Live data from Hacker News

Let’s Encrypt comes up with workaround for abandonware Android devices

arstechnica.com

1–10 of 132 posts

Re: Let’s Encrypt comes up with workaround for abandonware Android devices

#3
I have always wondered a bit what is the purpose of expiration dates. For certificates or GPG keys alike. Once they expire it often enough creates some problems. Either because renewal has just been forgotten or because there are some technical issues, like in the Let's Encrypt / Android case.

If you have a security incident you can't wait for the expiration date anyway, you need to revoke. And hopefully users have a mechanism to note the revocation in time.

So expiration dates help to avoid using weak algorithms forever. But does that need to be done on a fixed date per certificate? Wouldn't that be a more gradual approach in the libraries? And of course they are not updated they get less secure as time goes by. And sooner or later compatibility issues will do the job. E. g. most Nokia Symbian phones don't do https any more, because all they can handle is SHA-1 certificate signatures. That was a gradual decline in functionality.

Re: Let’s Encrypt comes up with workaround for abandonware Android devices

#5
post #3

I have always wondered a bit what is the purpose of expiration dates. For certificates or GPG keys alike. Once they expire it often enough creates some problems. Either because renewal has just been forgotten or because there are some technical issues, like in the Let's Encrypt / Android case. If you have a security incident you can't wait for the expiration date anyway, you need to revoke. And hopefully users have a…

Things are moving in the other direction. Browser vendors have forced certificates used for browsers to a max life of 398 days.

There are multiple reasons, but you seem focused on the certificate management side. One advantage of doing things more frequently is they are forced to become more routine or automated. So shorter expirations should actually make expiration failures less likely over time. Of course the transition sucks.

Re: Let’s Encrypt comes up with workaround for abandonware Android devices

#6
post #3

I have always wondered a bit what is the purpose of expiration dates. For certificates or GPG keys alike. Once they expire it often enough creates some problems. Either because renewal has just been forgotten or because there are some technical issues, like in the Let's Encrypt / Android case. If you have a security incident you can't wait for the expiration date anyway, you need to revoke. And hopefully users have a…

I had a co-worker who was pushing for certs that were only valid for a day, or for hours or even minutes. It would solve the whole problem of revocation.

Re: Let’s Encrypt comes up with workaround for abandonware Android devices

#7
post #3

I have always wondered a bit what is the purpose of expiration dates. For certificates or GPG keys alike. Once they expire it often enough creates some problems. Either because renewal has just been forgotten or because there are some technical issues, like in the Let's Encrypt / Android case. If you have a security incident you can't wait for the expiration date anyway, you need to revoke. And hopefully users have a…

In order to revoke a certificate, you first must at least suspect it has been compromised. An expiration date can help limit the impact of compromises you don't suspect.

Re: Let’s Encrypt comes up with workaround for abandonware Android devices

#8
>Today, your example eight-years-obsolete install base of Android starts with version 4.2, which occupies 0.8 percent of the market.

Instead of hoping that the 0.8% will shrink over the next 4 years, Let's Encrypt should understand that the 0.8% are the sane, reasonable people who realize that their Android devices still work fine for their intended purpose and do not have to be mindlessly upgraded because of mass-media pressure.

We should work instead to expand that 0.8% to avoid ripping out the heart of the planet for pointless capitalism.

This is one of the reasons why I objected to Let's Encrypt in the first place. Anyone who takes any measure to make older devices obsolete when they are still perfectly capable should be ashamed!

We are in the middle of a mass extinction; we have destroyed the oceans with plastic and runoff; we have created an environmental catastrophe. Mindless media-driven consumerism must stop.

Re: Let’s Encrypt comes up with workaround for abandonware Android devices

#9
post #3

I have always wondered a bit what is the purpose of expiration dates. For certificates or GPG keys alike. Once they expire it often enough creates some problems. Either because renewal has just been forgotten or because there are some technical issues, like in the Let's Encrypt / Android case. If you have a security incident you can't wait for the expiration date anyway, you need to revoke. And hopefully users have a…

I assume expiration protects against the case where a valid certificate is forgotten and a bad actor gets their hands on it and abuses it without the domain owner noticing. Similar to how some sites enforce session expiration.

Re: Let’s Encrypt comes up with workaround for abandonware Android devices

#10
Not sure why author writes using negative language about the fact that Android cannot be remotely updated? To me that sounds like an agenda to encourage the use of less privacy conscious operating systems. If the OS can be remotely updated, nothing stops bad actor from updating particular phone with a keylogger to bypass any end to end messenger a target is using and so on. Remote update is a great option if it is initiated from a trusted source.
Post reply on HN