Live data from Hacker News

F-Droid site certificate expired

gitlab.com

71–80 of 115 posts

Re: F-Droid site certificate expired

#71
post #64

Earlier quoted context omitted.

Meanwhile, in the real world: - We went from the vast majority of traffic being unencrypted, allowing any passive attacker (from nation state to script kiddie sitting in the coffee shop) to snoop and any active attacker to trivially tamper with it, to all but a vanishing minority of connections being strongly encrypted. The scare tactics used to sell VPNs in YouTube ads used to all be true, and no longer are, due to…

With centralised trust, encryption is meaningless.

Trust isn't that centralized. Thanks to Certificate Transparency, a CA cannot issue a certificate that will be accepted by Chrome or Firefox without the site owner being able to detect that.

Re: F-Droid site certificate expired

#72

[flagged]

Honestly, someone coming in unasked and trying to get you on the free plan of their own product, is kind of rude.

F-Droid is on a free tier of an open core, but not fully FOSS product. A product that is publicly listed on the stock exchange, at that!

They're throwing stones in a glass house.

It's not like their purity gets them anywhere. Google is kicking open software (already hidden and scare walled) off their platform soon and nobody will have F-Droid without permission from Google.

It's better to be pragmatic and focus on the battles that matter. Like the one against Google.

Re: F-Droid site certificate expired

#73
post #2

Licaon_Kter @licaon-kter 4 hours ago Maintainer Looks like while we have new certificates ( https://monitor.f-droid.org/services/tls-certs ) rotation failed. :( They acknowledge rotation failed but it is still failing [1]. Perhaps something to do with how certs are rotated on their CDN? [1] - https://www.ssllabs.com/ssltest/analyze.html?d=f%2ddroid.org...

Would not surprise me. Although it looks like F-Droid is hosted with Hetzner, I have encountered more than one failure to rotate certificates on account of Linode API changes, requiring manual update of the Python Linode API client to resolve.

Re: F-Droid site certificate expired

#74
post #72

Earlier quoted context omitted.

Honestly, someone coming in unasked and trying to get you on the free plan of their own product, is kind of rude.

F-Droid is on a free tier of an open core, but not fully FOSS product. A product that is publicly listed on the stock exchange, at that! They're throwing stones in a glass house. It's not like their purity gets them anywhere. Google is kicking open software (already hidden and scare walled) off their platform soon and nobody will have F-Droid without permission from Google. It's better to be pragmatic and focus on th…

Things are "scare walled" because things are scary. Just because something claims to be OSI-fucking-open-source doesn't mean anything.

It's better to be pragmatic. Agreed. The developer community needs to get its shit together if it wants to have carvouts compared to the other ~99.9999% of users.

Re: F-Droid site certificate expired

#75
post #63

Earlier quoted context omitted.

> - We went from the vast majority of traffic being unencrypted, allowing any passive attacker (from nation state to script kiddie sitting in the coffee shop) to snoop and any active attacker to trivially tamper with it, to all but a vanishing minority of connections being strongly encrypted. I still don't understand why this is so terrible. Public wifi networks were certainly a real problem, but that's not where the…

> If you're on a traditional home internet connection, who exactly can tamper with your traffic? Your ISP can, and that's not great, but it doesn't strike me as blaring siren levels of terrible, either. This characterization in on the same level of sophistication as "the Internet is just a series of pipes". Every transit station has the opportunity to read or even tamper with the bytes on an unencrypted http connecti…

Thanks for this, I legitimately didn't realize every interlink in the entire chain has the ability to tamper with a connection. I'm still very concerned about the centralization of https but I understand the need somewhat more.

Re: F-Droid site certificate expired

#76

Earlier quoted context omitted.

> - We went from the vast majority of traffic being unencrypted, allowing any passive attacker (from nation state to script kiddie sitting in the coffee shop) to snoop and any active attacker to trivially tamper with it, to all but a vanishing minority of connections being strongly encrypted. I still don't understand why this is so terrible. Public wifi networks were certainly a real problem, but that's not where the…

> Your ISP can And already has! ISPs used to inject ads into unencrypted connections: https://www.infoworld.com/article/2241797/code-injection-new...

I'm not defending the practice, but informing users they've reached a data cap is really not the same thing as injecting ads!

Re: F-Droid site certificate expired

#77

[flagged]

Being entirely based on FOSS is the #1 overarching priority of the entire F-Droid project and always has been. The person who blatantly didn't even bother to check the organization they're talking to, and offered up unsolicited spam for a pointless service... is the one engaging in snobbery.

I didn't know FDroid used entirely FOSS services. Strong disagree that when offering up something free to help with a problem that's clearly being had one must first do a deep dive on the org. This conversation could be as simple as "hey we like FDroid and would happily help support it by providing our service for free to make sure this doesn't happen again", "No thanks, we only use FOSS'.

Re: F-Droid site certificate expired

#78

Earlier quoted context omitted.

> Your ISP can And already has! ISPs used to inject ads into unencrypted connections: https://www.infoworld.com/article/2241797/code-injection-new...

I'm not defending the practice, but informing users they've reached a data cap is really not the same thing as injecting ads!

Alright what about telling you about other plans they offer. I'd consider that an ad: https://lukerodgers.ca/2023/12/09/optimum-isp-is-mitming-its...

Re: F-Droid site certificate expired

#79
post #74
post #72

Earlier quoted context omitted.

F-Droid is on a free tier of an open core, but not fully FOSS product. A product that is publicly listed on the stock exchange, at that! They're throwing stones in a glass house. It's not like their purity gets them anywhere. Google is kicking open software (already hidden and scare walled) off their platform soon and nobody will have F-Droid without permission from Google. It's better to be pragmatic and focus on th…

Things are "scare walled" because things are scary. Just because something claims to be OSI-fucking-open-source doesn't mean anything. It's better to be pragmatic. Agreed. The developer community needs to get its shit together if it wants to have carvouts compared to the other ~99.9999% of users.

> Things are "scare walled" because things are scary.

It's 100% about power.

Imagine if websites were scare walled. If Microsoft had owned the Internet, that might have happened. Websites can do "scary" things, after all.

You can buy guns and knives and drive 60 miles per hour. You can give your banking information away. So many things scare the user less than Google does. Not to mention you have to go five settings deep to untick a setting to even enable it.

Again, I reiterate: It's 100% about power.

We should stop being afraid, we should stop trying to "protect the children", and we should stand up for our rights.

Post reply on HN