Live data from Hacker News

Tell HN: Sci-Hub's TLS certificate has started failing

news.ycombinator.com

131–140 of 154 posts

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#131
post #127

Earlier quoted context omitted.

> the Internet's original intent: to facilitate the fast and open communication of information Where'd you get that from? I think the Internet's original intent was to do it "because we can". Everything else came afterward.

The Internet was a United States Department of Defense project to create a communications network that could still function despite damage. It had nothing to do with fast, nor open, communication. That was just a by-product during the 90s.

In particular, to guarantee a devastating response to a Soviet first nuclear strike. As I recall.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#132
post #127

Earlier quoted context omitted.

> the Internet's original intent: to facilitate the fast and open communication of information Where'd you get that from? I think the Internet's original intent was to do it "because we can". Everything else came afterward.

The Internet was a United States Department of Defense project to create a communications network that could still function despite damage. It had nothing to do with fast, nor open, communication. That was just a by-product during the 90s.

To answer both of your points, fast was implied by virtue of it being a communication network.

The open part can be pedantically removed in the case of ARPAnet, but I've not met anyone who confuses the Internet with ARPAnet. The Internet, as it came to be called in the 90's with the rise of the World Wide Web, WAS at it's core 'open'. Pretty much everyone I've met who was around and working on the ARPAnet saw it as a foregone conclusion it (a network based on the lessons learned through ARPAnet) would be going public in one way or another.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#133
post #55

This type of thing is my number one objection to Certificate Authorities. In fact, it's my objection to computation illiteracy being acceptable in general amongst users. Devs and agencies cannot be trusted not to screw with things. If the average Joe cannot understand what is going on behind the curtains, they aren't free. Freedom is a scary thing to many groups, and unfortunately, more and more we are seeing the pen…

File a defect log to the book of Genesis, assign it to original developer, the God himself.

Why are you surprised that humans are being humans?

Why can't you put trust into the fact that there are more people being good most of the time.

Internet tools should be like paper and pencil, opinionless. Pencil maker doesn't get to control what gets written by the pencil, a social media platform maker doesn't get to control what gets said on the platform. Only when legally required, the pencil may be seized; only when legally required a social media post be taken down.

If with the protection and power of USA we can't stand by the Freedom of Expression in the marketplace of ideas, we are doomed to get an authoritarian overlords.

This "I don't like this free and open internet" because my ideas are losing is very dangerous power grab.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#134
post #44

Earlier quoted context omitted.

Firefox will happily accept self-signed certificates chaining to manually imported CAs. However, there are a lot of severely outdated guides on creating self-signed certificates out there, and many of the certificates produced that way won't be accepted by any modern browser. OpenSSL's terrible command-line UX certainly doesn't help matters. I've found easypki[1] to be the most convenient tool for this purpose. [1]:…

The person you're replying to doesn't have any problem with certs. Their problem is that they (or their employer) hijack a TLD for whatever ludicrous reason, and HSTS pre-loading applies to their hijacked names the same as it would to real names.

Ah, got it.

Well, another argument in favor of not overloading TLDs for internal domains, then, and just buying an additional domain if you really want to have separate internal and external domains.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#135

Earlier quoted context omitted.

This reads like a conspiracy theory. Who are the pro HTTPS everywhere people that are _also_ secretly trying to further censorship? This would have to be a fairly vast conspiracy, but, you don't provide any evidence.

It's a simple fact. It doesn't need to be planned or conspirated. The fact that root CAs are at the top, modulo self signed certs exchanged person to person IRL, is certainly no secret. The conspiracy would be that they might use the fact to censor or listen, whoever they are. The conspiracy would be not to tell anyone beforehand, because otherwise it wouldn't be a conspiracy anymore. What kind of exhaustive evidence…

Who are "they"? Google? Mozilla? Microsoft? Apple? The 100s of CAs? And, are they all working together? And there hasn't been a single whistleblower to expose this?

What do you mean "listen"? CAs can invalidate certs at will, but, they have no mechanism to listen on communications (unless you give them your private key, but, then anyone you give your private key to can eavesdrop).

The CA system has lots of issues. It would be a pretty big conspiracy if there were thousands of people that knew of something better and said nothing. But, there is absolutely no proof that anyone has any idea how to do better than the CA system. Do you know of such a system or have any evidence that someone else does? Google, despite their flaws w.r.t. privacy, has done quite a bit of work to improve the CA situation - Certificate Transparency, for example.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#136
post #67

Earlier quoted context omitted.

Let's not pretend the real reason google isn't so gung-ho about https everywhere is to prevent the ISPs from muscling into their businesses: * ads on page * seeing all internet traffic to enhance targeting

You make it sound like this is a bad thing. Regardless of if it also benefits Google's business model, both of these things benefit users and website owners. The only thing that benefits from injecting ads into a page or deeper ISP tracking is some ISP executive's bonus.

Challenge: Next person that downvotes me, also leave a comment explaining why.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#137

Max Weber wrote the government has a monopoly on the legitimate use of force while arguing that we trade safety for freedom to build modern societies. Going forward the ability to trust information will matter as much as physical safety. We're starting to build institutions that regulate that for us, CAs are one of the first. Depending on where you stand this is either a success or a failure of institutional trust.

Keep in mind all of Weber's argument. Government has a monopoly on the legitimate use of force . Weber claims that the state is the "only human Gemeinschaft which lays claim to the monopoly on the legitimated use of physical force. However, this monopoly is limited to a certain geographical area, and in fact this limitation to a particular area is one of the things that defines a state."[2] In other words, Weber desc…

It sounds like a more fundamental question is, "Who authorized this Max Weber dude to dictate who may legitimately use force?"

He has an opinion, I have an opinion, you have an opinion, Charles Koch has an opinion... everybody has an opinion.

At some point, the answer to questions like this always comes down to "God," or "Nobody," or "Whoever has the most money/biggest weapons." It's an unsatisfying debate.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#138
post #127

Earlier quoted context omitted.

> the Internet's original intent: to facilitate the fast and open communication of information Where'd you get that from? I think the Internet's original intent was to do it "because we can". Everything else came afterward.

The Internet was a United States Department of Defense project to create a communications network that could still function despite damage. It had nothing to do with fast, nor open, communication. That was just a by-product during the 90s.

There were other internetworking projects at the same time as ARPANET. The DoD's tech was better, and to people like the IETF, "better tech" is all that matters in picking a standard. But most of the people driving the adoption of internetworking among large corporations and organizations weren't DoD people, or even people with a defence mindset. They were just sysadmins, librarians, and communications engineers trying to freely peer their networks with other networks, adopting whatever standards came along that would allow them to do that. Such folk worked on their own standards (see e.g. MIT's Chaosnet) but chose to switch over to the [IETF standardization of the] ARPANET stack when it became clear that's where the future was.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#139
post #127

Earlier quoted context omitted.

> the Internet's original intent: to facilitate the fast and open communication of information Where'd you get that from? I think the Internet's original intent was to do it "because we can". Everything else came afterward.

The Internet was a United States Department of Defense project to create a communications network that could still function despite damage. It had nothing to do with fast, nor open, communication. That was just a by-product during the 90s.

You're referring to ARPA net, which is not "The Internet".

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#140
post #138
post #127

Earlier quoted context omitted.

The Internet was a United States Department of Defense project to create a communications network that could still function despite damage. It had nothing to do with fast, nor open, communication. That was just a by-product during the 90s.

There were other internetworking projects at the same time as ARPANET. The DoD's tech was better, and to people like the IETF, "better tech" is all that matters in picking a standard. But most of the people driving the adoption of internetworking among large corporations and organizations weren't DoD people, or even people with a defence mindset. They were just sysadmins, librarians, and communications engineers tryi…

Precisely this. The Internet was born out of the dreams and efforts of many nerdy people who had no reason to do it other than it could be done, and nobody had done it before.

That reasoning drove the majority of computer technology progress during the 1980s and 1990s. It wasn't until AFTER the birth of the World Wide Web did mainstream businesses start to really look at monetizing this new market, and in a symbiotic way hackers and nerds and geeks started crowing about altruistic philosophies like decentralization and how information "wants" to be free.

Post reply on HN