Live data from Hacker News

Tell HN: Sci-Hub's TLS certificate has started failing

news.ycombinator.com

121–130 of 154 posts

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#121

Earlier quoted context omitted.

I‘d imagine it’s because the average user is pretty dumb and probably not able/willing to go that extra step of adding a certificate manually.

I wouldn't say someone is dumb because they don't understand how SSL in the browser works. In the same sense I'm not dumb because I can't perform heart surgery.

Dumb in the sense of "will not say anything, not complain nor ask question", you know, literally mute.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#123

Earlier quoted context omitted.

You're not the only one. I hypothesised about this before in previous SciHub discussions, and SciHub isn't the only site that is/will be affected. Security is the ostensible benefit, and it's the one they advertise the most; easier censorship and centralised access control is the other---something which a lot of the pro-(traditional)-HTTPS advocates don't advertise. Make HTTPS mandatory (so no more HTTP), make it nea…

This reads like a conspiracy theory. Who are the pro HTTPS everywhere people that are _also_ secretly trying to further censorship? This would have to be a fairly vast conspiracy, but, you don't provide any evidence.

It's a simple fact. It doesn't need to be planned or conspirated. The fact that root CAs are at the top, modulo self signed certs exchanged person to person IRL, is certainly no secret. The conspiracy would be that they might use the fact to censor or listen, whoever they are. The conspiracy would be not to tell anyone beforehand, because otherwise it wouldn't be a conspiracy anymore. What kind of exhaustive evidence do you expect for the claim that they are not saying something? And maybe you are right, this is extremely hypothetical, they would never take action to invalidate certs... Hey, wait a second!!!

The real conspiracy would be to know a better system and not tell anyone. Which is like sponsoring scientific discoveries and then hiding those behind a pay wall. Oh wait again.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#124
post #27

Earlier quoted context omitted.

I doubt they just went out and did it randomly. I'd guess it was done via court order. The ACS got a court order against them that also ordered that 'internet search engines, web hosting sites, internet service providers (ISPs), domain name registrars and domain name registries cease facilitating “any or all domain names and websites through which Defendant Sci-Hub engages in unlawful access to, use, reproduction, an…

I‘m really no expert on American law but can such a broad worded verdict be legal? I would have imagined that they‘d have to name every company/person that has to comply with it.

The last article I saw on it was saying they got tired of playing whack-a-mole so went back and the court gave them a blanket ban.

I'm sure they could challenge it if they wanted to step on to US soil which, in this case, probably isn't such a good idea.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#125
post #44

Earlier quoted context omitted.

That's exactly how it's set up. Doesn't help, I'm apparently not allowed to tell my browser what to do in this instance.

Firefox will happily accept self-signed certificates chaining to manually imported CAs. However, there are a lot of severely outdated guides on creating self-signed certificates out there, and many of the certificates produced that way won't be accepted by any modern browser. OpenSSL's terrible command-line UX certainly doesn't help matters. I've found easypki[1] to be the most convenient tool for this purpose. [1]:…

The person you're replying to doesn't have any problem with certs. Their problem is that they (or their employer) hijack a TLD for whatever ludicrous reason, and HSTS pre-loading applies to their hijacked names the same as it would to real names.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#126

Earlier quoted context omitted.

This is absolutely insane, and Microsoft really has no position to make these demands. Does McDonalds have the right to get your drivers licensed revoked? (Even if you say... use the drive thru to steal mcnuggets?) Hell no, and neither does microsoft.

Could MS not ultimately stop honoring said vendor's certificates?

Yes, in the extreme case, Microsoft would be able to issue an urgent security update whose only purpose was to remove this CA from the Schannel trust store. The effect would be that IE, Edge, Chrome and most other SSL/TLS applications on Windows ceased to trust those certs. That's obviously really drastic, but they could certainly do it. (Firefox and various Free things wouldn't be affected because even on Windows they don't use Microsoft's trust store)

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#127
post #55

This type of thing is my number one objection to Certificate Authorities. In fact, it's my objection to computation illiteracy being acceptable in general amongst users. Devs and agencies cannot be trusted not to screw with things. If the average Joe cannot understand what is going on behind the curtains, they aren't free. Freedom is a scary thing to many groups, and unfortunately, more and more we are seeing the pen…

> the Internet's original intent: to facilitate the fast and open communication of information Where'd you get that from? I think the Internet's original intent was to do it "because we can". Everything else came afterward.

The Internet was a United States Department of Defense project to create a communications network that could still function despite damage. It had nothing to do with fast, nor open, communication. That was just a by-product during the 90s.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#128

Earlier quoted context omitted.

I just tried https://sci-hub.tw/ (Chrome) and got a secure connection without warnings. Since the issuer of the certificate that my browser showed for the connection is "Comodo" I guess the revocation didn't reach my browser yet? EDIT: IE and Firefox say "insecure". What really annoys me: There does not seem to be any way - none that I could find - to get IE and Firefox to connect anyway?

There does not seem to be any way - none that I could find - to get IE and Firefox to connect anyway? In Firefox, I think you can only by disabling the check (Preferences → Advanced → Certificates → Query OCSP ...). You probably don't want to keep that disabled, though.

It's fairly marginal, which is why it's switched off in Chrome. To get acceptable performance in the real world they have to soft fail. But that means most bad guys would just force it to fail and then it treats that as OK. So it's a seat-belt that snaps if there's a sudden impact. Not great.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#129
post #57

Earlier quoted context omitted.

Well said. I blame 2nd coming Jobs (iMac and iPod era) and same period Microsoft for a lot of this as they competed with each other. Usability became more important than flexibility. And intuitive operation prioritized over ease of learning. There's a lot to be said for a harder to use computer with a learning curve, but which affords you more power to be a creator instead of a consumer at the end of the curve. I'd g…

This is really silly to me. Making computers accessible seems like a completely reasonable, sound priority. Yes, computer literacy is something we all need to work towards, but we'll never be in a world where the average person understands PKI, and saying that we should limit accessibility until they do is absurd.

Not what I'm suggesting. More what I am suggesting is that we REALLY need to get away from teaching software products, and start teaching how to use computers.

Example:

Teaching fundamental abstractions before basing education on one set or another.

Teaching fundamental program sets/basics of toolchains (Think scripts, text editors, and intro to program compilation.)

Teaching fundamental protocols.

Teaching about infrastructure.

Teaching how to do X in Windows/Mac/Linux.

IN THAT ORDER. Notice that that curriculum, while it would likely have to choose one OS or another based on circumstances, focuses on what you can DO with a computer, and lays a foundation through which the neophyte user can begin to understand what a computer and the NET really are.

The NET isn't a pretty screen. It isn't one company's search engine, it's the means by which info goes from HERE to THERE. A computer isn't some mere calculator. It is an extension of our minds (and should be civically treated as such, but that's another post).

I can die happy if within my lifetime, my occupation in the tech industry becomes "unskilled" labor. For I will have contributed to finding a way to elevate mankind to a me level.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#130
post #127

Earlier quoted context omitted.

> the Internet's original intent: to facilitate the fast and open communication of information Where'd you get that from? I think the Internet's original intent was to do it "because we can". Everything else came afterward.

The Internet was a United States Department of Defense project to create a communications network that could still function despite damage. It had nothing to do with fast, nor open, communication. That was just a by-product during the 90s.

[deleted]
Post reply on HN