Live data from Hacker News

F-Droid site certificate expired

gitlab.com

51–60 of 115 posts

Re: F-Droid site certificate expired

#51

Earlier quoted context omitted.

It is, if your objective is to closely centralize the web. If you make https mandatory, via scare tactics, only people with certificates will have websites. If you make ephemeral certificates mandatory by taking advantage of a monopoly, then only big SSL providers who can afford it will survive. Then, when you have only two or three big SSL providers, it's way easier to shut someone off by denying them a certificate,…

Meanwhile, in the real world: - We went from the vast majority of traffic being unencrypted, allowing any passive attacker (from nation state to script kiddie sitting in the coffee shop) to snoop and any active attacker to trivially tamper with it, to all but a vanishing minority of connections being strongly encrypted. The scare tactics used to sell VPNs in YouTube ads used to all be true, and no longer are, due to…

> - We went from the vast majority of traffic being unencrypted, allowing any passive attacker (from nation state to script kiddie sitting in the coffee shop) to snoop and any active attacker to trivially tamper with it, to all but a vanishing minority of connections being strongly encrypted.

I still don't understand why this is so terrible.

Public wifi networks were certainly a real problem, but that's not where the majority of internet usage happens, and they could have been fixed on a different layer.

If you're on a traditional home internet connection, who exactly can tamper with your traffic? Your ISP can, and that's not great, but it doesn't strike me as blaring siren levels of terrible, either. Even with HTTPS, the companies behind my OS and web browser can still see everything I do, so in exchange for all this work we've removed maybe 1 out of 3 parties from the equation. And, personally, I trust the OS and browser vendors less than I trust my ISP!

Some progress is better than none, and it's still nice that my ISP can't tamper with my connection any more. Unfortunate, TLS also took away my ability to inspect my own traffic! This makes it more difficult for me to monitor what my OS and browser vendor are doing, and as I've said previously, I trust these parties comparatively less than my ISP.

> - We went from TLS certificates being unaffordable to hobbyists to TLS certificates being not only free, but trivial to automatically obtain.

Sure, but it's also trivial to just throw up a website on Github Pages, or forgo the website completely and use Instagram. TLS is "trivial" if you rely the infrastructure of a specific external party.

Please help me understand what I'm missing because I find this really frustrating!

Re: F-Droid site certificate expired

#52

[flagged]

Being entirely based on FOSS is the #1 overarching priority of the entire F-Droid project and always has been. The person who blatantly didn't even bother to check the organization they're talking to, and offered up unsolicited spam for a pointless service... is the one engaging in snobbery.

Re: F-Droid site certificate expired

#53

[flagged]

I think for a service that hosts only FOSS mobile apps, it's a pretty reasonable goal to also try to host and monitor the service using only open source tools. They may not be able to be able to do that 100%, but it's fair to ask.

It's funny, because I had the opposite reaction: I found it a little bit distasteful that, while I'm sure the guy had a genuine desire to help, he's also using F-Droid's issue tracker as a means of advertising his product, as presumably there are other people who might see that issue report and have need for it, and become a paying customer.

(To be fair, this isn't brazen spam; the "ad" is targeted and offered in the spirit of help, and if they offer perpetual free usage for open source products, he's not trying to extract money from F-Droid. But still.)

> Why would you even both responding except to declare "I am better than thou?"

Maybe don't take the most uncharitable interpretation of something said by a random person on the internet who you don't know? Someone who at least has the bona-fide of volunteering their time to help keep a valuable open source project online? Perhaps the F-Droid project does actually have a stated policy of using open source hosting/monitoring tools, and he was genuinely asking in case he missed something, and would actually like to use that service if it is indeed open source.

I think it's pretty weird to assume good faith with the Oh Dear guy's advertisement, but assume the unpaid volunteer helping run F-Droid is a holier-than-thou prat. But hey, of course, capitalism and hustle are the most important things!

Re: F-Droid site certificate expired

#54

Earlier quoted context omitted.

Meanwhile, in the real world: - We went from the vast majority of traffic being unencrypted, allowing any passive attacker (from nation state to script kiddie sitting in the coffee shop) to snoop and any active attacker to trivially tamper with it, to all but a vanishing minority of connections being strongly encrypted. The scare tactics used to sell VPNs in YouTube ads used to all be true, and no longer are, due to…

> - We went from the vast majority of traffic being unencrypted, allowing any passive attacker (from nation state to script kiddie sitting in the coffee shop) to snoop and any active attacker to trivially tamper with it, to all but a vanishing minority of connections being strongly encrypted. I still don't understand why this is so terrible. Public wifi networks were certainly a real problem, but that's not where the…

> Some progress is better than none, and it's still nice that my ISP can't snoop on me any more. Unfortunate, TLS also took away my ability to inspect my own traffic! This makes it more difficult for me to monitor what my OS and browser vendor are doing, and as I've said previously, i trust these parties comparatively less than my ISP.

It might be more correct to say that Certificate Pinning made it so you can't inspect your own traffic - for sites with TLS but without certificate pinning, you can just as easily create your own root certificate and force the browser and OS to trust the cert by installing it at the OS level. This is (part of, atleast) how tools like Fiddler and Charles Proxy allow you to inspect HTTPS traffic, the other part being a mitm proxy that replaces the server's actual cert with one the mitm proxy generates [0]

[0]: https://www.charlesproxy.com/documentation/proxying/ssl-prox...

Re: F-Droid site certificate expired

#55

Earlier quoted context omitted.

It is, if your objective is to closely centralize the web. If you make https mandatory, via scare tactics, only people with certificates will have websites. If you make ephemeral certificates mandatory by taking advantage of a monopoly, then only big SSL providers who can afford it will survive. Then, when you have only two or three big SSL providers, it's way easier to shut someone off by denying them a certificate,…

Great explanation and very apt for out time when we regularly hear of people being banned/debanked/jailed for their political views in western countries.

The web PKI is certainly a potential point of failure in online communications, but fortunately there is almost no history of certificate revocation over content disputes. The biggest targets have been domain name registrars and CDNs.

Let's Encrypt has emphasized that it doesn't have the resources to investigate content disputes (currently, it's issuing nearly 10 million certificates per day, with no human intervention for any of them) and that having to adjudicate who's entitled to have a certificate by non-automated criteria would throw the model of free-of-charge certificates into doubt.

Meanwhile, encrypting web traffic makes it harder for governments to know who is reading or saying what. (Not always impossible, just harder.) Without it, we could have phenomena like keyword searches over Internet traffic in order to instantly determine who's searching for or otherwise reading or writing specific terms!

I'm very aware that it's still easy to observe who visits a particular site (based on SNI, as someone else mentioned in this thread). But there's a chicken-and-egg problem for protecting that information, and encrypting the actual site traffic is at least the chicken, while the egg may be coming with ECH.

Overall, transit encryption is very good for free expression online, and people who want to undermine or limit online speech are much more likely to be trying to undermine encryption than to promote it.

The biggest thing that Let's Encrypt in particular does to mitigate the risk of being unable to serve particular subscribers is to ensure that ACME is an open protocol that can be implemented by different CAs, and that it's very easy for subscribers to switch CAs at any time for any reason. The certificate system is more centralized than many people involved with it would prefer, but at least it's avoiding vendor lock-in.

Re: F-Droid site certificate expired

#56
post #3

Because those ephemeral LE certificates are such a great idea...

It is, if your objective is to closely centralize the web. If you make https mandatory, via scare tactics, only people with certificates will have websites. If you make ephemeral certificates mandatory by taking advantage of a monopoly, then only big SSL providers who can afford it will survive. Then, when you have only two or three big SSL providers, it's way easier to shut someone off by denying them a certificate,…

In caddy it takes more effort to NOT have https.

Re: F-Droid site certificate expired

#57

Earlier quoted context omitted.

> - We went from the vast majority of traffic being unencrypted, allowing any passive attacker (from nation state to script kiddie sitting in the coffee shop) to snoop and any active attacker to trivially tamper with it, to all but a vanishing minority of connections being strongly encrypted. I still don't understand why this is so terrible. Public wifi networks were certainly a real problem, but that's not where the…

> Some progress is better than none, and it's still nice that my ISP can't snoop on me any more. Unfortunate, TLS also took away my ability to inspect my own traffic! This makes it more difficult for me to monitor what my OS and browser vendor are doing, and as I've said previously, i trust these parties comparatively less than my ISP. It might be more correct to say that Certificate Pinning made it so you can't insp…

I've used mitm proxies, the problem is I don't know whether the software is behaving the same way under a proxy as it would normally.

Edit: To be clear, I'm not even suggesting the software would be doing this maliciously! Apps do all sorts of weird things when you try to proxy them, I know this because I do run most of my traffic through a proxy (for non-privacy reasons). Just for example, QUIC gets disabled.

Re: F-Droid site certificate expired

#58

Earlier quoted context omitted.

Meanwhile, in the real world: - We went from the vast majority of traffic being unencrypted, allowing any passive attacker (from nation state to script kiddie sitting in the coffee shop) to snoop and any active attacker to trivially tamper with it, to all but a vanishing minority of connections being strongly encrypted. The scare tactics used to sell VPNs in YouTube ads used to all be true, and no longer are, due to…

> - We went from the vast majority of traffic being unencrypted, allowing any passive attacker (from nation state to script kiddie sitting in the coffee shop) to snoop and any active attacker to trivially tamper with it, to all but a vanishing minority of connections being strongly encrypted. I still don't understand why this is so terrible. Public wifi networks were certainly a real problem, but that's not where the…

> I still don't understand why this is so terrible.

While I don't really have a scary threat model, I don't love the idea that my ISP could have been watching my traffic. Maybe there's a world where my government has ordered ISPs to log specifics about traffic in order to trap dissidents doing things they don't like. But sure, I live in the US, which isn't (yet) an authoritarian nightmare (yet!). But maybe I live in Texas, and I'm searching for information about getting an abortion (illegal to have one there in most cases). Maybe I'm a schoolteacher in Florida, and I'm searching information on critical race theory (a topic banned from instruction in Florida schools). I want that traffic to be private.

> Even with HTTPS, the companies behind my OS and web browser can still see everything I do, so in exchange for all this work we've removed maybe 1 out of 3 parties from the equation

I mean, that's on you for using a proprietary OS owned by a for-profit corporation. I get that desktop Linux or a de-Googled Android phone isn't for everyone, but those are options you have, if you're really worried.

And there are quite a few major browsers that are open source, so even if you can't inspect their traffic at runtime, if you really are truly serious about this, you can audit their source code and do your own builds. Yes, I would consider that unnecessarily paranoid, but the option is there for you, and you can even run these browsers on proprietary OSes. And honestly, I assume you use Chrome anyway; if that's the case then you clearly are not serious about this if you're using a web browser made by an advertising company. (If you're using something else: awesome, and apologies for the bad assumption.)

> Unfortunate, TLS also took away my ability to inspect my own traffic! This makes it more difficult for me to monitor what my OS and browser vendor are doing

You can still do this, but it does require more work setting up your own CA and installing it as trusted in your own devices, and them MitM'ing your traffic at the router in order to present a cert from your CA before forwarding the connection on to the real site.

Yes, this is out of reach for the average home internet user, but if you are the kind of person who is thinking about doing traffic monitoring on your home network, then you have the skills to do this. Meanwhile, the other 99% of us get better privacy online; I think that's a perfectly fine trade off.

> and as I've said previously, I trust [my OS and browser vendor] comparatively less than my ISP.

My ISP is Comcast; even if my OS and browser vendor was Microsoft or Apple, I think I'd probably still trust Comcast less. Fortunately my OS and browser vendors are not Microsoft or Apple, so I don't have to worry about that, but still.

> Sure, but it's also trivial to just throw up a website on Github Pages, or forgo the website completely and use Instagram. TLS is "trivial" if you rely the infrastructure of a specific external party.

Running a website, even from your home internet connection, still means relying on the infrastructure of a third party. There's no way to get away from that.

And you still can run one without TLS. Browsers will still display unencrypted pages, though I'll admit that I'd be unsurprised if some future versions of major browsers stopped allowing that, or made it look scary to your average user.

> Please help me understand what I'm missing because I find this really frustrating!

I think what you are missing is that people actually do value connection encryption, for real reasons, not paranoid, tin-foil-hat reasons. And while you do present some valid downsides, we believe those downsides are overblown, or at the very least worth it in the trade off. It's fine for you to not agree with that trade off, which is a shame, but... that's life.

Re: F-Droid site certificate expired

#59

Earlier quoted context omitted.

> Some progress is better than none, and it's still nice that my ISP can't snoop on me any more. Unfortunate, TLS also took away my ability to inspect my own traffic! This makes it more difficult for me to monitor what my OS and browser vendor are doing, and as I've said previously, i trust these parties comparatively less than my ISP. It might be more correct to say that Certificate Pinning made it so you can't insp…

I've used mitm proxies, the problem is I don't know whether the software is behaving the same way under a proxy as it would normally. Edit: To be clear, I'm not even suggesting the software would be doing this maliciously! Apps do all sorts of weird things when you try to proxy them, I know this because I do run most of my traffic through a proxy (for non-privacy reasons). Just for example, QUIC gets disabled.

If you're that worried about software being that devious, then you probably shouldn't be using that software at all, regardless of your ability to monitor its traffic.

Re: F-Droid site certificate expired

#60

Earlier quoted context omitted.

Meanwhile, in the real world: - We went from the vast majority of traffic being unencrypted, allowing any passive attacker (from nation state to script kiddie sitting in the coffee shop) to snoop and any active attacker to trivially tamper with it, to all but a vanishing minority of connections being strongly encrypted. The scare tactics used to sell VPNs in YouTube ads used to all be true, and no longer are, due to…

Meanwhile, in the real world: - We now provide a completely free certs for a malicious web-sites - Degraded encryption value so much it's not even indicated anymore (remember the green bar for EV?) - Pavlov-trained everyone to dumb-click through 'this page is not secure' warnings - SNI exists and even without it anything not on CDN is blocked very easily

> We now provide a completely free certs for a malicious web-sites

Malicious websites never had a problem buying certs before. Sure, the bar is lower now, but I don't think it was a particularly meaningful bar before. Besides, the most common ways to get malicious websites shut down are to get their webhost to cut them off, or get a court order to seize their domain name. Getting their TLS cert revoked isn't common, and doesn't really do the job anyway.

> Degraded encryption value so much it's not even indicated anymore (remember the green bar for EV?)

No, we've degraded the identity verification afforded by EV and those former browser features. Remember that the promise of SSL/TLS was two things: 1) your traffic is private, 2) it verifies that the server you thought you were contacting is actually the one you reached.

I think (2) was always going to be difficult: either you make it hard and expensive to acquire TLS certificates, and (2) has value, or you don't, and it doesn't. I think pervasive encryption is way more important than site owner identity validation. And I don't think the value of an EV cert was even all that high back when browsers called them out in their UI. There are lots of examples of people trivially managing to get an EV cert from somewhere, with their locally-registered "Stripe, LLC" or whatever in the "validated" company name field of their cert.

> Pavlov-trained everyone to dumb-click through 'this page is not secure' warnings

Not sure what that has to do with this. That was more of a problem back when we didn't have Let's Encrypt, so lots of people were using self-signed certs, or let their certs expire and didn't fix it, or whatever. These days I expect certificate warnings are fairly rare, and so users might actually start paying attention to them again.

> SNI exists and even without it anything not on CDN is blocked very easily

ESNI also exists, and while not being available everywhere, it'll get there. But this is a bizarre complaint, as it's entirely trivial to block traffic when there's no TLS at all.

Post reply on HN