Live data from Hacker News

The Impending Doom of Expiring Root CAs and Legacy Clients

scotthelme.co.uk

91–100 of 209 posts

Re: The Impending Doom of Expiring Root CAs and Legacy Clients

#91

If you have a current Firefox that first diagram may not be correct for you. Let's tell a brief story about why. Servers, as Scott explains, are supposed to present a "chain" of certificates, in practice it's one leaf and then just anything else that might be useful for clients to assemble a trust path. If you do this everything works. But lots of servers are misconfigured and present only the leaf certificate, not l…

Interesting note about Firefox there.

I've certainly expirenced the missing "missing intermediate cert" problem before. It is a bit of a nightmare to debug.

1. Had issue, raise support ticket: TLS not working

2. Ticket closed as can't reproduce

3. Try myself again locally, also can't reproduce. Hmpf!

4. 2 months goes by..

5. Experience same issue. Debug more carefully locally, use openssl go get proof of missing intermediate

6. Raise support ticket with platform team, then try to convince them that just because most people are not affected, it still needs to be fixed!

Re: The Impending Doom of Expiring Root CAs and Legacy Clients

#92
post #22

Earlier quoted context omitted.

Someone on HN recently floated the idea of a company that would make quality, non-smart electronics and appliances that would also be easily serviceable. I wish this existed and would pay significantly more for products like this. To address your question, I think they’re all “smart” now. I ended up getting a low-end Samsung 4K a few months ago and it’s been good so far. It starts up very quickly, maybe 1-2 seconds.…

Never add your WiFi credentials you your TV. It doesn’t let you remove them so you’re only option is to create a “dummy” network (ex: phone as a hotspot) and switch to it. Also, watch out for clueless^helpful friends and relatives who try to “fix” your TV’s WiFi.

IIUC, you're saying there's no obvious way to make the TV stop using the Wifi network once you tell it the SSID + password.

Couldn't you just change the wifi password?

Re: The Impending Doom of Expiring Root CAs and Legacy Clients

#93
post #58

Earlier quoted context omitted.

Yeah, I would be less upset about the ad situation if they had made it clear up front and given me a choice like Amazon does with the Kindle. That said, when companies price the ad-free premium at 1000x the expected ad revenue, it gets aggravating again.

What's the advantage of this? Surely they're better off pricing it at 2x the expected ad revenue, since then they can expect to get twice as much now as they otherwise would get eventually ? Indeed, even if it were 1.01x the expected ad revenue they've won with this upsell.

Charging 1.01x the expected ad revenue wouldn't cover the cost of implementing the no-ad option. Even 2x might be in break-even territory when you include extra support costs and the like (one person on the phone because they bought no-ads and got ads due to a mishap somewhere wipes out the profit from a lot of no-ad sales).

There's also the funny issue where people who can afford to pay extra for the no-ads option are exactly the people that advertisers want to show ads to. If the no-ads option is $5, then you're left selling ads with a target market of people who can't afford or don't want to spend $5, and that ends up driving down your ad revenue. A large gap between the expected ad revenue and the price of the no-ad option helps mitigate this effect.

Re: The Impending Doom of Expiring Root CAs and Legacy Clients

#94

I begrudgingly bought a 'Smart TV' just because I wanted a 4K monitor. But I use it as a dumb monitor and watch app-based content through an Apple TV. At least I'm reasonably sure the Apple TV will be updated for 5-10 years, and is a lot more disposable than a giant TV. My last TV worked great for about 12 years. No way Panasonic would've kept supporting it that long. Honestly, the thing I hate most about smart TVs,…

I honestly do not know why TV Manufacturers have not make the "smart" function upgrade and modular

Buy a tv, then in 5 years when I need more functionality I simply upgrade the "smart module" for $50 instead of having to replace the entire TV

Of course they would then probably try to make a "as a service" subscription bullshit and it would be worse than we have now so never-mind I retract this comment

Re: The Impending Doom of Expiring Root CAs and Legacy Clients

#95
post #22

Earlier quoted context omitted.

Someone on HN recently floated the idea of a company that would make quality, non-smart electronics and appliances that would also be easily serviceable. I wish this existed and would pay significantly more for products like this. To address your question, I think they’re all “smart” now. I ended up getting a low-end Samsung 4K a few months ago and it’s been good so far. It starts up very quickly, maybe 1-2 seconds.…

Never add your WiFi credentials you your TV. It doesn’t let you remove them so you’re only option is to create a “dummy” network (ex: phone as a hotspot) and switch to it. Also, watch out for clueless^helpful friends and relatives who try to “fix” your TV’s WiFi.

This is why you segment out your WiFi, I have 4 SSID's

1. Normal Traffic

2. Guest

3. Security Devices (Camera's, and other Home Automation)

4. Media Devices (Roku, FireTV, Smart TV's, etc)

media devices only have access to my home Plex server and the internet nothing else

Re: The Impending Doom of Expiring Root CAs and Legacy Clients

#96

Earlier quoted context omitted.

Doubt it would work. Hardware is commoditized and low margin. That's why TVs are embedding internet advertising, to make fat stacks from their otherwise barely profitable products.

Wouldn’t that work in _favor_ of the startup idea? If the hardware is a commodity and the market is for a bare-bones, self-serviceable “just a TV”, then the startup should have significantly lower engineering costs and benefit from the low component costs. Given that people on this thread are stating that they would pay a premium for such a product makes it seem even more viable. Maybe other people have different “se…

What people on HN say they would pay for, and what people actually pay for, are very different.

Re: The Impending Doom of Expiring Root CAs and Legacy Clients

#97

I begrudgingly bought a 'Smart TV' just because I wanted a 4K monitor. But I use it as a dumb monitor and watch app-based content through an Apple TV. At least I'm reasonably sure the Apple TV will be updated for 5-10 years, and is a lot more disposable than a giant TV. My last TV worked great for about 12 years. No way Panasonic would've kept supporting it that long. Honestly, the thing I hate most about smart TVs,…

Someone on HN recently floated the idea of a company that would make quality, non-smart electronics and appliances that would also be easily serviceable. I wish this existed and would pay significantly more for products like this. To address your question, I think they’re all “smart” now. I ended up getting a low-end Samsung 4K a few months ago and it’s been good so far. It starts up very quickly, maybe 1-2 seconds.…

I believe a lot of television manufacturers already offer the equivalent of that as "commercial TVs" or "digital signage" they are marketed toward businesses. I think they're typically more expensive because they don't collect and sell data to subsidize cost, but that might be what you're looking for. Here's an example of a Samsung digital signage TV https://www.samsung.com/us/business/products/displays/4k-uhd...

Re: The Impending Doom of Expiring Root CAs and Legacy Clients

#98
post #17
post #7

Having expiring certificates/key rotation might be a net negative: if you keep the private key secure, there is no need to rotate it, and it avoids a lot of hassle. Also, if you have a revocation mechanism, then rotation doesn't add that much for keys that are only used for signing and not for encryption (like the CA keys). Of course in some cases like domains it's necessary since the domain can be transferred, but t…

It's a good point. At any given time, the key is either compromised or it's not. And you may or may not know either way. If it's compromised, and you know, then it should be revoked -- if your only mechanism to revoke it is waiting some amount of time (several days, months, or even a decade) you have a pretty big problem. If you don't have a way to detect if it's compromised, rotating a precaution almost makes sense…

What we're talking about here are trust roots and one of the things people usually get wrong when they try to draw a diagram of how this works is they draw certificates as nodes and then just connect those nodes together with abstract lines.

Actually the correct mental model is a graph of public keys and the lines between them (joining two nodes directionally) are the certificates.

So although we traditionally handle the root trust set as a bunch of self-signed certificates, those certificates are largely unimportant, what's vital is the public keys baked inside them.

As a result what makes older roots obsolete is not a signature algorithm, but the type and size of key chosen when they were created, that key is in a very real sense the root.

This AddTrust root for example was 2048-bit RSA. You can use that size of RSA key today for your funny cat video site, no problem, but it's clearly an inadequate choice for a CA root. Fortunately roots like this are gradually expiring.

If I figure out how to build a machine that can break 2048-bit RSA keys for $10M per key it makes no sense to target your cat videos. But a CA root is an attractive target. So we'd like to have more margin for the roots not the same or less.

Some years ago Mozilla finally prohibited 1024-bit RSA keys in roots. Some of the oldest roots in the business were 1024-bit RSA, which today would not be considered acceptable even on your cat video site, but when those roots were created 1024-bit RSA seemed safe enough.

In 5-10 years you'd probably want as much as possible for roots to be the more compact elliptic curve public keys, maybe there will be some better (more secure) curves in use by then, maybe not.

Re: The Impending Doom of Expiring Root CAs and Legacy Clients

#99

Earlier quoted context omitted.

Someone on HN recently floated the idea of a company that would make quality, non-smart electronics and appliances that would also be easily serviceable. I wish this existed and would pay significantly more for products like this. To address your question, I think they’re all “smart” now. I ended up getting a low-end Samsung 4K a few months ago and it’s been good so far. It starts up very quickly, maybe 1-2 seconds.…

Specifically for TVs, you can get a new display driver board for whatever panel is in there. Eats HDMI/DP, spits out eDP or VBO or whatever the panel format is. Often these are pretty basic, with a minimal OSD pasted in by the Shenzhen seller who configures the thing to your order. Personally I'm trying to get my hands on the SDK for the software that runs in the driver chip (does the OSD and the scaling and everythi…

Nice. Do any of those support 100+Hz frame rate or Freesync?

Re: The Impending Doom of Expiring Root CAs and Legacy Clients

#100

"Impending" doom? Devices from 10 years ago are _already_ useless online. Not only are the root certificates completely expired, but let's see which protocols does an openssl 0.9.8 build from a decade ago have in common with, say, current Gmail's IMAPS server: NONE.

My TP-LINK Wifi-N router bought in 2010 still works nicely on latest OpenWRT and I assure you it runs software more up to date than 99% of closed firmware devices currently on the market. Open-source firmware is a way to go to stay current and to avoid producing more electronic waste.
Post reply on HN