Live data from Hacker News

Tell HN: Sci-Hub's TLS certificate has started failing

news.ycombinator.com

51–60 of 154 posts

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#51
post #24

It’s a sign of trouble, but I’m not sure it’s really “further” trouble, all it takes is for them to get a cert from Let’s Encrypt and call it a day. I’m surprised they weren’t using LE to begin with actually - since LE is available, why would you ever pay for another CA (excluding EV certificates)?

This is a much bigger deal than people are giving it credit for. At any point in history, have CAs revoked certs solely to censor a target website? Maybe the answer is yes. I don't know. But this is a rude wake-up call for me and everyone else who tried to force the world into this shape. We've all been shouting "You have to use TLS! It's fundamental security 101. If you're not using https, your site is probably brok…

All the various DNS alternatives people have pitched over the years pretty directly address the centralization issue you are getting at here. Often by casting themselves as decentralized.

Really the issue is that decentralization isn't very compatible with convenience and people generally place a lot more value on convenience than things like Sci-Hub.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#52
post #24

It’s a sign of trouble, but I’m not sure it’s really “further” trouble, all it takes is for them to get a cert from Let’s Encrypt and call it a day. I’m surprised they weren’t using LE to begin with actually - since LE is available, why would you ever pay for another CA (excluding EV certificates)?

...and then LE also revokes their certificate.

That is a really farfetched scenario which I would never imagine happening. LE are not Cloudflare, I am sure they would not ridicule their neutral mission without actual legal force.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#54
post #24

It’s a sign of trouble, but I’m not sure it’s really “further” trouble, all it takes is for them to get a cert from Let’s Encrypt and call it a day. I’m surprised they weren’t using LE to begin with actually - since LE is available, why would you ever pay for another CA (excluding EV certificates)?

This is a much bigger deal than people are giving it credit for. At any point in history, have CAs revoked certs solely to censor a target website? Maybe the answer is yes. I don't know. But this is a rude wake-up call for me and everyone else who tried to force the world into this shape. We've all been shouting "You have to use TLS! It's fundamental security 101. If you're not using https, your site is probably brok…

Self-signed certificates, trust on first use (or verify out of band) like SSH, works around most of this

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#55
This type of thing is my number one objection to Certificate Authorities.

In fact, it's my objection to computation illiteracy being acceptable in general amongst users. Devs and agencies cannot be trusted not to screw with things. If the average Joe cannot understand what is going on behind the curtains, they aren't free.

Freedom is a scary thing to many groups, and unfortunately, more and more we are seeing the pendulum swing further and further away from the Internet's original intent: to facilitate the fast and open communication of information. I want to say free and open, but unfortunately I have trouble being able to maintain that level of idealism anymore.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#56

Earlier quoted context omitted.

This is absolutely insane, and Microsoft really has no position to make these demands. Does McDonalds have the right to get your drivers licensed revoked? (Even if you say... use the drive thru to steal mcnuggets?) Hell no, and neither does microsoft.

Microsoft runs a root store. That gives them more leverage over the CAs than McDonalds has.

I'd be curious what would happen if the "too big to fail" issuers pushed back against this.

Microsoft's only option is to completely drop the root cert, right? So there's no real non-nuclear option...

In the broader sense, this is one downside of the shift towards Lets Encrypt and CAs being more interchangable: increased power of the root stores relative to them.

Sometimes that's good, sometimes it's evil.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#57
post #55

This type of thing is my number one objection to Certificate Authorities. In fact, it's my objection to computation illiteracy being acceptable in general amongst users. Devs and agencies cannot be trusted not to screw with things. If the average Joe cannot understand what is going on behind the curtains, they aren't free. Freedom is a scary thing to many groups, and unfortunately, more and more we are seeing the pen…

Well said. I blame 2nd coming Jobs (iMac and iPod era) and same period Microsoft for a lot of this as they competed with each other.

Usability became more important than flexibility. And intuitive operation prioritized over ease of learning.

There's a lot to be said for a harder to use computer with a learning curve, but which affords you more power to be a creator instead of a consumer at the end of the curve.

I'd go so far as to say that's better for us (as in, all humans).

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#58
post #52

Earlier quoted context omitted.

...and then LE also revokes their certificate.

That is a really farfetched scenario which I would never imagine happening. LE are not Cloudflare, I am sure they would not ridicule their neutral mission without actual legal force.

Unfortunately it's not far fetched. I wish it were. It's just an unpleasant thought we've decided not to think about.

LE are a US corp, subject to US laws, and at the whim of US court orders. The implications of that are worth gaming out.

Our laws are (arguably) mostly fair. But there are cases where they're not.

Picture a world where an administration rises to power in the US on a platform that seems insane, but everybody endorses it anyway. And this platform just so happens to be against the sort of thing you're trying to do on the internet.

Sci-hub are stealing. We as a community are mostly fine with that. We don't consider it stealing, because the moral good outweighs the bad by a hundred to one.

But this isn't about Sci-hub. This is about a world in which we're free to do as we please, because we have the ability to decide what we want to do. If we want to make a site that can make information available, and someone else doesn't like that information or feels that they own it, what do you do? You have no power.

And when you blindly put your faith in institutions like Let's Encrypt on their platform of openness and trust, you set yourself up for a shift: One day you wake up and find out you were mistaken, and we were all mistaken to push this centralized model in the name of security and convenience.

And of course, that's the fundamental truth, isn't it? Liberties have always been eroded by pushing security and convenience.

We should think carefully about who we trust, and why.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#59
post #52

Earlier quoted context omitted.

...and then LE also revokes their certificate.

That is a really farfetched scenario which I would never imagine happening. LE are not Cloudflare, I am sure they would not ridicule their neutral mission without actual legal force.

without actual legal force.

That's precisely the main concern here, given the nature of SciHub.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#60
Max Weber wrote the government has a monopoly on the legitimate use of force while arguing that we trade safety for freedom to build modern societies.

Going forward the ability to trust information will matter as much as physical safety. We're starting to build institutions that regulate that for us, CAs are one of the first.

Depending on where you stand this is either a success or a failure of institutional trust.

Post reply on HN