Live data from Hacker News

F-Droid site certificate expired

gitlab.com

1–10 of 115 posts

Re: F-Droid site certificate expired

#2
Licaon_Kter @licaon-kter 4 hours ago Maintainer Looks like while we have new certificates ( https://monitor.f-droid.org/services/tls-certs ) rotation failed. :(

They acknowledge rotation failed but it is still failing [1]. Perhaps something to do with how certs are rotated on their CDN?

[1] - https://www.ssllabs.com/ssltest/analyze.html?d=f%2ddroid.org...

Re: F-Droid site certificate expired

#5
post #3

Because those ephemeral LE certificates are such a great idea...

It is, if your objective is to closely centralize the web. If you make https mandatory, via scare tactics, only people with certificates will have websites. If you make ephemeral certificates mandatory by taking advantage of a monopoly, then only big SSL providers who can afford it will survive.

Then, when you have only two or three big SSL providers, it's way easier to shut someone off by denying them a certificate, and see their site vanish in mere weeks.

Re: F-Droid site certificate expired

#6
post #3

Because those ephemeral LE certificates are such a great idea...

It is, if your objective is to closely centralize the web. If you make https mandatory, via scare tactics, only people with certificates will have websites. If you make ephemeral certificates mandatory by taking advantage of a monopoly, then only big SSL providers who can afford it will survive. Then, when you have only two or three big SSL providers, it's way easier to shut someone off by denying them a certificate,…

Great explanation and very apt for out time when we regularly hear of people being banned/debanked/jailed for their political views in western countries.

Re: F-Droid site certificate expired

#8
post #3

Because those ephemeral LE certificates are such a great idea...

It is, if your objective is to closely centralize the web. If you make https mandatory, via scare tactics, only people with certificates will have websites. If you make ephemeral certificates mandatory by taking advantage of a monopoly, then only big SSL providers who can afford it will survive. Then, when you have only two or three big SSL providers, it's way easier to shut someone off by denying them a certificate,…

You don't need short expirations for that. CRLs/OCSP already provided a mechanism for certificates to be revoked before they expire.

However, short expirations severely limit the damage an attacker can do if they steal your private key.

And they avoid the situations where an organization simply forgets to renew a cert, because automating something so infrequent is genuinely difficult from an organizational standpoint. Employees leave, calendar reminders go missing, and yeah.

Re: F-Droid site certificate expired

#10
post #3

Because those ephemeral LE certificates are such a great idea...

They are. Unbreakable crypto for free, your clients don't have to exchange keys with you in person, and the only cost is running a script on a server that has to run automated code all day anyway
Post reply on HN