Conversation

Replying to
I think you would be surprised how often and badly-abused your principals (esp. point 1) are in "DevOps" culture. In which, there is a systemic lack of care and misunderstanding regarding authentication and trust relationships in software. Here are a few examples. (1/n)
2
3
Last example. In this HashiCorp talk (17:56 in video, "Verifying communications" section in transcript), solving SSH host key verification via Terraform and cloud-init is discussed: hashicorp.com/resources/clou That makes both Chris and I happy. (6/n)
1
2
WebPKI offers no real value over DANE TLSA records beyond Certificate Transparency and only Chromium fully enforces CT as of this month when backdating certificates to bypass it stopped being possible (due to 3 year issuance when they started requiring CT). Just started working.
2
1
Show replies