Live data from Hacker News

Standing on our own two feet

letsencrypt.org

111–120 of 200 posts

Re: Standing on our own two feet

#111

i hate how google puts warnings on non-ssl sites. why doe a static page that has no forms need ssl? non-ssl worked fine for 20 years for webpages and google comes along and says noooo not good enough.

A lot of shared hosts support LetsEncrypt now. I actually installed them on mine and to my surprise I saw a massive reduction in spam attacks also.

Re: Standing on our own two feet

#112
post #5

Earlier quoted context omitted.

Workaround is Firefox Mobile (because it ships with its own root certs), but that's a significant burden to place on the user.

Also the post says that Firefox doesn't work on Androids older than 5.0 which according to the dashboard are still 5.9% of devices. For those older devices, the only option is to install the new root certificate. Anyways, there are billions of Android devices out there. 33% of those is a large number. You can't just tell all of them that they are wrong. If this happens, people will move away from Let's encrypt in mas…

I don’t think they have a choice. Reading between the lines, the CA who cross-signed their previous root doesn’t really want to continue doing so (or asked for a lot more money) because LE usage reached levels that are just too risky. I don’t blame them: a single bad actor found doing something particularly nefarious with a LE certificate might lose them the trust their business is literally built upon. I don’t see any other CA queueing up to help what is typically their commercial nemesis. And as they say, at some point they would have to do it anyway, might as well rip the plaster off.

Re: Standing on our own two feet

#114

Earlier quoted context omitted.

I have a 2010 Android smartphone and it's painfully slow to navigate the modern web, almost unbearable. Browsing news websites is simply not worth my time of waiting for the phone to download and process 22MB of JS, CSS, and graphics. Being on wifi makes no difference; it's the CPU choking to render all that cruft. So yeah, 5% of traffic makes sense.

In firefox (at least in desktop version) you can disable javascript and css. Not sure if they are still downloaded.

For scripts: if script is disabled for a document, scripts are not downloaded. See https://searchfox.org/mozilla-central/rev/a5d9abfda1e26b1207... as of today

For stylesheets, I'm not certain how you're disabling them. Depending on how you do it, they may or may not get downloaded. The most common ways of disabling them result in them not being downloaded.

Re: Standing on our own two feet

#115
post #99

i hate how google puts warnings on non-ssl sites. why doe a static page that has no forms need ssl? non-ssl worked fine for 20 years for webpages and google comes along and says noooo not good enough.

Story time! Couple years ago I worked in a company in Asia. My boss went to China for work and bought some network equipment for the office: routers, access points etc. We didn't really need them, it's just so cheap he wanted to see how well it works. After setting them up and got it to work, we continue to use our devices as usual. But when we visit a company internal tool/dashboard page that we built ourselves, an…

ISP injecting scripts into unencrypted pages are pretty common, but a router injecting ads to all unencrypted traffics is a new low.

Re: Standing on our own two feet

#116
post #31
post #14

Could Google possibly be able (before were discuss willingness) to push an update to root certificate via Play Services? I'd like to think that anyone not using Play Services (i.e. Android with no Play) is likely using a custom browser, and would heed a call to switch to Firefox. The problem with some devices in Africa would be that many people will using older phone often don't have enough data for the big Play upda…

How much does that much data typically cost??

Here are some South Africa prices: https://www.mtn.co.za/recharge/data

Valid for a day: 25MB for $0.32; Valid for a week: 50MB for $0.64; Valid for a month: 100MB for $1.28, 1GB for $6.35

Re: Standing on our own two feet

#119
post #113

What about iOS? No word about it in this article.

According to apple [1] ISRG Root X1 is available all the way down to iOS 10. So that would be every iPhone since the 5.

As far as marketshare goes iOS 13 and 12 make up 94% of devices [2]. So I am guessing its an insignificant amount of actual users.

[1] https://support.apple.com/en-us/HT204132

[2] https://developer.apple.com/support/app-store/

Re: Standing on our own two feet

#120

Somewhat related, but in other thread two weeks ago people complain Google has too much power over Android ecosystem: https://news.ycombinator.com/item?id=24917918 Now, here people are suggesting Google should somehow update the old Androids. Be damned one way or the other.

Yes and Yes.

And both are reasonable and not excluding.

Google sells you a pocket computer with a locked down OS, not for your safety but to control the ability to run ads.

If they cared about user security, they would provide updates, no matter how "slow" (their excuse) the device gets.

If they didn't want full control to show ads (ads are downloaded by the GooglePlayServices, which is pretty much the kernel of all your android experience) then it would be trivial to install other android distributions like replicant.

hence, both a reasonable and google is evil. They want full control and do not care about (your) security updates.

Post reply on HN