Live data from Hacker News

What's the right UX for an expired certificate?

emilymstark.com

91–100 of 105 posts

Re: What's the right UX for an expired certificate?

#91

Earlier quoted context omitted.

> * My biggest issue with this whole situation, is that the user gets a better UX with no encryption whatsoever on a http:// site than a self-signed or expired cert on https://.\\ * I think that's a well-acknowledged issue but those who disagree on less-severe expiry warnings would simply argue here that it would be preferable to be strict in both cases and that the lax approach to http:// is just legacy baggage we s…

> http:// is just legacy baggage we should work toward getting rid of. I, the server, should decide what protocol to use, not the client i.e. some software provided by two of the largest World corporations, which are also, by sheer accident I suppose, American. I can send encrypted content over that insecure channel that only some receiver could decrypt and read. It's none of Google's or Apple's business like it wasn…

> I can send encrypted content over that insecure channel that only some receiver could decrypt and read.

We've tried this approach with email and has not resulted in a world where I can easily send secure emails to anyone I know.

Even setting aside the problem of inconsistent clients, you're asking for a world where every server re-invents wheels & you haven't even begun to think about solving for authentication (which is a very hard problem even with TLS)

Re: What's the right UX for an expired certificate?

#92
Surprised to see no discussion of this in the context of browser extension signing, and Firefox's little fiasco. Apparently, Mozilla's best judgment is that, after expiry, the extensions should just stop working with no way to restore them ... even though this meant forced disabling of privacy features, which could have outed people and got them killed.

https://news.ycombinator.com/item?id=19823701

Re: What's the right UX for an expired certificate?

#93
post #10

Earlier quoted context omitted.

Isn’t that what happens now when the cert expires? Except when it’s expired it’s a lot harder for users to figure out how to bypass the warnings so they can visit the site to find a contact link to report the issue. Remember not every site is actively checked by their maintainer every day. In an ideal world it shouldn’t be needed (and likewise UX for expired certs wouldn’t be needed), but in practice I think it has m…

OP's idea was to scare the users BEFORE it expires (and the admin still has time to renew). > Remember not every site is actively checked by their maintainer every day. Precisely… so scaring the users while the owner doesn't get the message is useless.

Owner will likely check their email more than visit their site. I know that’s true for various small sites of mine.

Re: What's the right UX for an expired certificate?

#94

A user should not experience an expired certificate. Hence, the right UX is: null.

Sure, in a perfect world we shouldn't need debuggers, seatbelts, emergency services, insurances and many other things, but that's not how reality works.

Well, the debugger is a good example, because it’s also not something that concerns the end user, but only the developer.

In the same way, certificate expiration is a problem that can easily and with 100% reliability be handled by operations. A end user should never be confronted with it.

Re: What's the right UX for an expired certificate?

#95

Earlier quoted context omitted.

> http:// is just legacy baggage we should work toward getting rid of. I, the server, should decide what protocol to use, not the client i.e. some software provided by two of the largest World corporations, which are also, by sheer accident I suppose, American. I can send encrypted content over that insecure channel that only some receiver could decrypt and read. It's none of Google's or Apple's business like it wasn…

> I can send encrypted content over that insecure channel that only some receiver could decrypt and read. We've tried this approach with email and has not resulted in a world where I can easily send secure emails to anyone I know. Even setting aside the problem of inconsistent clients, you're asking for a world where every server re-invents wheels & you haven't even begun to think about solving for authentication (wh…

I'm simply saying that HTTP is perfectly fine and it's not legacy.

Of course it's easier to pay for a certificate from a certification authority that maintains the infrastructure, and no, Letsencrypt is free only on the issue side, but maintaining HTTPS has its warts (for example: renew the certs every 3 months!)

but the problem is not HTTP, HTTP in the hands of people who know what they are doing is completely okay, if browsers ban HTTP I predict an explosion of protocols like Gemini or something similar

A lot of low power devices don't need or can't handle HTTPS and there's no problem if what they do doesn't need security nor identity verification.

Meanwhile it's baffling that we are pushing for internet non-public non-state-run identity authorities, while in UK, Japan, Russia, USA and many other countries such an authority don't even exist for real people...

Re: What's the right UX for an expired certificate?

#96

Earlier quoted context omitted.

> As I said, I am well aware of the perils of MITM. There are mitigations for all your concerns, and in each case, the question should be: is this better or worse than plan HTTP. I think it would be initially better, then gradually become worse. And that's a horrible thing when the public is concerned. There's still people out there concerned about the "memory effect" for battery charging, and recommending a full dis…

Also, today, if your Mom visits google.com, for the first time, and the hotel blocks port 443... guess what? It will try to connect to google.com using HTTP on port 80... at which point the hotel can inject whatever they like. In terms of UX, in my scenario, if they "really" wanted to, the browser could fake a HTTP:// scheme along with the crossed out lock icon, effectively identical to the status quo in terms of UX,…

Webmasters can ensure that browsers only load their websites over port 443 by submitting their domain to the HSTS Preload List.

Surprisingly, google.com is not on this list: https://hstspreload.org/?domain=google.com

Re: What's the right UX for an expired certificate?

#97

Earlier quoted context omitted.

The other answer to your question seemed to me to have guessed wrong what you're concerned about. My guess is that like a lot of non-experts, your thought was "Why do we need this CA role?" and that, fortunately, is something where I can appeal to your intuitions rather than needing some mathematical proof about cryptography you won't understand. This is about identity. How can we (and everybody else) agree on the id…

> How can we (and everybody else) agree on the identity of something? we do, I rephrase it, billions of people do it all the time everyday on WhatsApp. It's called TOFU The first T means Trust. Another example: Protonmail, it uses PGP, it works. The important thing for privacy is the encryption part, not the identity part. Even more so when we all know that full fledged HTTPS site put TENS OF MEGABYTES of garbage on…

> why the bank cannot buy a 10 year certificate it's a mystery to me, I sure hope they'll still be in business in 10 years time from now, at least they should be able to not think about this minutia so often.

There's no more reason they should "think" about this than, say, testing fire extinguishers, it's just routine maintenance, it is presumably somebody's job to ensure all the routine maintenance gets done. If you're holding a meeting about the certificates on the web site, rather than knowing that's maintained and monitored properly as part of normal operations, you screwed up.

Now, why does it need maintaining? Why not have them issued for 10 years (so, longer than many employees will work for the bank) ? Well the lifetime of a certificate in the Web PKI is in practice the best possible agility we can achieve for the entire Web PKI, so the longer the maximum lifetime, the slower we're able to fix any problems.

If the bank's new certificate today is valid for 10 years that means if we sunset things which are a terrible idea tomorrow they are still polluting the ecosystem until at least January 2033. A new browser, written by a team who are all in primary school today, might ship in 2033 and yet it's expected to put up with every weird thing we're still allowing, even if it's known to have been a bad idea for about a decade by then.

Currently the rule is 398 days, so if we outlaw something tomorrow, it's no longer a problem by the end of February 2024. More realistically, if we argue about it for a few weeks, and then agree to ban it from May 2023, it's no longer a problem by the second half of 2024.

Re: What's the right UX for an expired certificate?

#98

Earlier quoted context omitted.

> How can we (and everybody else) agree on the identity of something? we do, I rephrase it, billions of people do it all the time everyday on WhatsApp. It's called TOFU The first T means Trust. Another example: Protonmail, it uses PGP, it works. The important thing for privacy is the encryption part, not the identity part. Even more so when we all know that full fledged HTTPS site put TENS OF MEGABYTES of garbage on…

> why the bank cannot buy a 10 year certificate it's a mystery to me, I sure hope they'll still be in business in 10 years time from now, at least they should be able to not think about this minutia so often. There's no more reason they should "think" about this than, say, testing fire extinguishers, it's just routine maintenance, it is presumably somebody's job to ensure all the routine maintenance gets done. If you…

> fire extinguishers

fire extinguishers are for emergencies!

if a fire extinguisher doesn't work, people can die

if an HTTPS cert has expired, there is no risk involved, it can still be used only o. the domain it was issued for.

Anyway in.my country you have to check them every 3 years and someone comes to you, you don't have to remember about it.

> If the bank's new certificate today is valid for 10 year

nothing prevents reissuing new certificates before expiration, if necessary.

Re: What's the right UX for an expired certificate?

#99
post #12

Earlier quoted context omitted.

I know you're being downvoted for the tone, but I agree entirely. Security is not something to sacrifice to gain less angry users. I do agree, however, with the sentiment that the UX surrounding security leaves a lot to be desired. In most cases we train users to ignore or work around security problems - we don't give them tools to solve and embrace them.

Disagree with your disagree. I understand there’s a recession and security people have to justify their salaries. The most secure system imaginable is for your users to shut their computers and go outside. If you can’t provide security without usability, your system is worthless. The truth is that users want products that feel secure, rather than products that are secure.

This is a misguided and incorrect assessment except for your second point, IMO.

Re: What's the right UX for an expired certificate?

#100
post #12

Earlier quoted context omitted.

I know you're being downvoted for the tone, but I agree entirely. Security is not something to sacrifice to gain less angry users. I do agree, however, with the sentiment that the UX surrounding security leaves a lot to be desired. In most cases we train users to ignore or work around security problems - we don't give them tools to solve and embrace them.

> Security is not something to sacrifice to gain less angry users. Of course it is - it depends on Capital-C-Context. Sure, for the bank, the site you are supplying your credit card details, your email, etc - security is non-negotiable. For hackernews, for reddit, and for similar sites, then security is something to sacrifice, once again depending on context. I've trusted this certificate for the last 2, maybe 3 year…

I literally just said that I agree the UX is poor. Did you read my comment?
Post reply on HN