Live data from Hacker News

The Impending Doom of Expiring Root CAs and Legacy Clients

scotthelme.co.uk

181–190 of 209 posts

Re: The Impending Doom of Expiring Root CAs and Legacy Clients

#181

Earlier quoted context omitted.

Charging 1.01x the expected ad revenue wouldn't cover the cost of implementing the no-ad option. Even 2x might be in break-even territory when you include extra support costs and the like (one person on the phone because they bought no-ads and got ads due to a mishap somewhere wipes out the profit from a lot of no-ad sales). There's also the funny issue where people who can afford to pay extra for the no-ads option a…

Isn't this advertising pricing paradox proof of the exploitative nature of advertising?

Pretty much. In Australia Pay TV has more ads in it per hour than free to air TV.

Re: The Impending Doom of Expiring Root CAs and Legacy Clients

#182
post #8

Earlier quoted context omitted.

I never hooked up the smart tv to my wireless network. I have heard too many stories about data getting sent back to the manufacturers to sell your watching habits, etc. Instead, I use a Roku, that I know gets updates (and yes, they also sell your watching habits, but so far, nextdns.io's lists block the DNS that roku uses to do this.)

I have a dummy hotspot with no access to anything whatsoever, and which I allow my TV to connect to. Apart from exposing an undocumented API (with code execution capabilities), and allowing logging in as root over Telnet (without a password), it also tries to fetch software updates over plain HTTP. It's a bloody nightmare. On the plus side, it was possible to disable many of the smart features once I discovered the t…

Does anyone know of such hacking that someone has done and documented? I'd be interested in trying to telnet or connect to a Samsung TV that I have, or at least be able to sandbox it somehow.

Re: The Impending Doom of Expiring Root CAs and Legacy Clients

#183
post #50

Earlier quoted context omitted.

> ... I wanted a 4K monitor. To all the folks reading at home... I would remind everyone that a TV is not a monitor. I got a relatively inexpensive LG 43in TV to use as a desktop monitor. I've had issues. Beyond the usual "make sure your graphics card actually supports 4K" and such, you also need to take some time to dig through the TV settings when you are using it on a PC. In particular, you definitely want to turn…

Why not just get a 43" monitor instead of trying to misuse a TV as a monitor?

Because the 43" TV is $200 while an equivalent computer display is double or triple that.

Re: The Impending Doom of Expiring Root CAs and Legacy Clients

#184

Earlier quoted context omitted.

Interesting note about Firefox there. I've certainly expirenced the missing "missing intermediate cert" problem before. It is a bit of a nightmare to debug. 1. Had issue, raise support ticket: TLS not working 2. Ticket closed as can't reproduce 3. Try myself again locally, also can't reproduce. Hmpf! 4. 2 months goes by.. 5. Experience same issue. Debug more carefully locally, use openssl go get proof of missing inte…

You can often engage people, especially technical people who enjoy things being gameified - by showing them that Qualys gives them a lousy score for what they've done. https://www.ssllabs.com/ssltest/ Also this lets you out-source the decisions about what's important versus what really doesn't matter to somebody else, and unless you've got (or can hire someone who has got) hours per week to read and digest work in th…

ssllabs is great and only works for publicly accessibly websites.

The challenge in my experience is to resolve the issue for internal sites, the thousands of internal tools and test domains from every department. None of the public tools can reach them.

Re: The Impending Doom of Expiring Root CAs and Legacy Clients

#185

Certificates suck. They are monumentally user unfriendly and complex. How many major internet properties have had outages driven by certificate renewal in the last several years? Half? I know that enterprises I work with seem to have some sort of work impacting certificate problem every month. The ecosystem needs to become a lot more robust and user friendly in general. Unfortunately, I’m just a user of certificates…

While I empathise with your viewpoint, that the ecosystem is hard to work with, I'm afraid I don't think there are any quick solutions to this. > certificate warning date If this is user-visible then for most companies this would be nearly as bad as expiry, and if it's not user visible then it's not useful. > Make it easier for people to acquire and renew certs Let's Encrypt pretty much solves this problem. The place…

Certificates don't have to be difficult. The major CDN and hosting providers can setup TLS automatically with no user action. CloudFlare rolled great command line tools to handle internal certificates and CA (see cfssl).

I've worked at startups with fully functional PKI. It's almost trivial to achieve, as long as you've got configuration management over all the servers (ansible, salt and assimilated).

On the other hand. I've worked at a large bank trying to make TLS work across the firm and it was a mess. There was no motivation to have any automation around certificates management and no control over server configurations. One simple issue for example, CA on linux are managed by the ca-certificates package, all it takes to keep TLS working is to upgrade that package every couple years "apt-get upgrade ca-certificates". Some servers haven't had upgrade since 2015. It wasn't particularly difficult to get 10k servers from 5 departments upgraded after handing them instructions to do so, but of course a few other departments won't act until things break (and sometimes still won't act in spite of active incidents).

Re: The Impending Doom of Expiring Root CAs and Legacy Clients

#186

Earlier quoted context omitted.

You can often engage people, especially technical people who enjoy things being gameified - by showing them that Qualys gives them a lousy score for what they've done. https://www.ssllabs.com/ssltest/ Also this lets you out-source the decisions about what's important versus what really doesn't matter to somebody else, and unless you've got (or can hire someone who has got) hours per week to read and digest work in th…

ssllabs is great and only works for publicly accessibly websites. The challenge in my experience is to resolve the issue for internal sites, the thousands of internal tools and test domains from every department. None of the public tools can reach them.

If you like ssllabs, you will love https://www.hardenize.com

Much more intel, better performance and a better UI.

No affiliation, just a fan since day one.

Re: The Impending Doom of Expiring Root CAs and Legacy Clients

#187
post #178

Earlier quoted context omitted.

Specifically for TVs, you can get a new display driver board for whatever panel is in there. Eats HDMI/DP, spits out eDP or VBO or whatever the panel format is. Often these are pretty basic, with a minimal OSD pasted in by the Shenzhen seller who configures the thing to your order. Personally I'm trying to get my hands on the SDK for the software that runs in the driver chip (does the OSD and the scaling and everythi…

Any pointers to forums/projects or sellers of these? Sounds like a bit of a rabbit hole, tbh :-)

I found this for the Realtek rtd2556 chip which there are plenty of boards for on ebay when you search for edp+hdmi+converter: https://github.com/ghent360/RTD-2660-Programmer

Re: The Impending Doom of Expiring Root CAs and Legacy Clients

#188

Earlier quoted context omitted.

Curious why multiple HDMI inputs matter, given a decent A/V receiver (a few hundred bucks) can handle it for you (along with waay better options for audio)?

AVRs are a huge hassle to deal with, and overkill when you only have 2 or 3 devices to switch between and/or don’t have many audio-only devices. AVRs made more sense during the days when we’d have CD players, tape decks, VCRs and DVD player, vinyl record players, cable/satellite STBs, and a game console or two all hooked up. Now it’s just an STB (if you aren’t a cord-cutter), a Roku/AppleTV/Chromecast/FireTV, and may…

It seems our experiences and priorities are quite different. I've never found any "hassle" in using an AVR for its intended, dedicated purpose: centrally managing various audio and video inputs and outputs and driving surround speakers & subwoofer. Inputs include Cable box/DVR, PS4, AppleTV, and (sometimes) Nintendo Switch. Audio out leverages our home theater surround system, and video out is a single HDMI into the tv. I have no interest in using any "smart" tv features, tv speakers, nor attempts at playing the role of a dedicated receiver. Unless you're a hardcore gamer measuring latency, IMHO use of an AVR is simply the right tool for the job. Nothing overkill about it. Put the "smarts" in a decent universal remote, keep the tv as dumb (literally; it's for video only) as possible, ensure everything sounds great, and never fiddle with the cables ones it's set up. YMMV, but this has served me very well for over 15 years.

Re: The Impending Doom of Expiring Root CAs and Legacy Clients

#189

Earlier quoted context omitted.

> you can get a new display driver board for whatever panel is in there. Eats HDMI/DP, spits out eDP or VBO or whatever the panel format is Do these boards support HDCP?

HDCP strippers are a thing now, so this shouldn’t be a concern.

For 4K? And are they legal?

Re: The Impending Doom of Expiring Root CAs and Legacy Clients

#190

Earlier quoted context omitted.

AVRs are a huge hassle to deal with, and overkill when you only have 2 or 3 devices to switch between and/or don’t have many audio-only devices. AVRs made more sense during the days when we’d have CD players, tape decks, VCRs and DVD player, vinyl record players, cable/satellite STBs, and a game console or two all hooked up. Now it’s just an STB (if you aren’t a cord-cutter), a Roku/AppleTV/Chromecast/FireTV, and may…

Without an AV Receiver, how would you drive a set of speakers?

[deleted]
Post reply on HN