Earlier quoted context omitted.
No play services on an Android phone in the US probably implies willingness to tinker. No play services on an Android phone in China only implies it's an Android phone. In the developing world, it most likely implies a very low cost Android phone of Chinese origin. Bundling things that need timely updates with the OS with no mechanism to update them individually is a design error. Things like root certificates, time…
In an ideal world carriers wouldn't have a say in what software updates were installed on my phone. Comcast doesn't control the software on the computers it services. Why should Telus control what updates are made available for my phone?
Standing on our own two feet
71–80 of 200 posts
Re: Standing on our own two feet
#72Let’s Encrypt cross-signature with IdenTrust "DST Root X3" is ending on September 1, 2021 but 33.8% of Android devices are running versions under 7.1 which don't trust Let’s Encrypt new root certificate "ISRG Root X1"
Workaround is Firefox Mobile (because it ships with its own root certs), but that's a significant burden to place on the user.
Re: Standing on our own two feet
#73Now, here people are suggesting Google should somehow update the old Androids.
Be damned one way or the other.
Re: Standing on our own two feet
#74now the corporates got a valid point, why you dont want to use lets encrypt? still the 33% of the devices is a quite a large number to consider.
But like they said in the article, those 33% of Android phones represent "1-5% of the traffic" of the "large integrators" websites that LE communicated with.
Re: Standing on our own two feet
#75Earlier quoted context omitted.
Also the post says that Firefox doesn't work on Androids older than 5.0 which according to the dashboard are still 5.9% of devices. For those older devices, the only option is to install the new root certificate. Anyways, there are billions of Android devices out there. 33% of those is a large number. You can't just tell all of them that they are wrong. If this happens, people will move away from Let's encrypt in mas…
Not sure about that. Move away from Let's Encrypt to what? More likely, most smaller to medium sized sites will say forget those old Android guys.
Re: Standing on our own two feet
#76i hate how google puts warnings on non-ssl sites. why doe a static page that has no forms need ssl? non-ssl worked fine for 20 years for webpages and google comes along and says noooo not good enough.
Re: Standing on our own two feet
#77Earlier quoted context omitted.
Workaround is Firefox Mobile (because it ships with its own root certs), but that's a significant burden to place on the user.
Also the post says that Firefox doesn't work on Androids older than 5.0 which according to the dashboard are still 5.9% of devices. For those older devices, the only option is to install the new root certificate. Anyways, there are billions of Android devices out there. 33% of those is a large number. You can't just tell all of them that they are wrong. If this happens, people will move away from Let's encrypt in mas…
Re: Standing on our own two feet
#78They propose to install Firefox to work around the root certificate problem on old android devices. But can’t you just manually install their root certificate on most phones?
Re: Standing on our own two feet
#79Earlier quoted context omitted.
But like they said in the article, those 33% of Android phones represent "1-5% of the traffic" of the "large integrators" websites that LE communicated with.
Well that's an easy choice, lose 1-5% of traffic or pay $100 for a certificate from a vendor whose root doesn't expire next year?
Re: Standing on our own two feet
#80Does anyone have experiences with ZeroSSL? Caddy has been building in support so I think it could be a drop-in replacement for Caddy/CertMagic/ACMEx users.
ACMEz* ;) Seconding regecks' comment. We're gradually making ZeroSSL a default CA for Caddy. (I am currently implementing multi-CA support into Caddy and CertMagic, so that Caddy will be able to use both Let's Encrypt and ZeroSSL for redundancy. It's the first server to support this!) This is a good thing for the ecosystem.
As in, replacing LE as the default, or supplementing it? (And if the former, why?)