Live data from Hacker News

What's the right UX for an expired certificate?

emilymstark.com

101–105 of 105 posts

Re: What's the right UX for an expired certificate?

#101
post #12

Earlier quoted context omitted.

I know you're being downvoted for the tone, but I agree entirely. Security is not something to sacrifice to gain less angry users. I do agree, however, with the sentiment that the UX surrounding security leaves a lot to be desired. In most cases we train users to ignore or work around security problems - we don't give them tools to solve and embrace them.

Here's the thing: Expired certificate warnings reduce security. Because they're excessively dramatic about a routine non-issue, people learn to ignore and bypass them. Now people won't head real certificate warnings. Unfortunately, the browser security nerds don't understand human psychology, and are more scared of the fact an expired cert can't be revoked (a nearly pointless edge case) versus users ignoring all cert…

We agree on this.

Re: What's the right UX for an expired certificate?

#102
post #100

Earlier quoted context omitted.

> Security is not something to sacrifice to gain less angry users. Of course it is - it depends on Capital-C-Context. Sure, for the bank, the site you are supplying your credit card details, your email, etc - security is non-negotiable. For hackernews, for reddit, and for similar sites, then security is something to sacrifice, once again depending on context. I've trusted this certificate for the last 2, maybe 3 year…

I literally just said that I agree the UX is poor. Did you read my comment?

> I literally just said that I agree the UX is poor. Did you read my comment?

But I agree with that comment. The one I disagreed with is:

> Security is not something to sacrifice to gain less angry users.

Maybe I should rephrase (I'm a notoriously poor communicator) ...

Sometimes (like in the cases I pointed out), the security messages and warnings must be sacrificed because the practical security either doesn't matter (like hackernews) or hasn't been compromised (like the 5m after midnight example).

Re: What's the right UX for an expired certificate?

#103
post #100

Earlier quoted context omitted.

I literally just said that I agree the UX is poor. Did you read my comment?

> I literally just said that I agree the UX is poor. Did you read my comment? But I agree with that comment. The one I disagreed with is: > Security is not something to sacrifice to gain less angry users. Maybe I should rephrase (I'm a notoriously poor communicator) ... Sometimes (like in the cases I pointed out), the security messages and warnings must be sacrificed because the practical security either doesn't matt…

Swallowing certificate expiration is not acceptable security, no. _Something_ needs to happen. What else is there than warning the user?

That being said, I've never liked how certificates are designed to begin with. They're overly complicated for very little gain IMO.

Re: What's the right UX for an expired certificate?

#104

Earlier quoted context omitted.

> I can send encrypted content over that insecure channel that only some receiver could decrypt and read. We've tried this approach with email and has not resulted in a world where I can easily send secure emails to anyone I know. Even setting aside the problem of inconsistent clients, you're asking for a world where every server re-invents wheels & you haven't even begun to think about solving for authentication (wh…

I'm simply saying that HTTP is perfectly fine and it's not legacy. Of course it's easier to pay for a certificate from a certification authority that maintains the infrastructure, and no, Letsencrypt is free only on the issue side, but maintaining HTTPS has its warts (for example: renew the certs every 3 months!) but the problem is not HTTP, HTTP in the hands of people who know what they are doing is completely okay,…

> it's baffling that we are pushing for internet non-public non-state-run identity authorities, while in UK, Japan, Russia, USA and many other countries such an authority don't even exist for real people...

This I'm fully onboard with. We absolutely need to be more active in moving away from this approach of centralised authorities - there's unfortunately no rreal candidates for this outside of the blockchain space. I think we're stuck in an awkward time where many "I need an alternative to centralised systems" innovators end up turning to blockchain, which inevitably leads to vapourware. Hopefully that tendency disappears soon.

Otherwise though, you seem to be avoiding the elephant in the room with HTTP.

> there's no problem if what they do doesn't need security

The fundamental problem is that users need security, and implementers are tasked with making this decision on behalf of users (users don't "choose" to use an unencrypted protocol on the web). Implementers have historically not been the best stewards of user needs. IOW: there are far too many cases of things that do need security where implementers don't believe it does.

Re: What's the right UX for an expired certificate?

#105

Earlier quoted context omitted.

> why the bank cannot buy a 10 year certificate it's a mystery to me, I sure hope they'll still be in business in 10 years time from now, at least they should be able to not think about this minutia so often. There's no more reason they should "think" about this than, say, testing fire extinguishers, it's just routine maintenance, it is presumably somebody's job to ensure all the routine maintenance gets done. If you…

> fire extinguishers fire extinguishers are for emergencies! if a fire extinguisher doesn't work, people can die if an HTTPS cert has expired, there is no risk involved, it can still be used only o. the domain it was issued for. Anyway in.my country you have to check them every 3 years and someone comes to you, you don't have to remember about it. > If the bank's new certificate today is valid for 10 year nothing pre…

> nothing prevents reissuing new certificates before expiration, if necessary.

So you want a product advertised with a 10 year lifespan, but sometimes it fails much earlier? I guess I have great news, you can use the existing product this way, although everybody you work with may find you exasperatingly incompetent.

Post reply on HN