Earlier quoted context omitted.
Correct me if I'm wrong, but the signed server-identifying cert is swapped in TLS before the connection is encrypted, no? So it's not technically infeasible to have networking gear drop any connection which doesn't chain back to a government-approved root?
So it's not technically infeasible to have networking gear drop any connection which doesn't chain back to a government-approved root? Yse, and that is a very scary thought. China is doing something similar already.
Tell HN: Sci-Hub's TLS certificate has started failing
71–80 of 154 posts
Re: Tell HN: Sci-Hub's TLS certificate has started failing
#72Earlier quoted context omitted.
There are plenty of reasons to pay for a certificate. Wildcard certificates only came out last month on LE, and people might still be weary to switch their primary site over so quickly. Additionally, there's still a few cases I can think of where a custom certificate might be needed. For instance, I recently consolidated my personal projects and site onto one server. I needed a single certificate that'd cover two dom…
You can definitely get certs from LetsEncrypt that have SANs for multiple unrelated domains. I haven’t tried out wildcard certificates at all yet, but I would be surprised if it didn’t allow combining those features…
Re: Tell HN: Sci-Hub's TLS certificate has started failing
#73This type of thing is my number one objection to Certificate Authorities. In fact, it's my objection to computation illiteracy being acceptable in general amongst users. Devs and agencies cannot be trusted not to screw with things. If the average Joe cannot understand what is going on behind the curtains, they aren't free. Freedom is a scary thing to many groups, and unfortunately, more and more we are seeing the pen…
Well said. I blame 2nd coming Jobs (iMac and iPod era) and same period Microsoft for a lot of this as they competed with each other. Usability became more important than flexibility. And intuitive operation prioritized over ease of learning. There's a lot to be said for a harder to use computer with a learning curve, but which affords you more power to be a creator instead of a consumer at the end of the curve. I'd g…
Making computers accessible seems like a completely reasonable, sound priority. Yes, computer literacy is something we all need to work towards, but we'll never be in a world where the average person understands PKI, and saying that we should limit accessibility until they do is absurd.
Re: Tell HN: Sci-Hub's TLS certificate has started failing
#74It’s a sign of trouble, but I’m not sure it’s really “further” trouble, all it takes is for them to get a cert from Let’s Encrypt and call it a day. I’m surprised they weren’t using LE to begin with actually - since LE is available, why would you ever pay for another CA (excluding EV certificates)?
This is a much bigger deal than people are giving it credit for. At any point in history, have CAs revoked certs solely to censor a target website? Maybe the answer is yes. I don't know. But this is a rude wake-up call for me and everyone else who tried to force the world into this shape. We've all been shouting "You have to use TLS! It's fundamental security 101. If you're not using https, your site is probably brok…
SEC takedowns have happened for years without relying on TLS.
Re: Tell HN: Sci-Hub's TLS certificate has started failing
#75What's there to stop them self signing their cert and allowing everyone interested to add it to their certificate store?
Re: Tell HN: Sci-Hub's TLS certificate has started failing
#76Max Weber wrote the government has a monopoly on the legitimate use of force while arguing that we trade safety for freedom to build modern societies. Going forward the ability to trust information will matter as much as physical safety. We're starting to build institutions that regulate that for us, CAs are one of the first. Depending on where you stand this is either a success or a failure of institutional trust.
Government has a monopoly on the legitimate use of force.
Weber claims that the state is the "only human Gemeinschaft which lays claim to the monopoly on the legitimated use of physical force. However, this monopoly is limited to a certain geographical area, and in fact this limitation to a particular area is one of the things that defines a state."[2] In other words, Weber describes the state as any organization that succeeds in holding the exclusive right to use, threaten, or authorize physical force against residents of its territory. Such a monopoly, according to Weber, must occur via a process of legitimation.
https://en.wikipedia.org/wiki/Monopoly_on_violence
This is mis-read by many Libertarians, including Charles Koch,[1] who directly funds a wide set of Libertarian institutional propaganda mills,[2] that this invalidates government. It does not.
Absent a monopoly, there are multiple parties that claim legitimacy over use of force, including lical strongmen, tribes, or corporations, for all of which there is an extensive history of same (including Koch Industries, to the present).
Government's monopoly is not for unlimited use of force, but for legitimate use.
And if some alternate structure emerges claiming this right, it is, ipso facto, government.
It is also possible for actual or nominal governments' use of force to be illegitimate. Which it rather frequently is.
________________________________
Notes:
1. https://www.marketplace.org/2015/10/21/business/corner-offic...
2. Amply documented, see: https://en.wikipedia.org/wiki/Political_activities_of_the_Ko... https://www.sourcewatch.org/index.php/Koch_Brothers
Re: Tell HN: Sci-Hub's TLS certificate has started failing
#77It’s a sign of trouble, but I’m not sure it’s really “further” trouble, all it takes is for them to get a cert from Let’s Encrypt and call it a day. I’m surprised they weren’t using LE to begin with actually - since LE is available, why would you ever pay for another CA (excluding EV certificates)?
There are plenty of reasons to pay for a certificate. Wildcard certificates only came out last month on LE, and people might still be weary to switch their primary site over so quickly. Additionally, there's still a few cases I can think of where a custom certificate might be needed. For instance, I recently consolidated my personal projects and site onto one server. I needed a single certificate that'd cover two dom…
Re: Tell HN: Sci-Hub's TLS certificate has started failing
#78Earlier quoted context omitted.
Well said. I blame 2nd coming Jobs (iMac and iPod era) and same period Microsoft for a lot of this as they competed with each other. Usability became more important than flexibility. And intuitive operation prioritized over ease of learning. There's a lot to be said for a harder to use computer with a learning curve, but which affords you more power to be a creator instead of a consumer at the end of the curve. I'd g…
More importantly, the ability to write and run your own code easily, of which learning is only part of the process. From that perspective, Apple was closed from almost the beginning, while the PC and various other micros of the time (ZX, C64, etc.) started out open.
Re: Tell HN: Sci-Hub's TLS certificate has started failing
#79Earlier quoted context omitted.
Issuer: COMODO That figures. When will we stop giving money to those scumbags? Trying to register the Let's Encrypt trademark was enough for me to never give them a cent again.
I doubt they just went out and did it randomly. I'd guess it was done via court order. The ACS got a court order against them that also ordered that 'internet search engines, web hosting sites, internet service providers (ISPs), domain name registrars and domain name registries cease facilitating “any or all domain names and websites through which Defendant Sci-Hub engages in unlawful access to, use, reproduction, an…
Re: Tell HN: Sci-Hub's TLS certificate has started failing
#80It’s a sign of trouble, but I’m not sure it’s really “further” trouble, all it takes is for them to get a cert from Let’s Encrypt and call it a day. I’m surprised they weren’t using LE to begin with actually - since LE is available, why would you ever pay for another CA (excluding EV certificates)?
...and then LE also revokes their certificate.