• 0 Posts
  • 130 Comments
Joined 1 year ago
cake
Cake day: July 14th, 2023

help-circle




  • What exactly are you trusting a cert provider with and what are the security implications?

    End users trust the cert provider. The cert provider has a process that they use to determine if they can trust you.

    What attack vectors do you open yourself up to when trusting a certificate authority with your websites’ certificates?

    You’re not really trusting them with your certificates. You don’t give them your private key or anything like that, and the certs are visible to anyone navigating to your website.

    Your new vulnerabilities are basically limited to what you do for them - any changes you make to your domain’s DNS config, or anything you host, etc. - and depend on that introducing a vulnerability of its own. You also open a new phishing attack vector, where someone might contact you, posing as the certificate authority, and ask you to make a change that would introduce a vulnerability.

    In what way could it benefit security and/or privacy to utilize a paid service?

    For most use cases, as far as I know, it doesn’t.

    LetsEncrypt doesn’t offer EV or OV certificates, which you may need for your use case. However, these are mostly relevant at the enterprise level. Maybe you have a storefront and want an EV cert?

    LetsEncrypt also only offers community support, and if you set something up wrong you could be less secure.

    Other CAs may offer services that enhance privacy and security, as well, like scanning your site to confirm your config is sound… but the core offering isn’t really going to be different (aside from LE having intentionally short renewal periods), and theoretically you could get those same services from a different vendor.




  • They have no recourse

    They can do all of the following:

    1. Report the seller to the platform for selling stolen goods.
    2. Return the stolen goods to the rightful owner, if they’re able to get their information, or if not, to Valve or even just the police department.
    3. File a suit in small claims court against the seller for damages (the amount they paid + any other expenses they’ve incurred, like the cost to mail it to the rightful owner, including legal fees) or, if the platform won’t provide the seller’s information, against the platform itself.

  • Each credit reporting agency offers this option, at no charge …

    It is highly recommended to lock your credit. Frankly, it should be locked by default. In September of 2017, Equifax announced a data breach that exposed the personal information of 147 million people.

    Note that, before this incident, it wasn’t consistently free. I remember it being free to lock, but costing $20 or so to unlock. A law passed in 2018 required credit bureaus to offer freezes and unfreezes (and to fulfill them within certain time frames) for free.

    Also note that you might need to look for a “freeze” instead of a lock. Experian charges $25/month for their “CreditLock” service, for example, but they offer a free security freeze.










  • Traction control and other related features is a bigger deal than AWD in my opinion. In the past five years I’ve had AWD engage maybe twice.

    Also, you can replace two tires at once as opposed to all four, depending on the specific vehicle and how much the difference will be between the tires you’re keeping and getting rid of. You only need to replace all four if the difference is enough to cause issues.

    There are a ton of crossover SUVs with FWD, though. Here are a few:

    • Honda CR-V
    • Toyota RAV4
    • Lexus RX 350
    • Toyota Highlander
    • Hyundai Tucson
    • Hyundai Palisade
    • Kia Telluride
    • Nissan Kicks
    • Nissan Rogue
    • Nissan Murano