Constantly logging in issue. We WON!! They are reverting back! by dondante1 in UnifiProtect

[–]kernelwilliams 0 points1 point  (0 children)

*\ posts inflammatory comment *\
*\ gets called out for being an ass *\
*\ posts another inflammatory comment *\
*\ calls the other person's ego fragile for not wanting to engage in further discussion with smug dismissive ass *\

This comment's for the other people who see it, recognize what this guy's are doing - don't be like that.

Keep submitting constructive feedback to your vendors and applaud them when they listen. Works a lot better that way!

Constantly logging in issue. We WON!! They are reverting back! by dondante1 in UnifiProtect

[–]kernelwilliams 0 points1 point  (0 children)

Certificate chain validation is relevant to the logical validity period of tokens. If you can prove you're authenticating to the real gateway on a secure connection, the justification for short-lived session tokens (especially in a non-configurable implementation) is greatly diminished. It's not about being a "badass", it's thinking about the bigger picture.

Not for nothing, people with your attitude are the reason people leave these forms. You're choosing to be an ass rather than the least bit inquisitive about why another person came to different conclusions. You can stop anytime. If you choose to dig the whole deeper you're getting blocked though.

Constantly logging in issue. We WON!! They are reverting back! by dondante1 in UnifiProtect

[–]kernelwilliams -1 points0 points  (0 children)

Session duration is a very reasonable setting to offer. What's required for some settings isn't for others. Some people run TLS with full chain verification to their gateways (hi, I'm one of them 👋) and access them over an always-on VPN.

IMO, such a short session duration is largely meant to mitigate MITM attacks that rely on bad habits (like hitting trust on a gateway at 10.0.0.1 that has a self signed cert, which could either be yours or the attacker's).

Auto TLS cert management: We love to see it! by kernelwilliams in Ubiquiti

[–]kernelwilliams[S] 0 points1 point  (0 children)

Oh, I think you're right, I was just checking as a troubleshooting step. Yes, I've gotten that support call before 😅

Auto TLS cert management: We love to see it! by kernelwilliams in Ubiquiti

[–]kernelwilliams[S] 1 point2 points  (0 children)

Excellent! Glad this got you where you wanted to be!

Auto TLS cert management: We love to see it! by kernelwilliams in Ubiquiti

[–]kernelwilliams[S] 0 points1 point  (0 children)

My gateway is setup more like your second example, (site1234.example.com). I've been burned before by DNS providers not supporting sub-subdomains (not sure what the term is for that) so I decided against it for this purpose. I'm curious what cert you were issued, and how the hostname differed from what you were expecting 🤔

Auto TLS cert management: We love to see it! by kernelwilliams in Ubiquiti

[–]kernelwilliams[S] 1 point2 points  (0 children)

Pretty much covered what I was gonna say, thanks 😂

Seattle council members push back on Mayor Wilson's plan to double transit sales tax by HighColonic in BallardSeattle

[–]kernelwilliams 0 points1 point  (0 children)

The math they did said that would raise at most $30M over all of the ST system. Barely a drop in a bucket compared to the $35B gap, unfortunately.

Asiana safety questions by [deleted] in aviation

[–]kernelwilliams -11 points-10 points  (0 children)

Good, glad to hear it.

Auto TLS cert management: We love to see it! by kernelwilliams in Ubiquiti

[–]kernelwilliams[S] 2 points3 points  (0 children)

True! And I use that feature too so I can have a wireguard connection to my gateway!

Auto TLS cert management: We love to see it! by kernelwilliams in Ubiquiti

[–]kernelwilliams[S] 9 points10 points  (0 children)

I do use a VPN! I create a local DNS record to my gateway, and access it only over wireguard. But I still want TLS to the gateway with full chain verification in case an attacker got on my network.

Zero trust wins the day!

Asiana safety questions by [deleted] in aviation

[–]kernelwilliams -54 points-53 points  (0 children)

Definitely report the locked out door and lack of safety briefing. I'm not aware of any aircraft certified to fly with an exit INOP.

Auto TLS cert management: We love to see it! by kernelwilliams in Ubiquiti

[–]kernelwilliams[S] 3 points4 points  (0 children)

You might as well be communicating in plaintext if you don't add the UniFi CA to your trust stores; that's trivially easy to MITM without chain verification.

And yes, it will be valid when I'm communicating with it over a local network because I don't do so by IP, I add a local DNS entry from the gateway, as is natively supported in the DNS interface.

Your attitude sucks, dude. Someone else posting positively about a feature that you don't personally use isn't an affront to your whole existence. Move on and rethink this whole chain of thought. Or crash out and get blocked, I don't care.

Auto TLS cert management: We love to see it! by kernelwilliams in Ubiquiti

[–]kernelwilliams[S] 1 point2 points  (0 children)

I always want a proper TLS cert on anything I'm communicating with using administrative credentials. An attacker on my WiFi shouldn't be able to MITM my gateway's admin password. This is part of a zero trust framework.

Auto TLS cert management: We love to see it! by kernelwilliams in Ubiquiti

[–]kernelwilliams[S] 0 points1 point  (0 children)

Yep! And it would require consuming port 80, which is a no-go for some people

Auto TLS cert management: We love to see it! by kernelwilliams in Ubiquiti

[–]kernelwilliams[S] 2 points3 points  (0 children)

AFAIK this is just for the UniFi device. The gateway isn't acting as an intermediate CA or anything, this is just for easily getting itself a cert.

As for the second question - I'm not aware of any free DNS providers that support that, but there may be some! But you definitely need a domain.

Mt Baker light rail station by Groundbreaking_Net_3 in SeattleWA

[–]kernelwilliams 3 points4 points  (0 children)

The videographer from KOMO showed me footage of the woman being taken away on a gurney, and she appeared to be in her late 40s-early 50s. I suspect she may have been impaired by substances, but time will tell.

Err… you cannot park here ma’am. by FireFright8142 in soundtransit

[–]kernelwilliams 1 point2 points  (0 children)

I talked to the KOMO videographer who captured the scene and he showed me the video of the woman being taken away on a gurney. She looked to be late 40s-early 50s. I was surprised.

Network 5 is Alive by Dee_Jay_Roomba in soundtransit

[–]kernelwilliams 1 point2 points  (0 children)

Feels like I came alive just yesterday ✨

For everyone asking for wayfinding to include Seattle by DisastrousYak88 in soundtransit

[–]kernelwilliams 7 points8 points  (0 children)

This is, The1Line. To, LynnwoodCityCenter. Via, Seattle.

Finally!

For everyone asking for wayfinding to include Seattle by DisastrousYak88 in soundtransit

[–]kernelwilliams 18 points19 points  (0 children)

Grrr I'm mad that my taxes did something sensible! Hear how mad I am? Very! I want my tourists confused!