Live data from Hacker News

The Impending Doom of Expiring Root CAs and Legacy Clients

scotthelme.co.uk

171–180 of 209 posts

Re: The Impending Doom of Expiring Root CAs and Legacy Clients

#171

I begrudgingly bought a 'Smart TV' just because I wanted a 4K monitor. But I use it as a dumb monitor and watch app-based content through an Apple TV. At least I'm reasonably sure the Apple TV will be updated for 5-10 years, and is a lot more disposable than a giant TV. My last TV worked great for about 12 years. No way Panasonic would've kept supporting it that long. Honestly, the thing I hate most about smart TVs,…

[deleted]

Re: The Impending Doom of Expiring Root CAs and Legacy Clients

#172

Earlier quoted context omitted.

My TCL bootloops if it doesn't have an internet connection. It also shows ads on its screensaver. Coincidence? Dunno, but it's sure making TCL money and making me miserable.

Can you factory reset it? I have a TCL Roku TV which I've never connected to the Internet and it shows a pretty standard 'logo bouncing around the edges of the screen' screensaver.

I sure can. I can even select a screensaver other than the "city with ads" one. Then it starts to bootloop until I reset it to defaults and connect it to the internet. Yes, I need to do both, or it starts bootlooping again. Support is all too happy to walk me through the process.

Re: The Impending Doom of Expiring Root CAs and Legacy Clients

#173

This might be a stupid question, but... Why do root certificates have to expire at all? The article presents this as if it's an immutable law of physics.

We have no real means of revoking certificates whose private keys have leaked. Eventual expiration seems better than nothing. Also, ciphers tend to become obsolete, so enforcing churn will help keep things moving forward. I'm not an expert here though, there may be other reasons.

> Eventual expiration seems better than nothing.

Does it? Because that is the cause of the 'impending doom' from TFA

Re: The Impending Doom of Expiring Root CAs and Legacy Clients

#174

Earlier quoted context omitted.

AVRs are a huge hassle to deal with, and overkill when you only have 2 or 3 devices to switch between and/or don’t have many audio-only devices. AVRs made more sense during the days when we’d have CD players, tape decks, VCRs and DVD player, vinyl record players, cable/satellite STBs, and a game console or two all hooked up. Now it’s just an STB (if you aren’t a cord-cutter), a Roku/AppleTV/Chromecast/FireTV, and may…

Without an AV Receiver, how would you drive a set of speakers?

That's what HDMI ARC is for - the TV can be connected to a normal speaker amplifier (so the TV acts as the receiver, basically).

I'm wary of using HDMI AVRs today because they add input lag.

Re: The Impending Doom of Expiring Root CAs and Legacy Clients

#175

Earlier quoted context omitted.

I really wish I could just remove the wifi chip. I'm tempted to take the rear panel off just to see if it's reasonably accessible.

Or just snip the antenna

Put it in a faraday cage.

Re: The Impending Doom of Expiring Root CAs and Legacy Clients

#176
post #55

Earlier quoted context omitted.

I have a dummy hotspot with no access to anything whatsoever, and which I allow my TV to connect to. Apart from exposing an undocumented API (with code execution capabilities), and allowing logging in as root over Telnet (without a password), it also tries to fetch software updates over plain HTTP. It's a bloody nightmare. On the plus side, it was possible to disable many of the smart features once I discovered the t…

Vulnerabilities are a massive trade off. I want my devices to be open to me, not to anyone. Seems like it should be straight forward to give you access to the device (like "scan this qrcode on the inside of this panel" and you get the private key). One can dream...

Yeah, pretty much every single "smart" device I've ever bought has had vulnerabilities that never got patched. It's ridiculous.

On the plus side, my 10 year-old laptop still finds a use as an access point/firewall for all those things. :D

Re: The Impending Doom of Expiring Root CAs and Legacy Clients

#177
post #50

Earlier quoted context omitted.

> ... I wanted a 4K monitor. To all the folks reading at home... I would remind everyone that a TV is not a monitor. I got a relatively inexpensive LG 43in TV to use as a desktop monitor. I've had issues. Beyond the usual "make sure your graphics card actually supports 4K" and such, you also need to take some time to dig through the TV settings when you are using it on a PC. In particular, you definitely want to turn…

I'm calling what I want for my living room a 'monitor'. I want a TV that's a monitor, basically, not the other way around. For my computer, I use a 32" LG 4K monitor, and it's great. No 'smart' features found there. But I can't find a 4K monitor in the 42-50" range that has multiple HDMI inputs that is not incredibly pricey (e.g. broadcast/commercial realm) I could use in my living room.

I've been having my eye on an LG 43UD79B [0] for a couple of months, that I would use both as a monitor and as a TV.

It has 4 HDMI inputs and a USB-C with display port. It even has a remote.

It's an IPS panel though. From what I hear not everyone loves those.

Amazon has it in France for around €600.

[0]https://www.lg.com/us/monitors/lg-43UD79-B-4k-uhd-led-monito...

Re: The Impending Doom of Expiring Root CAs and Legacy Clients

#178

Earlier quoted context omitted.

Someone on HN recently floated the idea of a company that would make quality, non-smart electronics and appliances that would also be easily serviceable. I wish this existed and would pay significantly more for products like this. To address your question, I think they’re all “smart” now. I ended up getting a low-end Samsung 4K a few months ago and it’s been good so far. It starts up very quickly, maybe 1-2 seconds.…

Specifically for TVs, you can get a new display driver board for whatever panel is in there. Eats HDMI/DP, spits out eDP or VBO or whatever the panel format is. Often these are pretty basic, with a minimal OSD pasted in by the Shenzhen seller who configures the thing to your order. Personally I'm trying to get my hands on the SDK for the software that runs in the driver chip (does the OSD and the scaling and everythi…

Any pointers to forums/projects or sellers of these? Sounds like a bit of a rabbit hole, tbh :-)

Re: The Impending Doom of Expiring Root CAs and Legacy Clients

#179
post #50

I begrudgingly bought a 'Smart TV' just because I wanted a 4K monitor. But I use it as a dumb monitor and watch app-based content through an Apple TV. At least I'm reasonably sure the Apple TV will be updated for 5-10 years, and is a lot more disposable than a giant TV. My last TV worked great for about 12 years. No way Panasonic would've kept supporting it that long. Honestly, the thing I hate most about smart TVs,…

> ... I wanted a 4K monitor. To all the folks reading at home... I would remind everyone that a TV is not a monitor. I got a relatively inexpensive LG 43in TV to use as a desktop monitor. I've had issues. Beyond the usual "make sure your graphics card actually supports 4K" and such, you also need to take some time to dig through the TV settings when you are using it on a PC. In particular, you definitely want to turn…

Why not just get a 43" monitor instead of trying to misuse a TV as a monitor?

Re: The Impending Doom of Expiring Root CAs and Legacy Clients

#180

This might be a stupid question, but... Why do root certificates have to expire at all? The article presents this as if it's an immutable law of physics.

We have no real means of revoking certificates whose private keys have leaked. Eventual expiration seems better than nothing. Also, ciphers tend to become obsolete, so enforcing churn will help keep things moving forward. I'm not an expert here though, there may be other reasons.

I feel like if a certificate gets compromised, the fact that it expires in 5 years won't be of any help from the security standpoint. There are already mechanisms in place to revoke certificates before they expire.

https://en.wikipedia.org/wiki/Certificate_revocation_list

https://en.wikipedia.org/wiki/Online_Certificate_Status_Prot...

Post reply on HN