Hacker Newsnew | past | comments | ask | show | jobs | submit | joshfng's commentslogin

How so?


Unfortunately, I cannot disclose any further details until GitLab give me permission to do so. All that I can say is that GitLab has certain features for custom domains that GitHub does not have. I plan on publishing a technical write-up once everything has been resolved.


Is this related to the issues recently discovered with the TLS-01-SNI validation method for TLS certs?

Looking over how GitLab handles setting up custom domains[1], it's pretty clear they were affected by that. I thought it was pretty much decided that's more a problem with the Baseline Requirements than with individual service providers like GitLab though. Mozilla even went so far as to forbid CAs from using two of the Baseline Requirement validation methods as a result of that vulnerability[2]. Assuming the CAs comply this shouldn't be an issue anymore, right?

Or were you referring to something else?

[1]: https://docs.gitlab.com//ce/user/project/pages/introduction....

[2]: https://groups.google.com/d/msg/mozilla.dev.security.policy/...


My finding was heavily inspired by Frans' report, but it is not actually related.


IMO, this is user error. GitLab adding validation on their side at app level is a nice to have feature for sure. Ultimately though, keep your DNS records up to date! If you stop using a service, stop pointing your records to it, simple. If you point any record to a service that matches based on CNAME, A or some other arbitrary value expect squatting/"hijacking" to occur if you delete your reservation of that name.


I am the security researcher that reported this issue to GitLab. There is more to the issue than is described in GitLab's security advisory and it was definitely a design flaw on GitLab's part. Hopefully, more details will be published soon.


Absolutely. If you're building a POC or MVP it's a quick and easy way to get something off the ground. The framework will take you pretty far before you have scaling issues (long enough to know if what you're making is worth it). The community is very knowledgeable and friendly, and gems for almost everything already exist.

If I needed to spin up a new project and get to work right away on something I'd go with rails no question. I've yet to find another language/framework combo that works as well as a Ruby & Rails stack (Laravel and Django are good alternatives too, I'm just more experienced with Ruby). Don't think too far ahead. Premature optimization or thinking about future scaling issues if starting a new project is time that could be spent better. Rails isn't going anywhere anytime soon.


GitLab acquired GitHost from me a couple years ago [1]. They were able to do more with it than I ever could of. It's a very niche product that probably wasn't worth the engineering effort to keep it feature complete, especially at GitLab's pace of adding new features. GitHost was created before CI/CD was integrated into GitLab core. It was a much simpler product to automate deployments for back then.

[1] https://about.gitlab.com/2015/04/26/gitlab-acquires-githost/


Thanks! I'll work on adding that :)


Pale Blue Dot is based on Hyperlax (hyperlax.tv). Huge thanks to Taylor Crane (https://twitter.com/taykcrane) for letting me modify it for this purpose!


Any feedback would be great. Particularly interested in hearing what others think of the pricing model.


If you're looking for hosted GitLab that is private to you or your team/company check out https://githost.io


Josh is an awesome guy and he does a great job managing GitLab servers for people.


Yeah it's been highly requested. We just added ssl for custom domains on CI master instances too!


Https support will be added to CI instances within the next few days.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: