I have always wondered a bit what is the purpose of expiration dates. For certificates or GPG keys alike. Once they expire it often enough creates some problems. Either because renewal has just been forgotten or because there are some technical issues, like in the Let's Encrypt / Android case. If you have a security incident you can't wait for the expiration date anyway, you need to revoke. And hopefully users have a…
I assume expiration protects against the case where a valid certificate is forgotten and a bad actor gets their hands on it and abuses it without the domain owner noticing. Similar to how some sites enforce session expiration.
Let’s Encrypt comes up with workaround for abandonware Android devices
11–20 of 132 posts
Re: Let’s Encrypt comes up with workaround for abandonware Android devices
#12I have always wondered a bit what is the purpose of expiration dates. For certificates or GPG keys alike. Once they expire it often enough creates some problems. Either because renewal has just been forgotten or because there are some technical issues, like in the Let's Encrypt / Android case. If you have a security incident you can't wait for the expiration date anyway, you need to revoke. And hopefully users have a…
I had a co-worker who was pushing for certs that were only valid for a day, or for hours or even minutes. It would solve the whole problem of revocation.
Re: Let’s Encrypt comes up with workaround for abandonware Android devices
#13Not sure why author writes using negative language about the fact that Android cannot be remotely updated? To me that sounds like an agenda to encourage the use of less privacy conscious operating systems. If the OS can be remotely updated, nothing stops bad actor from updating particular phone with a keylogger to bypass any end to end messenger a target is using and so on. Remote update is a great option if it is in…
Re: Let’s Encrypt comes up with workaround for abandonware Android devices
#14What about iOS? Which is the oldest version that has the Let's Encrypt certificate?
If it would make sense, I'm pretty sure Apple could update the first iPhone still. And that would cover every iPhone 1 in existence. Android with its fragmentation makes that pretty much impossible.
Re: Let’s Encrypt comes up with workaround for abandonware Android devices
#15I have always wondered a bit what is the purpose of expiration dates. For certificates or GPG keys alike. Once they expire it often enough creates some problems. Either because renewal has just been forgotten or because there are some technical issues, like in the Let's Encrypt / Android case. If you have a security incident you can't wait for the expiration date anyway, you need to revoke. And hopefully users have a…
I had a co-worker who was pushing for certs that were only valid for a day, or for hours or even minutes. It would solve the whole problem of revocation.
Re: Let’s Encrypt comes up with workaround for abandonware Android devices
#16I have always wondered a bit what is the purpose of expiration dates. For certificates or GPG keys alike. Once they expire it often enough creates some problems. Either because renewal has just been forgotten or because there are some technical issues, like in the Let's Encrypt / Android case. If you have a security incident you can't wait for the expiration date anyway, you need to revoke. And hopefully users have a…
Re: Let’s Encrypt comes up with workaround for abandonware Android devices
#17I have always wondered a bit what is the purpose of expiration dates. For certificates or GPG keys alike. Once they expire it often enough creates some problems. Either because renewal has just been forgotten or because there are some technical issues, like in the Let's Encrypt / Android case. If you have a security incident you can't wait for the expiration date anyway, you need to revoke. And hopefully users have a…
I had a co-worker who was pushing for certs that were only valid for a day, or for hours or even minutes. It would solve the whole problem of revocation.
Re: Let’s Encrypt comes up with workaround for abandonware Android devices
#18Earlier quoted context omitted.
I assume expiration protects against the case where a valid certificate is forgotten and a bad actor gets their hands on it and abuses it without the domain owner noticing. Similar to how some sites enforce session expiration.
That is beginning to appear to be a very corner case. But we didn't know that when the standards were being written.
Re: Let’s Encrypt comes up with workaround for abandonware Android devices
#19I have always wondered a bit what is the purpose of expiration dates. For certificates or GPG keys alike. Once they expire it often enough creates some problems. Either because renewal has just been forgotten or because there are some technical issues, like in the Let's Encrypt / Android case. If you have a security incident you can't wait for the expiration date anyway, you need to revoke. And hopefully users have a…
If you don't have an expiry then you'd need to keep certificate revocations around forever, so your CRL grows without bound. Currently the certificate revocation list can remove expired certificates as clients won't use them. There's also lots of clients that don't check CRLs. Those clients would be forever vulnerable to a stolen certificate if we removed expiry.
Imagine if you inherited the infrastructure for a company where the previous admin created certs, lost track of them, and used questionable methods for securing them. I believe you'd struggle to find and revoke every previously issued certificate. The expiry ensures that gets cleaned up, eventually.
I don't have a good solution to the Nokia Symbian problem. I suspect if the device only supports SHA-1 then there are other unpatched security issues. Does anyone know if that's the case? If so, this seems more like a support and patching issue.
Re: Let’s Encrypt comes up with workaround for abandonware Android devices
#20>Today, your example eight-years-obsolete install base of Android starts with version 4.2, which occupies 0.8 percent of the market. Instead of hoping that the 0.8% will shrink over the next 4 years, Let's Encrypt should understand that the 0.8% are the sane, reasonable people who realize that their Android devices still work fine for their intended purpose and do not have to be mindlessly upgraded because of mass-me…
Solving this problem for 1/3 of Android users is going to help reduce the problem of electrical waste; even if they wear out Let's Encrypt will not be they reason why.