frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

GRC Tool Vanta Forces Insecure CAA Configuration

https://help.vanta.com/en/articles/11345446-creating-your-custom-domain-trust-center
2•Titan2189•11h ago

Comments

Titan2189•11h ago
To configure the Vanta Trust Center (a publicly available page listing a client's Certifications and Controls, usually hosted at trust.client.tld), Vanta requires customers to compromise on their DNS CAA configuration.

As their screenshots show, they ask you setup a CNAME from e.g. trust.customer.com to their abc123.cname.vantatrust.com.

However, if you are using CAA [1] on your root domain (to limit which Certificate Authorities are allowed to issue certificates for your domain), they _require_ you to add 4 (FOUR) new CAA records to your root domain. (shown at the bottom of the linked page)

The correct solution would be to simply publish CAA records at the destination that the CNAME is pointing to (abc123.cname.vantatrust.com)

I've brought this up with their support multiple times; but they're refusing to even acknowledge that this is a problem. They're claiming I am the first customer to ever bring this up; and that I should just add the records on my root domain - completely missing that fact that thereby I'm basically undermining what CAA is for.

I would understand it, if this was some random tool, but this specifically is a GRC Tool.

If you are another Vanta customer or have any other idea what I can do to approach this, please let me know. I want to use their tool. It's a good system and helping us out - I'm just refusing to actively downgrade our Security - for our SECURITY TOOL!

1) https://en.wikipedia.org/wiki/DNS_Certification_Authority_Au...

OpenAI Restructures to Become a More Traditional For-Profit Company

https://www.nytimes.com/2025/10/28/technology/openai-restructure-for-profit-company.html
1•occamschainsaw•7m ago•0 comments

Infrastructure behind Dust deep-dive agent

https://blog.dust.tt/building-deep-dive-infrastructure-for-ai-agents-that-actually-go-deep/
1•spolu•8m ago•0 comments

Kilo for Cursor Refugees Program

https://blog.kilocode.ai/p/kilo-for-cursor-refugees
1•janpio•10m ago•0 comments

Open-sourced game logic, art and Spine animations – SuperWEIRD Game Kit

https://ludenio.itch.io/superweird-game-kit
3•gamescodedogs•11m ago•2 comments

Republican plan would make deanonymization of US census data trivial

https://www.wired.com/story/republicans-differential-privacy-census-overhaul/
2•throw0101a•14m ago•1 comments

Show HN: AINativeKit-UI – Turn MCP JSON into ChatGPT App UIs

https://github.com/AINativeKit/ainativekit-ui
1•jakelin•16m ago•0 comments

Elon's antics may have cost Tesla more than a million vehicle sales

https://www.ft.com/content/2d304a41-d070-4646-8d26-8bfdc451f90b
3•toomanyrichies•18m ago•1 comments

Show HN: AI-powered element monitoring for websites

https://sitestable.co/
1•sitestable•19m ago•0 comments

Cognition Releases SWE-1.5: Near-SOTA Coding Performance at 950 tok/s

https://cognition.ai/blog/swe-1-5
5•yashvg•20m ago•1 comments

AOL to Be Acquired by Italy's Bending Spoons

https://variety.com/2025/digital/news/aol-acquired-bending-spoons-apollo-1236564783/
2•rmason•26m ago•2 comments

How to Kill 2 Monopolies with 1 Tool (X-ray lithography)

https://newsletter.semianalysis.com/p/how-to-kill-2-monopolies-with-1-tool
1•allenrb•26m ago•0 comments

Llamafile Returns

https://blog.mozilla.ai/llamafile-returns/
8•aittalam•29m ago•0 comments

Why does every second command fail with Foreign Char sets in there now?

https://forum.cursor.com/t/why-does-every-second-command-fail-with-foreign-char-sets-in-there-now...
1•pppoe•30m ago•1 comments

Phillips Machine – Monetary National Income Analogue Computer

https://en.wikipedia.org/wiki/Phillips_Machine
1•mosura•32m ago•1 comments

Faker: Generate Realistic Test Data in Python with One Line of Code – CodeCut

https://codecut.ai/faker-python-generate-test-data/
1•rbanffy•34m ago•0 comments

Ballroom Project Claims 123-Year-Old East Wing

https://www.nytimes.com/2025/10/23/us/politics/east-wing-obituary.html
1•rbanffy•35m ago•0 comments

Tell HN: I (accidentally) started "hosting" a government website

2•micro-jumbo•36m ago•1 comments

Jonas Hietala: Packing Neovim with Fennel

https://www.jonashietala.se/blog/2025/10/29/packing_neovim_with_fennel/
1•samtrack2019•36m ago•0 comments

UCLA math department TA, grader cuts spark concern over student learning

https://dailybruin.com/2025/10/28/ucla-math-department-ta-grader-cuts-spark-concern-over-student-...
1•amichail•36m ago•0 comments

Joke's on you, fleshbag! Channel 4's first AI presenter is dizzyingly grim

https://www.theguardian.com/tv-and-radio/2025/oct/21/channel-4-first-ai-presenter-dispatches
2•ChrisArchitect•41m ago•1 comments

New Infrastructure-as-Code Tool "Formae" Takes Aim at Terraform

https://www.infoq.com/news/2025/10/iac-formae/
1•rmason•43m ago•0 comments

We're Hiring Across the Globe

https://www.watercode.in/job-openings/
1•watercode•47m ago•0 comments

Meta's OpenZL: A Universal Compression Framework for Structured Data

https://www.infoq.com/news/2025/10/openzl-structured-compression/
1•maxloh•47m ago•0 comments

x86 is an octal machine (1995)

https://gist.github.com/seanjensengrey/f971c20d05d4d0efc0781f2f3c0353da
1•davikr•47m ago•0 comments

In Ancient Spain, a Nail Through the Skull Could Mean Enmity, or Honor

https://www.nytimes.com/2025/10/27/science/archaeology-spain-skulls.html
3•ilamont•51m ago•0 comments

Why We're Beating Modsecurity

https://github.com/1rhino2/RhinoWAF
2•1rhino2•51m ago•1 comments

Credit traders are buying protection against Oracle Corp. defaulting on its debt

https://www.bloomberg.com/news/articles/2025-10-29/oracle-default-swaps-jump-on-concerns-over-ai-...
9•zerosizedweasle•53m ago•3 comments

Do animals fall for optical illusions? It's complicated

https://arstechnica.com/science/2025/10/do-animals-fall-for-optical-illusions-its-complicated/
2•PaulHoule•53m ago•0 comments

Our first narrative collection: the Andrew Nelson papers

https://gamehistory.org/andrew-nelson-papers/
1•bpierre•55m ago•0 comments

Making Messaging Layer Security (MLS) More Decentralized

https://blog.phnx.im/making-mls-more-decentralized/
1•raphaelrobert•55m ago•0 comments