Live data from Hacker News

Tell HN: Sci-Hub's TLS certificate has started failing

news.ycombinator.com

31–40 of 154 posts

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#32
post #31

http://sci-hub.tw working here (Safari, MacOS) Sunday 8am in CA.

Similarly, the certificate I'm seeing on sci-hub.hk is set to expire in 2019, issued by COMODO. Connecting from St. Petersburg Russia.

It's not the expiration date; they used OCSP[1] to revoke it earlier. Your browser is probably just not looking up the certificate status on the OCSP server.

[1] https://en.wikipedia.org/wiki/Online_Certificate_Status_Prot...

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#34
post #5

Earlier quoted context omitted.

Being wiped from the internet by a disagreeable CA authority. If that is what "this" is.

That is not what "this" is.

The grandparent comment is right. I am not going to mess with default browser settings, and almost nobody is.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#35
post #23

Earlier quoted context omitted.

Chrome's already moving in this direction. Bypassing a HSTS error means you have to type "thisisunsafe", and they change the keyword sometimes (it used to be "badidea").

Firefox makes working around HSTS even harder. But to be fair, HSTS is the domain owner explicitly declaring "do require a valid certificate here!".

To disable HSTS permanently just do this: https://security.stackexchange.com/a/102315

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#36
post #30
post #27

Earlier quoted context omitted.

I doubt they just went out and did it randomly. I'd guess it was done via court order. The ACS got a court order against them that also ordered that 'internet search engines, web hosting sites, internet service providers (ISPs), domain name registrars and domain name registries cease facilitating “any or all domain names and websites through which Defendant Sci-Hub engages in unlawful access to, use, reproduction, an…

>they're super anti-piracy, and have a contract with all the CAs that requires them to unilaterally revoke any cert at Microsoft's discretion source?

https://social.technet.microsoft.com/wiki/contents/articles/...

> If Microsoft, it its sole discretion, identifies a DV Server Authentication certificate is being used to promote malware or unwanted software, Microsoft will contact the responsible CA and request that it revoke the certificate. The CA must either revoke the certificate within a commercially-reasonable timeframe, or it must request an exception from Microsoft within two (2) business days of receiving Microsoft’s request. Microsoft may either grant or deny the exception at its sole discretion. In the event that Microsoft does not grant the exception, the CA must revoke the certificate within a commercially-reasonable timeframe not to exceed two (2) business days.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#37
post #18

Earlier quoted context omitted.

On Chrome I can see that but I doubt Firefox would make that move. Plus, they won't remove the functionality to manually trust a cert (Business Users would complain).

> On Chrome I can see that but I doubt Firefox would make that move. Firefox has implemented the same rules around .dev tld's as google. I use vivaldi when accessing internal company .dev domains because firefox won't let me tell it to accept the self-signed certificate.

IIRC that's because Mozilla sources their HSTS Preload List from Chromium

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#38
post #31

http://sci-hub.tw working here (Safari, MacOS) Sunday 8am in CA.

Similarly, the certificate I'm seeing on sci-hub.hk is set to expire in 2019, issued by COMODO. Connecting from St. Petersburg Russia.

http://sci-hub.hk works, but https://sci-hub.hk gives me a revoked certificate error which I can't seem to work around in Firefox 55. Connecting from Belgium.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#39
post #28

Earlier quoted context omitted.

> On Chrome I can see that but I doubt Firefox would make that move. Firefox has implemented the same rules around .dev tld's as google. I use vivaldi when accessing internal company .dev domains because firefox won't let me tell it to accept the self-signed certificate.

An option could be to use certificates signed by a self-signed CA added to your trust store.

That's exactly how it's set up. Doesn't help, I'm apparently not allowed to tell my browser what to do in this instance.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#40
post #2

This is exactly what I said would happen when Google started making all of us use HTTPS.

You're not the only one. I hypothesised about this before in previous SciHub discussions, and SciHub isn't the only site that is/will be affected. Security is the ostensible benefit, and it's the one they advertise the most; easier censorship and centralised access control is the other---something which a lot of the pro-(traditional)-HTTPS advocates don't advertise. Make HTTPS mandatory (so no more HTTP), make it near impossible to bypass in browsers, and you have created a very effective censorship system controlled by the CAs and whatever interests they serve.

Slowly ostracising and forcing "compliance" of those who don't toe the line is easier than before. They want you to be obedient sheep, living in an illusion of security and safety while continuing to mindlessly consume under their control.

I will resist the urge to post that memorable Franklin quote.

Post reply on HN