Ahh yes, the feeling of issuing a TLS cert and watching all of the bots (that just learned about my hostname via Certificate Transparency PreCerts) racing and climbing over each other to be the first one to fuck up whatever application they are looking for. Go bots! Go!
filippo@abyssdomain...
replied 31 Oct 2023 23:51 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/PHJ7LC4M5qc2K3g438
@benjojo I wonder if there’s an argument for logs intentionally delaying availability of new leaves. They have 24h to merge them.
erincandescent@queer..
replied 31 Oct 2023 23:56 +0000
in reply to: https://abyssdomain.expert/users/filippo/statuses/111332314131370529
filippo@abyssdomain...
replied 01 Nov 2023 00:13 +0000
in reply to: https://queer.af/users/erincandescent/statuses/111332333513390307
@erincandescent @benjojo Which might be too late to use default credentials and take over unconfigured instances
cks@mastodon.social
replied 01 Nov 2023 01:29 +0000
in reply to: https://abyssdomain.expert/users/filippo/statuses/111332314131370529
@filippo @benjojo As a sysadmin, I feel torn. On the one hand, a delay might help me if my new server could have issues (but someone might hit it anyway, depending). On the other hand, a delay hurts me if someone has gotten a certificate for one of my hosts, since they have 24 hr+ to use the certificate. (I tend to come down on the side of 'publish now' in the end, partly because I've seen new web servers get hit right away even before CT logs.)
benjojo
replied 01 Nov 2023 12:17 +0000
in reply to: https://mastodon.social/users/cks/statuses/111332699828747197
@cks @filippo @erincandescent IMHO there is likely a good argument for a mid-way 1hr delay. Solves the "I just setup PHPMyAdmin an- oh it's gone" problem, while not delaying the process of notifications by too much. All of this is made quite brutual by "AutoCert" based stuff, where certs are issues far far faster than the infra behind the cert can safely take requests (then there is another argument on "why is your setup.php file unsafe by default")
29821632@noc.social
replied 01 Nov 2023 07:43 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/PHJ7LC4M5qc2K3g438
@benjojo I always felt uneasy about the public logging of possibly internal hosts, even from a bssic information disclosure and customer confidentiality perspective. I tend to try and obtain wildcard certs through ACME whenever possible to limit that.
benjojo
replied 01 Nov 2023 12:14 +0000
in reply to: https://noc.social/users/29821632/statuses/111334170893124400
In general yeah, you should be doing wildcard cert. But also in general, if the DNS name being unknown was the only thing that was keeping bad things from happening, you are in some seriously bad shape :) [Full disclosure: I'm not really a neutral player in this debate, since bgp.tools uses some of this stuff to it's advantage]