Live data from Hacker News

Standing on our own two feet

letsencrypt.org

191–200 of 200 posts

Re: Standing on our own two feet

#191
post #74

Earlier quoted context omitted.

But like they said in the article, those 33% of Android phones represent "1-5% of the traffic" of the "large integrators" websites that LE communicated with.

Well that's an easy choice, lose 1-5% of traffic or pay $100 for a certificate from a vendor whose root doesn't expire next year?

As long as this statement is true. They also dont's say who these big integrators are and the situation may be widely different between integrators and fields.

Re: Standing on our own two feet

#192
post #164

Earlier quoted context omitted.

Using a public CA is far better for security than a custom private one. It's a pain having to install the certificate on every client, server, piece of software, etc. and in my experience this inevitably leads to people disabling certificate checking as part of troubleshooting and this being left on. Also, sometimes people need to access documents and emails from home computers and the company may use some devices on…

So exposing your internal infrastructure to the whole world and risking a 3rd party (CA) turning the keys (literally) to your kingdom to someone else is better than someone making a mistake that’s very easy to discover and correct? > Also, sometimes people need to access documents and emails from home computers and the company may use some devices on which it isn't possible to install the CA That’s a plus as far most…

> So exposing your internal infrastructure to the whole world and risking a 3rd party (CA) turning the keys (literally) to your kingdom to someone else is better than someone making a mistake that’s very easy to discover and correct?

That's not how certificates work. The CA doesn't have your private key. They could theoretically sign a fake certificate with your hostname but that risk is still present if you use a private CA and is mitigated by certificate transparency

Re: Standing on our own two feet

#193
post #192

Earlier quoted context omitted.

So exposing your internal infrastructure to the whole world and risking a 3rd party (CA) turning the keys (literally) to your kingdom to someone else is better than someone making a mistake that’s very easy to discover and correct? > Also, sometimes people need to access documents and emails from home computers and the company may use some devices on which it isn't possible to install the CA That’s a plus as far most…

> So exposing your internal infrastructure to the whole world and risking a 3rd party (CA) turning the keys (literally) to your kingdom to someone else is better than someone making a mistake that’s very easy to discover and correct? That's not how certificates work. The CA doesn't have your private key. They could theoretically sign a fake certificate with your hostname but that risk is still present if you use a pr…

Yes, should’ve been more clear on that they sign a cert without your knowledge and hand to to someone performing mitm. How is that risk present when you roll your own PKI and validate against your private CA (or intermediate) only?

Regarding CT I’m not aware of any clients other than browsers actually enforcing that.

Re: Standing on our own two feet

#194
post #167

Earlier quoted context omitted.

The most impressive thing it that Let’s Encrypt are the ones who are trying to fix a problem that should be fixed by phone manufactures and telcos. I can see why, but I would also have like the phones to “break” so the owners would avoid those brands in the future, and pick one who care enough to push out update. Still, I can blame Let’s Encrypt, they just want to be the good guys, and the do it so beautifully and tr…

It probably wouldn't encourage many people to upgrade their phones, though. They would probably just see the website as broken and either click through the warning or abandon it completely

Nearly 60% of the web is using Let's Encrypt certs now. It's not just the one of two sites are going to break, it's going to be half the web.

Re: Standing on our own two feet

#195

Earlier quoted context omitted.

In firefox (at least in desktop version) you can disable javascript and css. Not sure if they are still downloaded.

For scripts: if script is disabled for a document, scripts are not downloaded. See https://searchfox.org/mozilla-central/rev/a5d9abfda1e26b1207... as of today For stylesheets, I'm not certain how you're disabling them. Depending on how you do it, they may or may not get downloaded. The most common ways of disabling them result in them not being downloaded.

View - Page style - No style

Re: Standing on our own two feet

#196

Earlier quoted context omitted.

For scripts: if script is disabled for a document, scripts are not downloaded. See https://searchfox.org/mozilla-central/rev/a5d9abfda1e26b1207... as of today For stylesheets, I'm not certain how you're disabling them. Depending on how you do it, they may or may not get downloaded. The most common ways of disabling them result in them not being downloaded.

View - Page style - No style

That one does not prevent downloading; just prevents application.

Re: Standing on our own two feet

#197
post #186
post #159

Earlier quoted context omitted.

But that model is flawed, and it's been more than a decade to learn that. The interesting thing is: We already have a model that works much better, and it's been around for longer. If you buy a computer with Windows it is completely normal that you still get your updates from Microsoft, even if your computer is built by a company that may no longer exist by the time you install the update. (That's not to say Windows…

Users of the Android OS are not Google's customers.

I'd wager that's untrue. Anyone who buys an app, or in app purchase, is directly a Google customer.

I'd also argue that even if someone uses Play Store services, but doesn't pay a penny, they're still a "customer" in a looser sense of the word. They're engaging in the market-place, likely using free apps subsidized by advertising. Even if you want to argue that they're the product instead of the client (and I'd be inclined to agree), they're still revenue-generating users.

Re: Standing on our own two feet

#198
post #192

Earlier quoted context omitted.

> So exposing your internal infrastructure to the whole world and risking a 3rd party (CA) turning the keys (literally) to your kingdom to someone else is better than someone making a mistake that’s very easy to discover and correct? That's not how certificates work. The CA doesn't have your private key. They could theoretically sign a fake certificate with your hostname but that risk is still present if you use a pr…

Yes, should’ve been more clear on that they sign a cert without your knowledge and hand to to someone performing mitm. How is that risk present when you roll your own PKI and validate against your private CA (or intermediate) only? Regarding CT I’m not aware of any clients other than browsers actually enforcing that.

Typically an internal CA adds to the certificate trust store rather than replacing it.

Re: Standing on our own two feet

#199

Earlier quoted context omitted.

Yes, should’ve been more clear on that they sign a cert without your knowledge and hand to to someone performing mitm. How is that risk present when you roll your own PKI and validate against your private CA (or intermediate) only? Regarding CT I’m not aware of any clients other than browsers actually enforcing that.

Typically an internal CA adds to the certificate trust store rather than replacing it.

Yes you are correct here (although I’ve seen both methods). At least 3rd party won’t easily know which hostnames to fake though

Re: Standing on our own two feet

#200
post #144

Earlier quoted context omitted.

Yes and Yes. And both are reasonable and not excluding. Google sells you a pocket computer with a locked down OS, not for your safety but to control the ability to run ads. If they cared about user security, they would provide updates, no matter how "slow" (their excuse) the device gets. If they didn't want full control to show ads (ads are downloaded by the GooglePlayServices, which is pretty much the kernel of all…

Google does provide updates. It's the device manufacturers and/or mobile operators who choose not to push them.

> Google does provide updates

That is a lie and you know it. Google updates the OS, but they are also directly responsible for many products they sold themselves with their brand. And those have as much updates as any other company, well maybe one or two more.

I happen to have two devices bought directly from google. One is stuck on android 2.3 and another on 4.0, both full of security holes, not updated because "it would be too slow" when in reality i can't even install replicant et al because google never worked with the component providers to offer compatible binary blobs for the hardware.

Yeah, android itself is opensource (mostly because it is built on top of GPLed linux code so they do not have an option) but 99% of what makes your phone run is a proprietary binary-only code provided by the likes of Qualcomm etc. And why phone manufacturers, google included, use the options with closed source binary blobs? To save $5 or so from the BOM cost in production.

Post reply on HN