Live data from Hacker News

Tell HN: Sci-Hub's TLS certificate has started failing

news.ycombinator.com

91–100 of 154 posts

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#91
post #89

Earlier quoted context omitted.

Yeah, understanding the internal combustion engine should not be a prerequisite for riding a bus.

Most people have at least a vague idea of how a combustion engine works, don't they?

Kids ride buses; I'm pretty sure they don't understand the marvels of engineering they're benefiting from.

My point is: it should be possible to use something without fully understanding the minutiae of how it works. We call this “user interface design”.

You should be allowed to live in a house without a full understanding of the architectural details that prevent it from falling down.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#92

COMODO has revoked their certificate, probably under a court order. You can temporarily work around this by disabling 'Query OCSP responder servers to confirm the current validity of certificates' under Privacy & Security in Firefox.

and not forgetting to enable back the OCSP queries once you have finished browsing Sci-Hub!

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#93
post #77

Earlier quoted context omitted.

There are plenty of reasons to pay for a certificate. Wildcard certificates only came out last month on LE, and people might still be weary to switch their primary site over so quickly. Additionally, there's still a few cases I can think of where a custom certificate might be needed. For instance, I recently consolidated my personal projects and site onto one server. I needed a single certificate that'd cover two dom…

Besides having a fancy name in the URL bar I can't think of any.

Using TLS on a server which doesn't have outbound/inbound access to the Internet/LetsEncrypt servers.

Sharing a (wildcard) certificate between multiple servers.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#94
post #77

Earlier quoted context omitted.

Besides having a fancy name in the URL bar I can't think of any.

Using TLS on a server which doesn't have outbound/inbound access to the Internet/LetsEncrypt servers. Sharing a (wildcard) certificate between multiple servers.

Thats a distribution problem. You don't need to be accessible from the outside internet to use a LE certificate. You can request a cert from another one, then copy it. (Either manually or automatically, that is up to you)

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#95
post #2

This is exactly what I said would happen when Google started making all of us use HTTPS.

You're not the only one. I hypothesised about this before in previous SciHub discussions, and SciHub isn't the only site that is/will be affected. Security is the ostensible benefit, and it's the one they advertise the most; easier censorship and centralised access control is the other---something which a lot of the pro-(traditional)-HTTPS advocates don't advertise. Make HTTPS mandatory (so no more HTTP), make it nea…

But then you have the other issue of your ISP having the ability to meddle with what it's sending you and silently injecting or removing content from the page. Really, I don't see a great solution either way.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#97
post #80

Earlier quoted context omitted.

...and then LE also revokes their certificate.

At this point you could go back to HTTP. And for LE: close down the company if that happens.

But then you have the issue of browsers marking your website as insecure, ISPs taking it upon themselves to enforce censorship, etc.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#98
post #80

Earlier quoted context omitted.

At this point you could go back to HTTP. And for LE: close down the company if that happens.

But then you have the issue of browsers marking your website as insecure, ISPs taking it upon themselves to enforce censorship, etc.

Yes. But at least as a company, you will still have your dignity. To not become a government pet.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#99

Earlier quoted context omitted.

This is really silly to me. Making computers accessible seems like a completely reasonable, sound priority. Yes, computer literacy is something we all need to work towards, but we'll never be in a world where the average person understands PKI, and saying that we should limit accessibility until they do is absurd.

but we'll never be in a world where the average person understands PKI 2000 years ago: "we'll never be in a world where the average person can read and write English"

I think my point stands even with a loose definition of 'never'.

Re: Tell HN: Sci-Hub's TLS certificate has started failing

#100
post #98

Earlier quoted context omitted.

But then you have the issue of browsers marking your website as insecure, ISPs taking it upon themselves to enforce censorship, etc.

Yes. But at least as a company, you will still have your dignity. To not become a government pet.

Really? A "government pet"?
Post reply on HN