<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: mghilardi</title><link>https://news.ycombinator.com/user?id=mghilardi</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sat, 10 Oct 2026 03:19:43 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=mghilardi" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by mghilardi in "Scripts I wrote that I use all the time"]]></title><description><![CDATA[
<p>Literally with my own shell: <a href="https://github.com/cosmos72/schemesh" rel="nofollow">https://github.com/cosmos72/schemesh</a></p>
]]></description><pubDate>Thu, 23 Oct 2025 13:29:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=45681587</link><dc:creator>mghilardi</dc:creator><comments>https://news.ycombinator.com/item?id=45681587</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45681587</guid></item><item><title><![CDATA[New comment by mghilardi in "Actalis: Insufficient Serial Number Entropy"]]></title><description><![CDATA[
<p>I think Actalis found itself between a very hard rock and an even harder place.
I am italian and I have worked with some public entities similar to the ones Actalis provided certificates to.
There is a private network "SPC" of public italian organizations, with many machine-to-machine HTTPS web services that MUST by law provide updates to the central government with quite strict deadlines.<p>On such networks, certificate pinning is very common and possibly even recommended, contrary to the "Basic Requirements" and recommendations of CAs.<p>Failing to respect such deadlines causes penalties to the local governments, and in grave cases may even be a crime: "public service interruption" which would initiate a trial, with more fines and possibly jail time.<p>Thus Actalis had to choose between:<p>1. follow the CAs "Basic Requirements" that force CAs to quickly revoke certificates when a problem is discovered. Then most of the certificates would be revoked <i>before</i> the public customers managed to replace them - disrupting their operativity, risking penalties for the missed deadlines and possibly trial and jail time for "public service interruption". To avoid this, they would then need to demonstrate in a public trial that the public customers were well informed that certificates could be revoked and re-issued at any time with very short warning time, and they did everything they could to avoid the "public service interruption", both pre-emptively (when negotiating the sell of certificates and educating the customers) and re-actively (when the serial numbers vulnerability was discovered). Quite a hard path.<p>2. contact the customers, push them to quickly replace the compromised certificates, and revoke them only <i>afterwards</i>, thus avoiding service disruptions.<p>They chose 2. Unluckily italian public organizations are <i>very</i> slow, which in the end caused Actalis to miss their BR deadlines by a long shot.</p>
]]></description><pubDate>Thu, 01 Aug 2019 12:06:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=20583045</link><dc:creator>mghilardi</dc:creator><comments>https://news.ycombinator.com/item?id=20583045</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=20583045</guid></item></channel></rss>