Hacker Newsnew | past | comments | ask | show | jobs | submit | AtNightWeCode's commentslogin

It would be simple today to abolish the use of CAs but it just a big cargo biz that makes money on nothing as usual based on peoples incompetence. For 99% of all sites today security would be handled better without CAs. People simply don't understand how it works.

All that was true until fairly recently. Today, you can get certificates for free and there’s more transparency than ever thanks to CT.

What would you suggest as an alternative? TOFU?

I could see that for local applications (e.g. making mDNS/.local and private IP certs TOFU capable by default would be amazing, and maybe even for some explicit hobbyist public TLDs?), but I don’t think I’d love it for my bank or email provider.


> It would be simple today to abolish the use of CAs […]

The main technical way I know of doing this would be by putting TLS public keys in DNS (DANE, RFC 6698), but then you have to make sure that DNS packets are not fiddled with, so you need to bring in DNSSEC.


Exactly, and in some ways, DNS is even more centralized. At least there’s a choice of CAs independent of TLDs.

That's a false concern, because the names the CAs are certifying are still DNS names. If your TLD reasssigns your DNS name out from under you, or even if your TLD starts returning false data on only selected queries, the CAs will be happy to issue a cert to the new holder.

It would be great to have a widely-recognizable pseudodomain out there where the names were key hashes. It would actually graft really easily into DNSSEC. The zone format doesn't have to change at all; you just declare that if the KSK hash matches the domain label under this specific TLD, you don't need to check upstream of that. Then you add a P2P protocol for getting the actual data, and start slowly pushing that protocol down the resolver tree to incrementally decentralize everything.


The whole point with a CA is that you have a neutral third party participant. Kinda broken no matter how you look at it. Especially in this case.

CAs is the problem. Not who runs them...

ClickHouse I would say is more for analytics and data warehouse types of loads. So not a direct competitor to those tools except maybe for Pinot.

It is very easy to ingest data into CH. We connected exchange topics and it just worked with zero code.

But the thing with CH is that it is pretty much a Russian product so you should not use it for production anymore.


I would like to see some sources on your claim about it being Russian. It is incorporated in the US with most developers in Amsterdam.

After the invasion of Ukraine they stayed silent for a while but that was because they needed to allow there developers to get out of Russia. Many of them are Ukrainians including the CTO and founder. As soon as it was safe for there team they took a very firm stance against Russia with Ukrainian flags on the website and written statement from the team.

I am not aware of any Russian influence currently.


It was created at Yandex, the biggest techcorp in Russia, by Alexey Milovidov among others. He is still the CTO there. So I will stay away. There are many good alternatives to pick.

Did you ditch nginx for the same reason?

We’ve come at a time in which we fear exploring projects like Apache Doris because we fear that OSS might be used in malicious ways by state-backed actors.

Why on earth is Shopify not just a web wrapped in an app like most apps? I mean, they implement most of that stuff for the desktop anyway.

There's quite a bit of research out there showing that application performance has a material impact on checkout conversion rate, so a single platform optimization potentially improves checkout for millions(?) of storefronts.

Google research from a decade ago that might as well been that their bot did not want to wait for pages to load. The performance difference between React native and a web wrapped in an app is pretty much zero today.

Seems like you've never had to worry about accessibility in hybrid apps...

We booted react native like 10 years ago and there is not much a web does not solve. We even did solve it for the desktop users anyway even before. A simple app as Shopify with mostly static content should not be any problem to build as a web.

Off topic but. I never liked how tailwind looks but that font. Inter Variable. That is a new level of garbage.

Cloudflare is my guess. They all use it. Maybe some bad DNS config that choked parts of their systems. Not necessarily CFs fault.

As I recall it. This was mostly a money scam that targeted private users with ads like "make sure to claim to your .name domain so no one else does it and use it to impersonate you". It was stupid from the beginning and never took off.

Things like this happens from time to time and yet people insists on using stupid TLD:s just because of "cool" suffixes.

The problem with gangster music was a hack I believe. Spotify never admitted it but I have many friends that had that problem. I did not.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: