Live data from Hacker News

F-Droid site certificate expired

gitlab.com

81–90 of 115 posts

Re: F-Droid site certificate expired

#81
post #70

Earlier quoted context omitted.

DANE is not a good idea. It makes DNS the CA. DNS doesn't have any stringent security requirements to its design or operation, as CAs do. It depends on a problematic protocol (that, among other things, limits the ability to deal with different operational and failure modes). And just because a nameserver provides a record, doesn't mean an authorized domain owner wanted that record to be an authorized secure transport…

No, it doesn't. It makes the registrar the CA. Which makes sense, they already authorize who owns which domain. They should absolutely do so cryptographically in some fashion. What's weird is that the major registrars never even tried to enter the PKI business. It would have made sense. It would even have hastened the adoption of much needed TLS extensions.

The registrar is not equivalent to a CA in DANE.

- A CA validates requests, signs CSRs, publishes cert revocation, issues certificates and trust anchors.

- A registrar in DANE merely passes a DS record you created to the TLD, along with the promise that this record was created by the domain zone owner. It's basically the validation step. Nothing to do with establishing or securing data, key/record management, etc; they're a glorified FTP tool.

I'm in favor of registrars getting more involved (since they are the authority on who controls a domain), but only with a completely different design. I have suggested many times that CAs establish an API to communicate directly with Registrars to perform the validation step, as this would eliminate 95% of attacks on Web PKI without introducing any downsides. So far my pleas have fallen on deaf ears. And since the oligopoly of browser vendors continue their attacks on system reliability (via ridiculous expiration times) without any real pushback, I don't see it changing.

Re: F-Droid site certificate expired

#82
post #72

Earlier quoted context omitted.

Honestly, someone coming in unasked and trying to get you on the free plan of their own product, is kind of rude.

F-Droid is on a free tier of an open core, but not fully FOSS product. A product that is publicly listed on the stock exchange, at that! They're throwing stones in a glass house. It's not like their purity gets them anywhere. Google is kicking open software (already hidden and scare walled) off their platform soon and nobody will have F-Droid without permission from Google. It's better to be pragmatic and focus on th…

F-Droid isn't throwing stones, that's someone entirely unaffiliated with the project. F-Droid's hosting and infrastructure makes use of many projects and products that are not FOSS.

Re: F-Droid site certificate expired

#83

Earlier quoted context omitted.

> Your ISP can And already has! ISPs used to inject ads into unencrypted connections: https://www.infoworld.com/article/2241797/code-injection-new...

I'm not defending the practice, but informing users they've reached a data cap is really not the same thing as injecting ads!

In my country's ISP, they outright force you to see an ad for 5s before you can open a webpage sometimes.

Re: F-Droid site certificate expired

#84

[flagged]

> The prat

Please don't use epithets like this on HN, regardless of whether they're in the discussion here. The first words in the “In Comments” section of the guidelines are “Be Kind”. Please take care to do that in all comments on HN.

https://news.ycombinator.com/newsguidelines.html

Re: F-Droid site certificate expired

#85
post #82
post #72

Earlier quoted context omitted.

F-Droid is on a free tier of an open core, but not fully FOSS product. A product that is publicly listed on the stock exchange, at that! They're throwing stones in a glass house. It's not like their purity gets them anywhere. Google is kicking open software (already hidden and scare walled) off their platform soon and nobody will have F-Droid without permission from Google. It's better to be pragmatic and focus on th…

F-Droid isn't throwing stones, that's someone entirely unaffiliated with the project. F-Droid's hosting and infrastructure makes use of many projects and products that are not FOSS.

Thank you for clarifying. I retract my prior statement in shame.

Whomever is saying this kind of stuff on behalf of a project they're unaffiliated with has some serious gall.

Re: F-Droid site certificate expired

#86
post #62

Earlier quoted context omitted.

> Paying money doesn't actually make people trustworthy. This is fundamentally a naive understanding of both security and certificates. Paying money absolutely makes people trustworthy because it's prohibitive to do it at scale. You might have one paid malicious certificate but you can have thousands of free ones. The one malicious domain gets banned, the thousands are whack-a-mole forever. Further, certificates used…

EV certs didn't actually afford the guarantees people hoped and expected. I could simply spend a few hundred dollars to register "Stripe, LLC" or "Microsoft, Inc." in my local jurisdiction, and then get an EV cert with that name on it. Browser vendors removed the extra UI around EV certs not because certs in general are easier to get, but because the identity "guarantee" afforded to EV certs was fairly easy to spoof.…

Again, this is an incredibly naive and uninformed take. Yes. You can spend hundreds of dollars to make one attempt at malicious activity, and yeah, that could also be fixed by tweaking EV requirements. (More than likely by putting a country flag on the EV banner.) One person as an example managing to get a problematic EV cert is not a sign of a broken system, it's a sign of a working system that only a few edge case examples exist.

Cybercriminals work at scale. The opinion you shared here is why Google, Microsoft, and Amazon are so easy to use for cybercrime. It's incredibly easy to hide bad behavior in cheap, disposable attempts on free accounts.

Cost virtually eliminates abuse. Bad actors are fronting effort and ideally small amounts of money to effectively bet on a high return. You make the cost to attempt high, it isn't worth it. Apart from some high profile blogs demonstrating the risk, EV certs have to my knowledge never been used maliciously, and hiding them from the browser bar just makes useful, high quality data about the trustworthiness of a site buried behind hidden menus.

Re: F-Droid site certificate expired

#87

Earlier quoted context omitted.

Meanwhile, in the real world: - We went from the vast majority of traffic being unencrypted, allowing any passive attacker (from nation state to script kiddie sitting in the coffee shop) to snoop and any active attacker to trivially tamper with it, to all but a vanishing minority of connections being strongly encrypted. The scare tactics used to sell VPNs in YouTube ads used to all be true, and no longer are, due to…

> - We went from the vast majority of traffic being unencrypted, allowing any passive attacker (from nation state to script kiddie sitting in the coffee shop) to snoop and any active attacker to trivially tamper with it, to all but a vanishing minority of connections being strongly encrypted. I still don't understand why this is so terrible. Public wifi networks were certainly a real problem, but that's not where the…

I mean I trust Linux and Firefox both being open source more than isp

Re: F-Droid site certificate expired

#88
post #65
post #58

Earlier quoted context omitted.

> I still don't understand why this is so terrible. While I don't really have a scary threat model, I don't love the idea that my ISP could have been watching my traffic. Maybe there's a world where my government has ordered ISPs to log specifics about traffic in order to trap dissidents doing things they don't like. But sure, I live in the US, which isn't (yet) an authoritarian nightmare (yet!). But maybe I live in…

Have you checked the list of root certificates your browser accepts as good? Do it and tell me you trust websites which have a green lock next to the url..

Yes, the trust model for TLS is broken and the handful of attempts made to fix it (Moxie's "Convergence" project from 2011[1], for instance) haven't born fruit.

However, in a security context "takes some effort" is far better than "takes no effort".

If CAA records (with DNSSEC) were used to reject certificates from the wrong issuer, we might even be able to get to "though very imperfect, takes a considerable amount of effort".

DANE is supposed to be the solution to this problem but it's absolutely awful to use and will lead to even more fragile infrastructure than we currently have with TLS certs (and also ultimately depends on DNSSEC). HPKP was the non-DNS solution but it was removed because it suffered from an even worse form of fragility that could lock out domains for years.

[1]: https://en.m.wikipedia.org/wiki/Convergence_(SSL)

Re: F-Droid site certificate expired

#89
post #2

Licaon_Kter @licaon-kter 4 hours ago Maintainer Looks like while we have new certificates ( https://monitor.f-droid.org/services/tls-certs ) rotation failed. :( They acknowledge rotation failed but it is still failing [1]. Perhaps something to do with how certs are rotated on their CDN? [1] - https://www.ssllabs.com/ssltest/analyze.html?d=f%2ddroid.org...

Would not surprise me. Although it looks like F-Droid is hosted with Hetzner, I have encountered more than one failure to rotate certificates on account of Linode API changes, requiring manual update of the Python Linode API client to resolve.

> API changes

This should be an oxymoron. We've forgotten the point of an API as a profession and it's downright shameful when something this important breaks needlessly. Would it have been that hard to just keep supporting whatever API calls were in existence as e.g. "v1" and put their new stuff in "v2"?

Re: F-Droid site certificate expired

#90
post #59

Earlier quoted context omitted.

I've used mitm proxies, the problem is I don't know whether the software is behaving the same way under a proxy as it would normally. Edit: To be clear, I'm not even suggesting the software would be doing this maliciously! Apps do all sorts of weird things when you try to proxy them, I know this because I do run most of my traffic through a proxy (for non-privacy reasons). Just for example, QUIC gets disabled.

If you're that worried about software being that devious, then you probably shouldn't be using that software at all, regardless of your ability to monitor its traffic.

this isn't solely about the aspect you're hinting at: plenty of smart appliances are effectively useless/inoperarive if not interacted with with their accompanying proprietary (shitty) smartphone app. Developing an alternative app requires reverse engineering; that's when you realize the current state of the art is obfuscating and encrypting each and every network layer even for gadgets as mundane as an RGB mood light.
Post reply on HN