For the best experience on desktop, install the Chrome extension to track your reading on news.ycombinator.com
Hacker Newsnew | past | comments | ask | show | jobs | submit | history | rot256's commentsregister

For LetsEncrypt, routing is authentication: if packets routed to the IP in the A record end up at your place, you can get a cert for that domain.


DNSSEC and DNS-01 challenges might do the trick at the cost of significant effort, provided LE could be directed to check, similar to the way MTA-STS works.


Let’s Encrypt has been doing DNSSEC validation for years. DNSSEC could have prevented the jabber.ru MITM attack.


I think that way to solve BGPs security problems might be to use a new cryptographic hammer, "Proof-Carraying Data", where messages come with cryptographic proofs that they were produced correctly. This allows you to basically just run BGP, but every AS proves that it ran it correctly. The proofs take constant time to verify, regardless of how large the network is, or how many hops the routing message has taken. Feasibility is helped by latency not being super critical in BGP and BGP being a pretty simple protocol; which makes computing these proofs plausible.

https://rot256.dev/post/bgp-pcd/

Proof-carrying data has come a long way in the last 10 years.

EDIT: you would still need RPKI, but not BGPSec


This seems useless and misguided? This training material contents is clearly AI generated, if people can't be assed to write a book, then why should people read it?

Maybe it's my teaching background, but there is something uniquely soulless about teaching humans with AI slop passed off as a course; this is the stuff of "Amazon AI generated book spammers" and to be honest, I expected better from Microsoft.

If people wanted LLM output, they can generate it themselves...


Rustlings superiority! Glad I did this back in 2019, it taught me a lot.


PipePipe? https://pipepipe.dev/

EDIT: also skips sponsor segments.


Seconded, pipepipe is excellent


As pointed out by Mark Galeotti, both the sources are less than reliable...

https://podcasts.apple.com/gb/podcast/in-moscows-shadows-120...

Whether dead or not, it is frankly disappointing that western media lends so much credence to sources which have been consistently wrong and made outright ridiculous claims before. Even if they try hedging it by calling them rumors, until more reliable sources emerge it is just noise...


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search:

HN For You