http://sci-hub.tw working here (Safari, MacOS) Sunday 8am in CA.
Connecting from St. Petersburg Russia.
31–40 of 154 posts
http://sci-hub.tw working here (Safari, MacOS) Sunday 8am in CA.
Connecting from St. Petersburg Russia.
http://sci-hub.tw working here (Safari, MacOS) Sunday 8am in CA.
Similarly, the certificate I'm seeing on sci-hub.hk is set to expire in 2019, issued by COMODO. Connecting from St. Petersburg Russia.
[1] https://en.wikipedia.org/wiki/Online_Certificate_Status_Prot...
Earlier quoted context omitted.
Chrome's already moving in this direction. Bypassing a HSTS error means you have to type "thisisunsafe", and they change the keyword sometimes (it used to be "badidea").
Firefox makes working around HSTS even harder. But to be fair, HSTS is the domain owner explicitly declaring "do require a valid certificate here!".
Earlier quoted context omitted.
I doubt they just went out and did it randomly. I'd guess it was done via court order. The ACS got a court order against them that also ordered that 'internet search engines, web hosting sites, internet service providers (ISPs), domain name registrars and domain name registries cease facilitating “any or all domain names and websites through which Defendant Sci-Hub engages in unlawful access to, use, reproduction, an…
>they're super anti-piracy, and have a contract with all the CAs that requires them to unilaterally revoke any cert at Microsoft's discretion source?
> If Microsoft, it its sole discretion, identifies a DV Server Authentication certificate is being used to promote malware or unwanted software, Microsoft will contact the responsible CA and request that it revoke the certificate. The CA must either revoke the certificate within a commercially-reasonable timeframe, or it must request an exception from Microsoft within two (2) business days of receiving Microsoft’s request. Microsoft may either grant or deny the exception at its sole discretion. In the event that Microsoft does not grant the exception, the CA must revoke the certificate within a commercially-reasonable timeframe not to exceed two (2) business days.
Earlier quoted context omitted.
On Chrome I can see that but I doubt Firefox would make that move. Plus, they won't remove the functionality to manually trust a cert (Business Users would complain).
> On Chrome I can see that but I doubt Firefox would make that move. Firefox has implemented the same rules around .dev tld's as google. I use vivaldi when accessing internal company .dev domains because firefox won't let me tell it to accept the self-signed certificate.
http://sci-hub.tw working here (Safari, MacOS) Sunday 8am in CA.
Similarly, the certificate I'm seeing on sci-hub.hk is set to expire in 2019, issued by COMODO. Connecting from St. Petersburg Russia.
Earlier quoted context omitted.
> On Chrome I can see that but I doubt Firefox would make that move. Firefox has implemented the same rules around .dev tld's as google. I use vivaldi when accessing internal company .dev domains because firefox won't let me tell it to accept the self-signed certificate.
An option could be to use certificates signed by a self-signed CA added to your trust store.
This is exactly what I said would happen when Google started making all of us use HTTPS.
Slowly ostracising and forcing "compliance" of those who don't toe the line is easier than before. They want you to be obedient sheep, living in an illusion of security and safety while continuing to mindlessly consume under their control.
I will resist the urge to post that memorable Franklin quote.