Earlier quoted context omitted.
Basically ZeroSSL and Buypass, yes. Buypass certificates have the additional benefit of being valid for 180 days. The rate limits are a bit stricter than with Let's Encrypt, I believe: https://www.buypass.com/ssl/resources/go-ssl-technical-speci...
I assume they are more trusted by older devices than Let's Encrypt. Source?
Let’s Encrypt DST Root CA X3 Expiration – September 2021
41–50 of 72 posts
Re: Let’s Encrypt DST Root CA X3 Expiration – September 2021
#42Earlier quoted context omitted.
It seems quite silly to me to enforce a massive MitM attack while at the same time sticking to the FIPS standards. Then again, a lot of governmental and financial security requirements are nonsensical to me, like mandatory password changes. When I, as a website host, need to choose between accepting millions of Android devices or a few organizations with an esoteric security configuration, I'll go for the Android dev…
Some of it is misguided, some of it is legacy, other parts _do_ make sense to the people involved. Mandatory password changes for example have not been recommended[0] by NCSC in the UK since ~2018. Continuing to do so is either legacy or misguided. As for "MitM" it's usually due to regulatory requirements to protect and inspect at boundaries to and from an organisations network. FIPS and OpenSSL is an interesting sub…
High complexity / weird rules too - and not one password across systems as they have endless DIFERRENT login systems.
So your tax software itself will require 90 day resets for all staff using that, every interface to IRS requiring it (which means every login for little used systems). It's bonkers. My worry - how do they even correlate / track login risk given all these different systems. Google (which has never required a password rotation) seems to be able to really figure out when risk is higher (new device from a new location) and lower (same device from 5 minutes ago). That makes turning on 2 factor with a hardware device MUCH easier - because it doesn't annoy you unnecessarily.
Re: Let’s Encrypt DST Root CA X3 Expiration – September 2021
#43Earlier quoted context omitted.
To a point. The environmental footprint of a 486 tower system today would be much higher than modern system because the humans that use it more slowly and who have to maintain it use a lot more resources.
I don't understand. The human wouldn't cease to exist regardless of how fast or slow their computer is, right?
Re: Let’s Encrypt DST Root CA X3 Expiration – September 2021
#44Earlier quoted context omitted.
I assume they are more trusted by older devices than Let's Encrypt. Source?
Is there a range of trust? AFAIK you either trust a cert (directly or transitively) or not.
Re: Let’s Encrypt DST Root CA X3 Expiration – September 2021
#45Earlier quoted context omitted.
I assume they are more trusted by older devices than Let's Encrypt. Source?
Is there a range of trust? AFAIK you either trust a cert (directly or transitively) or not.
Re: Let’s Encrypt DST Root CA X3 Expiration – September 2021
#46Earlier quoted context omitted.
I don't understand. The human wouldn't cease to exist regardless of how fast or slow their computer is, right?
It’s easier if you imagine an office full of people. If you have slower systems, you have to hire more people to do the same amount of work.
I'm also not very convinced on the premise. Unless you're doing something fairly specialized (scientific modeling, compiling) or your software is unduly bloated (which a lot of software is, but that is its own problem), the difference in speed really shouldn't add up to that much.
Re: Let’s Encrypt DST Root CA X3 Expiration – September 2021
#47"In OpenSSL 1.0.x, a quirk in certificate verification means that even clients that trust ISRG Root X1 will fail" All current FIPS accredited devices use openssl 1.0.X, so the lets encrypt cross-signing hack will essentially break multiple corporate networks until the next openssl fips module is released at the end of this year. And could take another 6 months to make it into live systems
Re: Let’s Encrypt DST Root CA X3 Expiration – September 2021
#48I wish Let's Encrypt had a plan to get cross-signed by a CA those older devices still trust.
Which devices ? They did find a solution for most Android devices, and it is now the default chain provided via ACME.
Re: Let’s Encrypt DST Root CA X3 Expiration – September 2021
#49Earlier quoted context omitted.
Some of it is misguided, some of it is legacy, other parts _do_ make sense to the people involved. Mandatory password changes for example have not been recommended[0] by NCSC in the UK since ~2018. Continuing to do so is either legacy or misguided. As for "MitM" it's usually due to regulatory requirements to protect and inspect at boundaries to and from an organisations network. FIPS and OpenSSL is an interesting sub…
Mandatory 90 day password changes are still required by the IRS in the US at least. High complexity / weird rules too - and not one password across systems as they have endless DIFERRENT login systems. So your tax software itself will require 90 day resets for all staff using that, every interface to IRS requiring it (which means every login for little used systems). It's bonkers. My worry - how do they even correlat…
Re: Let’s Encrypt DST Root CA X3 Expiration – September 2021
#50Earlier quoted context omitted.
Which devices ? They did find a solution for most Android devices, and it is now the default chain provided via ACME.
How about macOS for example? After September, Let’s Encrypt will become untrusted on all versions prior to 10.12.