Live data from Hacker News

Windows Certificate Manager does not display the complete trust list

hexatomium.github.io

81–90 of 103 posts

Re: Windows Certificate Manager does not display the complete trust list

#81
post #78

Earlier quoted context omitted.

Everyone talks about how great the alternatives for office are. Buy they are good. Not great. Even office word online is better than Google docs.

Comparing Google Docs to MS Office oh god. I mean i always found Google Docs and Word Online aweful, mostly I need Docs Offline. There aren't many times where I need them only or need Collaboration and even for that there would be lots of Toolings. Libre Office should be compared and if you are a Office 2003 User you wouldn't have a hard time to go to LibreOfice. Also on Mac LibreOffice is really really lightweight c…

I'm nearly the opposite.. I uninstalled my office 360 version from work when I left the job (validation failed anyway) and only used it for outlook for work anyhow... that said, I needed to update my resume. For that I have Libre Office... that's about all I use it for.

For me, google docs works well enough... I use the sheets more than the docs actually, as I keep track of my current bills with it. All of that said, there are a lot of tiny features in MS Office that LO doesn't have.... I don't need them, that doesn't mean that nobody does. I know plenty of people that can't give up their use of excel or word in favor of LO.

I also would love to see a fully free/open solution that works as well as Exchange+Outlook ... I've seen lots of alternatives and options, none are nearly as clean or well integrated. And for that matter, most are a bitch to setup/maintain on the server-side of things, or simply aren't actually free, there's usually a critical "plugin" that's only available with a support contract.

Re: Windows Certificate Manager does not display the complete trust list

#82
post #3

Earlier quoted context omitted.

1) Because MSFT provides great corporate support for desktops. Keyword: great. Not good. Great. 2) Because people are used to it. 3) Because Office products are the de facto standard, and they run best on windows. I could go on, but you get the point.

x) Anything related with drivers, especially video and audio With the exception of printers. Omg printers are such a PITA on windows I often just send a pdf to me and print it with the phone.

The past several printers I've had... I just had to open the add printer dialog (which is more of a pain than it should be) and it would just detect the printer.. this is from win7 through 10.

Now getting a new printer (new hardware) installed in Linux isn't usually so easy.. unless you're using a fairly mainstream HP Laser printer, which is actually what I recommend because it's so straight forward. Outside of that it's almost always a pain. My current printer is rigged up and connected to print from my phone from anywhere, I have it setup for remote printing via Chrome... which is kind of nice, ordering something, or paying a bill on a break at work and being able to print at home.

Unless you're using a really off brand, I haven't had trouble installing on windows via the add printer... it may take a while to download a full device list for printers, which aren't pre-installed, but that's time not difficulty.

Re: Windows Certificate Manager does not display the complete trust list

#83
post #37

Earlier quoted context omitted.

The problem with your argument is that this is an administrative GUI that isn't even normally presented to end users unless you search for it or know how MMC snap-ins work. It is a power-user interface by all measure. And while Microsoft does simplify UIs for end users, they don't typically do the same for administrative content (just look at anything in the Admin Tools, or MMC snap-ins, no sugar coating there). Your…

Please don't call commenters "apologists" on HN.

While I agree that UnoriginalGuy's post could have been phrased in a more neutral manner, the post he was replying to referred to the article as "linkbait" based on a "Windows bashing meme." Is that a neutral phrasing? Given that the article was revealing new information to most of the people here, I strongly disagree that the article is "linkbait."

I think you are personalizing the debate in exactly the way you are supposedly trying to avoid. Let's debate the facts, not hurt feelings. Nobody has been rude here (at least in the few posts I read). There is nothing wrong with calling someone an apologist, as long as it is done in a respectful way and not just to get a rise out of someone. We don't need to shrink the space for debate here any more than it already has been.

Re: Windows Certificate Manager does not display the complete trust list

#84
post #37

Earlier quoted context omitted.

Please don't call commenters "apologists" on HN.

While I agree that UnoriginalGuy's post could have been phrased in a more neutral manner, the post he was replying to referred to the article as "linkbait" based on a "Windows bashing meme." Is that a neutral phrasing? Given that the article was revealing new information to most of the people here, I strongly disagree that the article is "linkbait." I think you are personalizing the debate in exactly the way you are…

Totally fair point. I'm not invested in the debate so much as the word "apologist" sets me off.

Re: Windows Certificate Manager does not display the complete trust list

#85

Earlier quoted context omitted.

x) Anything related with drivers, especially video and audio With the exception of printers. Omg printers are such a PITA on windows I often just send a pdf to me and print it with the phone.

The past several printers I've had... I just had to open the add printer dialog (which is more of a pain than it should be) and it would just detect the printer.. this is from win7 through 10. Now getting a new printer (new hardware) installed in Linux isn't usually so easy.. unless you're using a fairly mainstream HP Laser printer, which is actually what I recommend because it's so straight forward. Outside of that…

I've an epson wifi printer and every time it gets a different ip windows can't find it anymore.

I used to have it on a dns reserved ip but damned new telco router doesn't have that option since I upgrades to fiber.

Every time the epson setup wants to restart the whole computer to start the detection and it is so annoying, I just let any other airprint device do the thing.

Re: Windows Certificate Manager does not display the complete trust list

#86
post #37

Earlier quoted context omitted.

Please don't call commenters "apologists" on HN.

While I agree that UnoriginalGuy's post could have been phrased in a more neutral manner, the post he was replying to referred to the article as "linkbait" based on a "Windows bashing meme." Is that a neutral phrasing? Given that the article was revealing new information to most of the people here, I strongly disagree that the article is "linkbait." I think you are personalizing the debate in exactly the way you are…

The "linkbait" comment reflects one of my triggers and the way in which writing on mobile may correlate with lower quality output on my part. As original posted the line had both "linkbait" and "amateur hour". If I'd been sitting at a keyboard rather than touch screen, I might have have written something more constructive. The rhythm is better, editing is easier, and input is not so painful that I am looking for an ending after a couple of paragraphs.

Objectively speaking, there is pretty strong evidence to support a belief that a "Windows bashing meme" exists to the extent that any meme can exist. Apple spent most of a decade and several billion dollars on buying over the air advertising for it's "I'm a PC campaign"; it's so socially acceptable to bash Windows that PG hisself engaged in it for many years; and a lynchpin of Silicon Valley mythology is NetScape got hosed even though it unicorn exited at about $10 Billion, Marc Andreesen's minority stake was enough to make him a VC and Jim Clark bought a gridiron football field length yacht.

It's not that I'm opposed to over-enthusiastic headlines, well written headlines should capture the reader's attention to the point that they click. What makes it "linkbait" to me is that it panders toward confirmation bias rather than encouraging curiosity: it's us-versus-them tech gossip of the sort that tends not to make people smarter. I often wonder about unicorns not seen because of YC's historical attitude toward Windows [e.g. the days when a tock processor announcement for the mid-year Macbook dominated the HN frontpage for a day or two].

As to the other topic, one form low quality HN comments [1] take is what I call "the internet pick apart". Break a post down into many sound-bites. Cast each into an unfavorable context. Then arbitrarily argue against each sound bite. The goal is to broaden the flame war across many fronts without creating a concentrated target for coherent rebuttal. The pattern is to apply it recursively to each of successive defence by the victim. The sport is to keep the target spinning [there are extra points for reintroducing sound-bites from higher in the thread].

That said, a comment that literally begins with the string "The problem with you" probably isn't intended to produce constructive dialog. Pig lipsticking it with "r argument" doesn't change the purpose. Credit where credit is due, at least the comment works its way up to the pick apart rather than down to the problem with me.

Anyway, whenever I find myself writing or saying "you" in a conversation I try to stop and try to rephrase. It's loaded. When I read comments that use "you" it's usually the rest of the internet seeping into HN. The exception is things like "You can safely assume that I didn't write this on mobile."

[1]: On the other hand, the internet pick apart and other forms of flaming and trolling and pointless arguing constitute some of the highest quality writing on the internet in general. Trolling and flaming are successful because they are writing for an audience and for entertainment and for the shear joy of writing...or at least it was for me.

Re: Windows Certificate Manager does not display the complete trust list

#87

Earlier quoted context omitted.

The bigger takeaway from this is with a system like this (fully managed by Windows Updates).. how can you remove certificates you don't trust? Latest documentation for this seems to be for IE 5. I sure as hell like to run dkpkg-reconfigure ca-certificates every once in a while after some roots get compromised and don't trust Microsoft to be on the ball.

It can be added to the disallowed certificate store, which takes precedence over any trusted stores. For example, using the root discussed in the article: 1. Download the root cert from http://ctldl.windowsupdate.com/msdownload/update/v3/static/t... (or save it from the browser's certificate viewer) 2. Open certmgr and import it into 'Untrusted Certificates'. (This just adds it for the current user's store. Could als…

so does this mean in a year I can make use of my free upgrade and then install a nice prepackaged something that will kill it's capacity to spy on me?

Re: Windows Certificate Manager does not display the complete trust list

#88

Is this really true? When I navigate to https://certplusrootcag1-test.opentrust.com/ I see the root certificate is "Certplus Root CA G1", not "OpenTrust Root CA G1"...

It is "CertplusRoot CA G1" in my system too. This CA was added recently (http://www.infoworld.com/article/2941594/security/microsoft-...).

Re: Windows Certificate Manager does not display the complete trust list

#89

Earlier quoted context omitted.

x) Anything related with drivers, especially video and audio With the exception of printers. Omg printers are such a PITA on windows I often just send a pdf to me and print it with the phone.

The past several printers I've had... I just had to open the add printer dialog (which is more of a pain than it should be) and it would just detect the printer.. this is from win7 through 10. Now getting a new printer (new hardware) installed in Linux isn't usually so easy.. unless you're using a fairly mainstream HP Laser printer, which is actually what I recommend because it's so straight forward. Outside of that…

With linux I usually just plug it in then hit print in the application. Then it prints... I've never run into a consumer model that needed installing in any way. I may just have been lucky.

Re: Windows Certificate Manager does not display the complete trust list

#90
What seems to be happening with Windows is that Microsoft is making the machine more a slave of their services with each new release. It's as if they're trying to catch up with Chromebooks, which are totally slaved to Google. Especially since Windows 10 is free with ads. Treating the local certificate store as a cache to the main certificate store at Microsoft HQ is consistent with this.

How difficult it is to hijack the link between the local and remote certificate stores? That's a potential attack surface. It's not hard-coded; it's a registry key (Software\Microsoft\SystemCertificates\AuthRoot\AutoUpdate). The default URL is "ctldl.windowsupdate.com".

So what protects that domain from being hijacked via DNS poisoning? It ought to have a valid SSL cert, right? Well, no. Go to "https://ctldl.windowsupdate.com/":

    ctldl.windowsupdate.com uses an invalid security certificate.

    The certificate is only valid for the following names:
    a248.e.akamai.net, *.akamaihd.net, *.akamaihd-staging.net,
    *.akamaized.net, *.akamaized-staging.net  
    (Error code: ssl_error_bad_cert_domain)
Uh oh. Am I missing something, or are root certs downloaded over an unsecured channel?
Post reply on HN