Live data from Hacker News

Standing on our own two feet

letsencrypt.org

31–40 of 200 posts

Re: Standing on our own two feet

#31
post #14

Could Google possibly be able (before were discuss willingness) to push an update to root certificate via Play Services? I'd like to think that anyone not using Play Services (i.e. Android with no Play) is likely using a custom browser, and would heed a call to switch to Firefox. The problem with some devices in Africa would be that many people will using older phone often don't have enough data for the big Play upda…

How much does that much data typically cost??

Re: Standing on our own two feet

#32
post #14

Could Google possibly be able (before were discuss willingness) to push an update to root certificate via Play Services? I'd like to think that anyone not using Play Services (i.e. Android with no Play) is likely using a custom browser, and would heed a call to switch to Firefox. The problem with some devices in Africa would be that many people will using older phone often don't have enough data for the big Play upda…

Actually I was surprised that there would be such an easy fix : Switching to Firefox. Which is apparently around 70MB, apparently affordable from what you wrote and definitely worth it if it allows you to unlock a chunk of the internet. So no need for an improbable and costly Play update.

Re: Standing on our own two feet

#33
post #5

Earlier quoted context omitted.

Workaround is Firefox Mobile (because it ships with its own root certs), but that's a significant burden to place on the user.

Also the post says that Firefox doesn't work on Androids older than 5.0 which according to the dashboard are still 5.9% of devices. For those older devices, the only option is to install the new root certificate. Anyways, there are billions of Android devices out there. 33% of those is a large number. You can't just tell all of them that they are wrong. If this happens, people will move away from Let's encrypt in mas…

How many other root certificates are going to be expiring in the next 3 years that older Android won't have updates for as well? Probably more than 1.

Re: Standing on our own two feet

#34
post #14

Could Google possibly be able (before were discuss willingness) to push an update to root certificate via Play Services? I'd like to think that anyone not using Play Services (i.e. Android with no Play) is likely using a custom browser, and would heed a call to switch to Firefox. The problem with some devices in Africa would be that many people will using older phone often don't have enough data for the big Play upda…

Actually I was surprised that there would be such an easy fix : Switching to Firefox. Which is apparently around 70MB, apparently affordable from what you wrote and definitely worth it if it allows you to unlock a chunk of the internet. So no need for an improbable and costly Play update.

That won't fix any other apps though will it? Anything that uses chrome webview for example.

Re: Standing on our own two feet

#35
I don't understand the motivation for making this change now. Why not keep the universally accepted root certificate as the default chain? Why does Let's Encrypt need to switch to their own root certificate now, and cause thousands of websites to break on older devices?

I don't even control the certificate provisioning process. We use Heroku and Webflow. This is frustrating.

Re: Standing on our own two feet

#36
post #14

Could Google possibly be able (before were discuss willingness) to push an update to root certificate via Play Services? I'd like to think that anyone not using Play Services (i.e. Android with no Play) is likely using a custom browser, and would heed a call to switch to Firefox. The problem with some devices in Africa would be that many people will using older phone often don't have enough data for the big Play upda…

Starting with Android 10, Google can push updates to lots of system components (media codecs, android frameworks, tzdata, …) https://android-developers.googleblog.com/2019/05/fresher-os...

But those on older versions are screwed. It's really a major fuck-up that Google didn't do this for root certs since the beginning of Android.

Re: Standing on our own two feet

#37
post #14

Could Google possibly be able (before were discuss willingness) to push an update to root certificate via Play Services? I'd like to think that anyone not using Play Services (i.e. Android with no Play) is likely using a custom browser, and would heed a call to switch to Firefox. The problem with some devices in Africa would be that many people will using older phone often don't have enough data for the big Play upda…

No play services on an Android phone in the US probably implies willingness to tinker. No play services on an Android phone in China only implies it's an Android phone. In the developing world, it most likely implies a very low cost Android phone of Chinese origin.

Bundling things that need timely updates with the OS with no mechanism to update them individually is a design error. Things like root certificates, time zone databases, leap second information, and even TLS libraries need to be updated on a regular basis. These items should be distributed outside of the general upgrade process, even if the general upgrade process worked (which is clearly not the case). Alternatively, root certs and TLS libraries could be bundled with applications as needed. You could probably have a stable core x.509 library and cipher algorithms bundled with the OS, so that the application level TLS library can be kept small. You still need to get tzdb updates out though.

In an ideal world, large OS vendors could work with carriers to get this small set of updates zero-rated in exchange for making sure they are very small and background downloaded only at times of low network congestion.

Re: Standing on our own two feet

#38

I don't understand the motivation for making this change now. Why not keep the universally accepted root certificate as the default chain? Why does Let's Encrypt need to switch to their own root certificate now, and cause thousands of websites to break on older devices? I don't even control the certificate provisioning process. We use Heroku and Webflow. This is frustrating.

"the DST Root X3 root certificate that we relied on to get us off the ground is going to expire - on September 1, 2021."

Re: Standing on our own two feet

#39

I don't understand the motivation for making this change now. Why not keep the universally accepted root certificate as the default chain? Why does Let's Encrypt need to switch to their own root certificate now, and cause thousands of websites to break on older devices? I don't even control the certificate provisioning process. We use Heroku and Webflow. This is frustrating.

Their cross cert expires in 10 months. Switching in January gives most people time to notice the problem while there's an easy temporary fix (switch to the soon to be expiring cross cert while you evaluate the root compatability of commercial CAs across the devices you support).

I imagine the cross cert cost a bunch of money, and they may not have the money to do that again.

Re: Standing on our own two feet

#40

> The remaining 33.8% of Android devices will eventually start getting certificate errors when users visit sites that have a Let’s Encrypt certificate. In our communications with large integrators, we have found that this represents around 1-5% of traffic to their sites. This one-third of Android devices only yields 5% of traffic? Interesting.

More interesting that % of traffic in this case would be unique users. But it's not surprising to me that people using Androids on older devices are using them to access the internet less; they're generally not as nice to use, but also if they were heavily used, they may have worn out by now.
Post reply on HN