motivator can actually increase sales quickly and ensure you dont hold inventory for long periods of time.

Also things are commonly bought in batches to reduce price. Your one painting later could either be much more expensive or require the artist to buy 50/100 units at once that risk becoming stuck inventory.


> because if I'm willing to give him my money after saving up for it, but it sells out first, wouldn't he make more money if he took mine then?

If the piece sold out, he made his money.


If I were him I would put out a limited edition at a fixed price like he currently does, but then add $X0? $X00? cumulatively to the price of each additional unit sold.


Peter Lik has a strategy sort of like this. It's still a limited edition of, say, 100, but the price increases as the edition sells out. The last print to sell may be 100x or more the first.


You can't directly compare the two scenarios. Without the incentive to buy due to limited availability, he might have never sold as many copies, or at least it might have taken much longer.


Just print it and glue stick it to your wall


It's the same situation with $1000 theater tickets. You aren't the market.


Great question. Servers should ship with secure defaults.


Make Error Messages Great Again

(Sorry, I hate that it has a political reference, but it's really how I feel about this. How the heck is that error message supposed to mean anything to anyone?)


Sometimes the message is different. I think it depends on the recipient server. Trying to scp to a dropbear ssh server on a router gives

   sh: /opt/libexec/sftp-server: not found
   scp: Connection closed
The -O resolution works.


Yeah, regardless of how one feels about the design decision to fail without fallback, the messaging seems like an oversight.


Yes, please and thanks. And I want a single line explaining how it is failing so I can copy paste it into Google and make the trivial fix. I don't want the beginning of a novel. Java was famous for dumping not only the relevant error message but it's entire family history since birth.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: