Live data from Hacker News

Let’s Encrypt comes up with workaround for abandonware Android devices

arstechnica.com

41–50 of 132 posts

Re: Let’s Encrypt comes up with workaround for abandonware Android devices

#41
post #35

Earlier quoted context omitted.

I just always assumed it was like the rest of SSL: It’s well-documented NSA saboteurs infiltrated the standards board. They forced through a bunch of bad proposals with the intention of making it overly complicated. The idea was to encourage misconfiguration and implementation bugs.

Where did you read this?

He’s referring to the leaks about NSA putting back doors into algorithms that Snowden leaked. Those algorithms were suspect from the beginning and avoided. It’s possible ones have gone undetected but that’s pure speculation without any kind of proof at this time. It’s also wholly irrelevant to this discussion and just pure FUD. Certificate expiration is needed to make certificate revocation perform well. Otherwise you need to keep the list of all certificates ever revoked whereas with expiration you can ignore checking expired certificates and more importantly revocation lists you download can prune certs that are otherwise expired anyway.

If anything, now that everything is connected to the internet you want shorter revocations (like days, weeks or months). That way the potential for abuse is shorter and the path for renewal is better trodden by organizations (ie less likely to forget about an expiring cert).

[1] https://www.theverge.com/2013/12/20/5231006/nsa-paid-10-mill...

[2] https://en.m.wikipedia.org/wiki/RSA_BSAFE

[3] https://en.m.wikipedia.org/wiki/Bullrun_(decryption_program)

Re: Let’s Encrypt comes up with workaround for abandonware Android devices

#42
post #3

I have always wondered a bit what is the purpose of expiration dates. For certificates or GPG keys alike. Once they expire it often enough creates some problems. Either because renewal has just been forgotten or because there are some technical issues, like in the Let's Encrypt / Android case. If you have a security incident you can't wait for the expiration date anyway, you need to revoke. And hopefully users have a…

You can remove expired certificates from the list of revoked certificates. Without expiration time that list could grow limitless making it impractical.

I know the concept is offensive to us who love optimization and efficiency, but would it actually be impractical, though? A root certificate is a couple of kilobytes. How much space would you need to store every single certificate in history for the next hundred years?

Re: Let’s Encrypt comes up with workaround for abandonware Android devices

#43
post #4

What about iOS? Which is the oldest version that has the Let's Encrypt certificate?

That should be iOS 10: https://support.apple.com/en-us/HT207177 (iPhone 5 supported, but no 4s).

See also: https://support.apple.com/en-us/HT209143

Re: Let’s Encrypt comes up with workaround for abandonware Android devices

#44
post #27

> Android, the world's only major consumer operating system that can't be centrally updated by its creator. The only one out of... two?

I, too, found that an interesting phrase. The way I see it, there are three major consumer operating systems; four if you think iOS and OSX should be considered separately. Out of those three/four, only one tries to keep devices working and up to date as long as possible... iOS/OSX allows central updating, but drops phones older than 5 years, and desktop/laptops from 5-7 years depending on the product series; users c…

> but Google cannot force OEMs to continue supporting a phone within a reasonable timeframe

Couldn't Google could pressure them to do it, by making this a legal requirement for a Google Play license for their devices?

Re: Let’s Encrypt comes up with workaround for abandonware Android devices

#45

Earlier quoted context omitted.

Windows, macOS, iOS, plus various flavours of Linux if you want to count them.

They can be updated by the creator, the updates don't have to be ran but they can say there is an update. With Android last I heard you had to wait for your manufactor to create the update, then for your telecoms provider to create an update and then you can see there is an update.

Yes, that's the article's point. Android is the outlier here.

Re: Let’s Encrypt comes up with workaround for abandonware Android devices

#46
post #6

Earlier quoted context omitted.

I had a co-worker who was pushing for certs that were only valid for a day, or for hours or even minutes. It would solve the whole problem of revocation.

You have to draw the line somewhere. Daily certs would probably increase the load for CAs by a lot. Also, energy consumption for certificate management would increase.

How compute intensive is a CA, anyway? I’d think that a few Raspberry Pi-ish devices would be enough to do it for an entire enterprise (or maybe even one, but fault tolerance).

Re: Let’s Encrypt comes up with workaround for abandonware Android devices

#47
"The new cross-sign will expire in early 2024, and hopefully versions of Android from 2016 and earlier will be dead by then."

Hard disagree. In this day and age, a device or OS that is merely 8 years old should be able to function! Is the issue limited to Lets Encrypt? If so its usage should be discouraged.

Re: Let’s Encrypt comes up with workaround for abandonware Android devices

#48

>Today, your example eight-years-obsolete install base of Android starts with version 4.2, which occupies 0.8 percent of the market. Instead of hoping that the 0.8% will shrink over the next 4 years, Let's Encrypt should understand that the 0.8% are the sane, reasonable people who realize that their Android devices still work fine for their intended purpose and do not have to be mindlessly upgraded because of mass-me…

The main problem with old devices is the battery. I don't like changing my phone too much, so I use it until the battery only is good for a 10 minute call or a day without calls, or one of my kids drop the phone and it gets broken. So I change it probably every three years, and sometimes my wife use the new phone and I use her old phone. (She use the phone more than me.) One possibility is that the manufactures add m…

To a large extent this is mitigated by having removable batteries. From what I've heard the Nexus 10 perhaps is a notable exception where the available alternate batteries aren't very good; mine needs a new battery but I don't really use it enough to justify one plus it's a somewhat more involved process than just popping it out.

I'm still using a Note 3 from 2013, it's on its third battery (though the second probably could have been fine another year or more). I also recently upgraded it to Android 10 (LineageOS) -- the last supported Android OS was 5. It's a small pain to backup and restore, it's nicer to have a simple OS upgrade that preserves apps/data, but it's a viable option for many old devices. It's enough choice for me to decide between trying to limp along with outdated software (many random app crashes went away after upgrading), upgrading the OS yourself, and buying a new device.

Re: Let’s Encrypt comes up with workaround for abandonware Android devices

#49
post #47

"The new cross-sign will expire in early 2024, and hopefully versions of Android from 2016 and earlier will be dead by then." Hard disagree. In this day and age, a device or OS that is merely 8 years old should be able to function! Is the issue limited to Lets Encrypt? If so its usage should be discouraged.

Just FYI, the issue is with certificates in general, nothing to do with LE specifically.

Dumbed down, the problem is that someone the old device never heard of, is not trustworthy.

Of course, an OS should still work after 8 years. But the problem is, that the OS has been abandoned (by the device manufacturer and possibly the community), so it is falling apart. Anything that accesses the internet needs regular maintenance to not become a security hazard.

Re: Let’s Encrypt comes up with workaround for abandonware Android devices

#50

>Today, your example eight-years-obsolete install base of Android starts with version 4.2, which occupies 0.8 percent of the market. Instead of hoping that the 0.8% will shrink over the next 4 years, Let's Encrypt should understand that the 0.8% are the sane, reasonable people who realize that their Android devices still work fine for their intended purpose and do not have to be mindlessly upgraded because of mass-me…

> Instead of hoping that the 0.8% will shrink over the next 4 years, Let's Encrypt should understand that the 0.8% are the sane, reasonable people who realize that their Android devices still work fine for their intended purpose and do not have to be mindlessly upgraded because of mass-media pressure.

It may also be just people who don't want to throw their "smart" fridge out after only 4 years...IoT obsolescence will make this worse in the coming years.

Post reply on HN