Live data from Hacker News

Tell HN: Sci-Hub's TLS certificate has started failing

news.ycombinator.com

21–30 of 154 posts

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#21

Earlier quoted context omitted.

This seems to affect all their domain variants, but it still works without encryption: http://sci-hub.tw Edit: already noted by detaro https://news.ycombinator.com/item?id=16952051

I just tried https://sci-hub.tw/ (Chrome) and got a secure connection without warnings. Since the issuer of the certificate that my browser showed for the connection is "Comodo" I guess the revocation didn't reach my browser yet? EDIT: IE and Firefox say "insecure". What really annoys me: There does not seem to be any way - none that I could find - to get IE and Firefox to connect anyway?

[deleted]

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#22
post #9

Earlier quoted context omitted.

You can always manually trust certificates via various means, it's the basis for almost any corporate network, most browsers also offer a simply dialog to bypass certificate warnings.

Browsers seem to be moving towards making it harder to bypass, which is probably a good thing for the average user. I wouldn't be surprised to see the ability to ignore https errors (or access http sites at all) locked behind a developer setting or something.

Chrome's already moving in this direction. Bypassing a HSTS error means you have to type "thisisunsafe", and they change the keyword sometimes (it used to be "badidea").

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#23

Earlier quoted context omitted.

Browsers seem to be moving towards making it harder to bypass, which is probably a good thing for the average user. I wouldn't be surprised to see the ability to ignore https errors (or access http sites at all) locked behind a developer setting or something.

Chrome's already moving in this direction. Bypassing a HSTS error means you have to type "thisisunsafe", and they change the keyword sometimes (it used to be "badidea").

Firefox makes working around HSTS even harder. But to be fair, HSTS is the domain owner explicitly declaring "do require a valid certificate here!".

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#24
It’s a sign of trouble, but I’m not sure it’s really “further” trouble, all it takes is for them to get a cert from Let’s Encrypt and call it a day. I’m surprised they weren’t using LE to begin with actually - since LE is available, why would you ever pay for another CA (excluding EV certificates)?

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#25
post #18

Earlier quoted context omitted.

Browsers seem to be moving towards making it harder to bypass, which is probably a good thing for the average user. I wouldn't be surprised to see the ability to ignore https errors (or access http sites at all) locked behind a developer setting or something.

On Chrome I can see that but I doubt Firefox would make that move. Plus, they won't remove the functionality to manually trust a cert (Business Users would complain).

> On Chrome I can see that but I doubt Firefox would make that move.

Firefox has implemented the same rules around .dev tld's as google. I use vivaldi when accessing internal company .dev domains because firefox won't let me tell it to accept the self-signed certificate.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#26
post #2

This is exactly what I said would happen when Google started making all of us use HTTPS.

Oh, look. Google as the absolute arbiter of information. Who could've ever predicted that they'd start using their position for evil?

How exactly do you see Google doing anything here, outside of a general "they encourage HTTPS" (but the site still works fine over HTTP)?

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#27

crt.sh reports it was revoked on the 26th: https://crt.sh/?id=274083328

Issuer: COMODO That figures. When will we stop giving money to those scumbags? Trying to register the Let's Encrypt trademark was enough for me to never give them a cent again.

I doubt they just went out and did it randomly. I'd guess it was done via court order. The ACS got a court order against them that also ordered that 'internet search engines, web hosting sites, internet service providers (ISPs), domain name registrars and domain name registries cease facilitating “any or all domain names and websites through which Defendant Sci-Hub engages in unlawful access to, use, reproduction, and distribution of the ACS Marks or ACS's Copyrighted Works.”' (https://www.sciencemag.org/news/2017/11/court-demands-search...)

Alternatively, Microsoft might have had something to do with it (they're super anti-piracy, and have a contract with all the CAs that requires them to unilaterally revoke any cert at Microsoft's discretion), but I think that's far less likely than the court order.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#28
post #18

Earlier quoted context omitted.

On Chrome I can see that but I doubt Firefox would make that move. Plus, they won't remove the functionality to manually trust a cert (Business Users would complain).

> On Chrome I can see that but I doubt Firefox would make that move. Firefox has implemented the same rules around .dev tld's as google. I use vivaldi when accessing internal company .dev domains because firefox won't let me tell it to accept the self-signed certificate.

An option could be to use certificates signed by a self-signed CA added to your trust store.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#30
post #27

Earlier quoted context omitted.

Issuer: COMODO That figures. When will we stop giving money to those scumbags? Trying to register the Let's Encrypt trademark was enough for me to never give them a cent again.

I doubt they just went out and did it randomly. I'd guess it was done via court order. The ACS got a court order against them that also ordered that 'internet search engines, web hosting sites, internet service providers (ISPs), domain name registrars and domain name registries cease facilitating “any or all domain names and websites through which Defendant Sci-Hub engages in unlawful access to, use, reproduction, an…

>they're super anti-piracy, and have a contract with all the CAs that requires them to unilaterally revoke any cert at Microsoft's discretion

source?

Post reply on HN