#SSL and #TLS analysis of good and bad aspects of a web server’s setup. #sysadmin
on 02026-06-29#Tom7 #humor #video about malicious compliance with #TLS #protocols.
on 02026-04-13#HN discussion saying Certbot doesn’t work to get #TLS certs for IP addresses, but "lego" does: lego --domains 206.189.27.68 --accept-tos --http --disable-cn run --profile shortlived #LetsEncrypt
#LetsEncrypt #news: “Short-lived and IP address certificates are now generally available from Let’s Encrypt. These certificates are valid for 160 hours, just over six days.” But unstable: “IP address certificates must be short-lived certificates.” #TLS #security
on 02026-01-16more about #CloudFlare #TLS fingerprinting blocking #scraping and recommending #curl-impersonate and yifeikong’s #curl_cffi library which uses it
on 02024-09-11more discussion on #CloudFlare #TLS fingerprinting blocking #scraping and the creation of #scrapeninja
on 02024-09-11#CloudFlare on #TLS fingerprinting to block not scraping but MITM attacks
on 02024-09-11#scraping problems with #CloudFlare #TLS fingerprinting, using #Puppeteer to evade it, then writing curlninja or "scrapeninja" using #BoringSSL as a lighter-weight alternative
#CloudFlare using #TLS fingerprinting (implementation profiling) to block #scraping, fixable in #Python with the "tls-client" package from the Cheese Shop
on 02024-09-11an outage of #Lets-Encrypt last week caused by #certificate-transparency; for half an hour they were issuing bad certs, 645 in total, which they had to revoke later, but 261 are still in use! #security #TLS
on 02023-06-24