Live data from Hacker News

Tell HN: Sci-Hub's TLS certificate has started failing

news.ycombinator.com

101–110 of 154 posts

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#101

Earlier quoted context omitted.

This is really silly to me. Making computers accessible seems like a completely reasonable, sound priority. Yes, computer literacy is something we all need to work towards, but we'll never be in a world where the average person understands PKI, and saying that we should limit accessibility until they do is absurd.

but we'll never be in a world where the average person understands PKI 2000 years ago: "we'll never be in a world where the average person can read and write English"

[deleted]

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#102
post #24

It’s a sign of trouble, but I’m not sure it’s really “further” trouble, all it takes is for them to get a cert from Let’s Encrypt and call it a day. I’m surprised they weren’t using LE to begin with actually - since LE is available, why would you ever pay for another CA (excluding EV certificates)?

If you're on AWS it's easy enough to just use their CA with ALB

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#103
post #70

What's there to stop them self signing their cert and allowing everyone interested to add it to their certificate store?

I‘d imagine it’s because the average user is pretty dumb and probably not able/willing to go that extra step of adding a certificate manually.

I wouldn't say someone is dumb because they don't understand how SSL in the browser works. In the same sense I'm not dumb because I can't perform heart surgery.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#105
post #52

Earlier quoted context omitted.

That is a really farfetched scenario which I would never imagine happening. LE are not Cloudflare, I am sure they would not ridicule their neutral mission without actual legal force.

Unfortunately it's not far fetched. I wish it were. It's just an unpleasant thought we've decided not to think about. LE are a US corp, subject to US laws, and at the whim of US court orders. The implications of that are worth gaming out. Our laws are (arguably) mostly fair. But there are cases where they're not. Picture a world where an administration rises to power in the US on a platform that seems insane, but eve…

Sorry this is a pet peeve of mine, but I don't think sci-hub is stealing, it's infringing copyright. And this is one of those instances where I think what words we use to describe what sci-hub is doing matters.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#107

I'm a little confused. Setting aside the legal/ethical underpinnings.. Is the issue here that people are worried that an SA can revoke a cert or that it will be harder for the layperson to get to this particular site?

Both, I think. The certificate has clearly been revoked.[0] If Sci-Hub requested that, no problem. But if some third party did it, that's clearly a vulnerability.

And yes, the impact is that many people lose access. Or need to access via HTTP instead of HTTPS. Which exposes information about what they access. Unless the use the Tor onion site, which is maybe beyond most people's skills.

0) https://crt.sh/?id=274083328

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#108

Earlier quoted context omitted.

I do not see how censorship at the CA level is worse than the ISP/ DNS level. We should not discourage people from using TLS because it allows for one of many other methods to censor. SEC takedowns have happened for years without relying on TLS.

ISP/DNS-takedowns affect only customers of a single provider. Compelling every US provider is tedious and would still not affect people in other jurisdictions. CA-levy takedowns affect everyone.

A takedown against the hosting ISP would affect everyone, and DNS takedowns can involve changing the authoritative record.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#109

Earlier quoted context omitted.

This is really silly to me. Making computers accessible seems like a completely reasonable, sound priority. Yes, computer literacy is something we all need to work towards, but we'll never be in a world where the average person understands PKI, and saying that we should limit accessibility until they do is absurd.

but we'll never be in a world where the average person understands PKI 2000 years ago: "we'll never be in a world where the average person can read and write English"

Then let's re-evaluate the situation in 2000 years. Until then, PKI is still useful without the average person understands it. Just like how languages are useful without everyone understanding it.

I doubt this is even the point of GP.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#110
post #67

Earlier quoted context omitted.

You're not the only one. I hypothesised about this before in previous SciHub discussions, and SciHub isn't the only site that is/will be affected. Security is the ostensible benefit, and it's the one they advertise the most; easier censorship and centralised access control is the other---something which a lot of the pro-(traditional)-HTTPS advocates don't advertise. Make HTTPS mandatory (so no more HTTP), make it nea…

Let's not pretend the real reason google isn't so gung-ho about https everywhere is to prevent the ISPs from muscling into their businesses: * ads on page * seeing all internet traffic to enhance targeting

You make it sound like this is a bad thing. Regardless of if it also benefits Google's business model, both of these things benefit users and website owners. The only thing that benefits from injecting ads into a page or deeper ISP tracking is some ISP executive's bonus.
Post reply on HN