Live data from Hacker News

“Users will only be able to view patents via HTTP. HTTPS will no longer work”

uspto.gov

1–10 of 172 posts

Re: “Users will only be able to view patents via HTTP. HTTPS will no longer work”

#4
Why on Earth could they possibly feel it necessary to do this? The United States Patent Office doesn't have a complex system of sub-domains or even an EV license, if money were the object then they could just go with Let's Encrypt (not to mention the current license continues until 2018 anyway).

The amount of computing power it takes to encrypt with SSL is minimal, especially if you use some of the newer systems like ECDSA and should not be of concern to a company like the Patent Office.

Re: “Users will only be able to view patents via HTTP. HTTPS will no longer work”

#5
They have a valid cert in use that only expires in 2019, and it's SHA256. But when you visit over HTTPS, this happens:

  HTTP/1.0 302 Found
  Location: http://portal.uspto.gov/pair/PublicPair
  Server: BigIP
Why would they want to do this? Seems incredibly dumb to me, huge step backwards.

Re: “Users will only be able to view patents via HTTP. HTTPS will no longer work”

#6

> beginning at 12:01 a.m., Friday, April 21 and ending at 2 a.m., Friday, April 21 ET.

> Immediately after the maintenance, users will only be able to access Public PAIR through URLs beginning with HTTP, such as http://portal.uspto.gov/pair/PublicPair. Past URLs using HTTPS to access Public Pair, such as https://portal.uspto.gov/pair/PublicPair, will no longer work.

So it seems that the maintenance will turn of HTTPS, not that it's unavailable during the maintenance.

Re: “Users will only be able to view patents via HTTP. HTTPS will no longer work”

#7

> beginning at 12:01 a.m., Friday, April 21 and ending at 2 a.m., Friday, April 21 ET.

> During the maintenance period, Public PAIR will be unavailable.

> Immediately after the maintenance, users will only be able to access Public PAIR through URLs beginning with HTTP,

Re: “Users will only be able to view patents via HTTP. HTTPS will no longer work”

#8

> beginning at 12:01 a.m., Friday, April 21 and ending at 2 a.m., Friday, April 21 ET.

I don't think you read the whole thing.

> Immediately after the maintenance, users will only be able to access Public PAIR through URLs beginning with HTTP, such as http://portal.uspto.gov/pair/PublicPair. Past URLs using HTTPS to access Public Pair, such as https://portal.uspto.gov/pair/PublicPair, will no longer work.

Re: “Users will only be able to view patents via HTTP. HTTPS will no longer work”

#9

> beginning at 12:01 a.m., Friday, April 21 and ending at 2 a.m., Friday, April 21 ET.

I think that's the maintenance period, after which https won't be available.

Immediately after the maintenance, users will only be able to access Public PAIR through URLs beginning with HTTP, such as http://portal.uspto.gov/pair/PublicPair. Past URLs using HTTPS to access Public Pair, such as https://portal.uspto.gov/pair/PublicPair, will no longer work.

Re: “Users will only be able to view patents via HTTP. HTTPS will no longer work”

#10
post #5

They have a valid cert in use that only expires in 2019, and it's SHA256. But when you visit over HTTPS, this happens: HTTP/1.0 302 Found Location: http://portal.uspto.gov/pair/PublicPair Server: BigIP Why would they want to do this? Seems incredibly dumb to me, huge step backwards.

Does TLS termination cost extra for BigIP? Maybe their license expired or something?
Post reply on HN