Sigh.
Just got told by a company internal app that it's time to change my password.
Can we please stop with the fake #security? My password is a long string of randomly generated characters. Nobody's going to guess it any time soon.
Signal feed
Post
Remote status
Context
17Sigh.
Just got told by a company internal app that it's time to change my password.
Can we please stop with the fake #security? My password is a long string of randomly generated characters. Nobody's going to guess it any time soon.
As for public CAs requiring TLS certificates to be rotated every 21 seconds, they're doing that because
1. OCSP has epically failed,
2. everybody had to go back to CRLs, and
3. in order for CRLs to not get monstrously huge, certificates must expire quickly so they can be quickly deleted from the CRL.
None of this applies to company internal stuff. Long-lived certificates are still fine in those environments.
Removing the TLS Client EKU is an epic fail and has made a lot of people justifiably upset, but that isn't the same thing as certificate rotation.
I certainly wouldn't mind if someone offered a better alternative to this rapid certificate rotation as it is rather inelegant, but I can't think of one. Can you?
Also, OCSP was even more inelegant. As someone who was dreading having to actually use it in a non-browser client app to validate a server certificate: good riddance.
@i @7666 @argv_minus_one Good luck getting your domain registrar's DNS to cooperate or running your own.
I'm not familiar with DANE, but according to Wikipedia https://en.wikipedia.org/wiki/DNS-based_Authentication_of_Named_Entities it has the rather serious problem that everything is signed with 1024-bit RSA.
This is…not great.
Replacing CAs with DNS server operators sounds like an okay idea in theory, but it'll only work if DNS server operators are prepared for the responsibility, which it doesn't sound like they are. Not yet, at least.
@argv_minus_one @7666 @i DANE's only actual deployment is with MTAs where it is used to ensure you aren't getting downgraded with a MiTM.
And even there it flopped hard because it's annoying to get running and maintain.
Replies
0Fetching replies…
We can't find the internet
Attempting to reconnect
Something went wrong!
Attempting to reconnect