It’s a sign of trouble, but I’m not sure it’s really “further” trouble, all it takes is for them to get a cert from Let’s Encrypt and call it a day. I’m surprised they weren’t using LE to begin with actually - since LE is available, why would you ever pay for another CA (excluding EV certificates)?
Tell HN: Sci-Hub's TLS certificate has started failing
41–50 of 154 posts
Re: Tell HN: Sci-Hub's TLS certificate has started failing
#42It’s a sign of trouble, but I’m not sure it’s really “further” trouble, all it takes is for them to get a cert from Let’s Encrypt and call it a day. I’m surprised they weren’t using LE to begin with actually - since LE is available, why would you ever pay for another CA (excluding EV certificates)?
For instance, I recently consolidated my personal projects and site onto one server. I needed a single certificate that'd cover two domains. Digicert combined two of my orders into one certificate with two wildcard SANs. You wouldn't be able to do that with LE.
Edit: I was under the impression you couldn't do multiple wildcard SANs in LE but according to some forum posts it's fully possible as long as validation passes.
Re: Tell HN: Sci-Hub's TLS certificate has started failing
#43You can temporarily work around this by disabling 'Query OCSP responder servers to confirm the current validity of certificates' under Privacy & Security in Firefox.
Re: Tell HN: Sci-Hub's TLS certificate has started failing
#44Earlier quoted context omitted.
An option could be to use certificates signed by a self-signed CA added to your trust store.
That's exactly how it's set up. Doesn't help, I'm apparently not allowed to tell my browser what to do in this instance.
Re: Tell HN: Sci-Hub's TLS certificate has started failing
#45Re: Tell HN: Sci-Hub's TLS certificate has started failing
#46Earlier quoted context omitted.
>they're super anti-piracy, and have a contract with all the CAs that requires them to unilaterally revoke any cert at Microsoft's discretion source?
https://social.technet.microsoft.com/wiki/contents/articles/... > If Microsoft, it its sole discretion, identifies a DV Server Authentication certificate is being used to promote malware or unwanted software, Microsoft will contact the responsible CA and request that it revoke the certificate. The CA must either revoke the certificate within a commercially-reasonable timeframe, or it must request an exception from Mi…
Hell no, and neither does microsoft.
Re: Tell HN: Sci-Hub's TLS certificate has started failing
#47It’s a sign of trouble, but I’m not sure it’s really “further” trouble, all it takes is for them to get a cert from Let’s Encrypt and call it a day. I’m surprised they weren’t using LE to begin with actually - since LE is available, why would you ever pay for another CA (excluding EV certificates)?
There are plenty of reasons to pay for a certificate. Wildcard certificates only came out last month on LE, and people might still be weary to switch their primary site over so quickly. Additionally, there's still a few cases I can think of where a custom certificate might be needed. For instance, I recently consolidated my personal projects and site onto one server. I needed a single certificate that'd cover two dom…
Re: Tell HN: Sci-Hub's TLS certificate has started failing
#48It’s a sign of trouble, but I’m not sure it’s really “further” trouble, all it takes is for them to get a cert from Let’s Encrypt and call it a day. I’m surprised they weren’t using LE to begin with actually - since LE is available, why would you ever pay for another CA (excluding EV certificates)?
At any point in history, have CAs revoked certs solely to censor a target website?
Maybe the answer is yes. I don't know. But this is a rude wake-up call for me and everyone else who tried to force the world into this shape.
We've all been shouting "You have to use TLS! It's fundamental security 101. If you're not using https, your site is probably broken. And there's no reason not to do it, since it's so easy."
Surprise: Now nobdoy trusts http, and those that control https can revoke their trust based on arbitrary human morals rather than solid technical reasons.
I was a pentester for years and not once did anybody mention this threat anywhere. It's blindingly obvious in hindsight, but it was too easy not to think about it.
Let's Encrypt is in the exact same position. Why do we trust them? Think about it -- they're under US jurisdiction and subject to US laws. The government could compel them to revoke certs.
We're lucky that it's just a minor annoyance. Picture a world where no major browser renders http at all, and the only way to get a site online is to have a trusted cert.
This is not far from reality: If the Magic Leap turns out not to be vaporware, they're going to be launching a DRM-powered internet that can't be adblocked. And that means we'll all be subject to government whims far more than we'd like to admit.
Re: Tell HN: Sci-Hub's TLS certificate has started failing
#49Earlier quoted context omitted.
https://social.technet.microsoft.com/wiki/contents/articles/... > If Microsoft, it its sole discretion, identifies a DV Server Authentication certificate is being used to promote malware or unwanted software, Microsoft will contact the responsible CA and request that it revoke the certificate. The CA must either revoke the certificate within a commercially-reasonable timeframe, or it must request an exception from Mi…
This is absolutely insane, and Microsoft really has no position to make these demands. Does McDonalds have the right to get your drivers licensed revoked? (Even if you say... use the drive thru to steal mcnuggets?) Hell no, and neither does microsoft.