Hacker Newsnew | past | comments | ask | show | jobs | submit | joking's commentslogin

not available in your country...

I suppose for any in europe waking up like me that I can save you one click and some time.


My case, I have to manage a portal for old tvs and those don’t accept the LE root certificate since they changed a couple of years ago. Unfortunately the vendor is unable to update the firmware with new certificates and we are sold


Yeah that LE root certificate change broke our PROD for about 25% of traffic when it happened. Everyone acts like we control our client's cert chains. Clients don't look at the failure and think "our system is broken - we should upgrade". They look at the connection failure and think "this vendor is busted - might as well switch to someone who works". I switched away from LE to the other free ACME provider for our public-facing certs after that.


Roots for all CAs are going to be rotating much more frequently now. Looking to be every 5 years.


Sounds like planned obsolescence if devices stop working after 5 years or less.


Only for devices that do not allow you to patch the CA bundle as an aftermarket repair. Call your representative and demand Right to Repair legislation.


That is ... basically all of them? Other than general purpose desktop/laptop computers that is. Show me a TV or smartphone that does allow you to push new roots to it...


I'd be interested in hearing more - do you have a source for this?

Seems to me CAs have intermediate certificates and can rotate those, not much upside to rotating the root certificates, and lots of downsides.


The upside to rotating roots is:

1. These might need to happen as emergencies if something bad happens

2. If roots rotate often then we build the muscle of making sure trust bundles can be updated

I think the weird amount they are being rotated today is the real root cause if broken devices and we need to stop the bleed at some point.


> If roots rotate often then we build the muscle of making sure trust bundles can be updated

Five years is not enough incentive to push this change. A TV manufacturer can simply shrug and claim that the device is not under warranty anymore. We'll only end up with more bricked devices.


5 years also is a step not a destination


Sounds more like a detour across hot coals that doesn't get us anywhere closer to the destination.


> 1. These might need to happen as emergencies if something bad happens

Isn't this the whole point of intermediate certificates, though?

You know, all the CA's online systems only having an intermediate certificate (and even then, keeping it in a HSM) and the CA's root only being used for 20 seconds or so every year to update the intermediate certificates? And the rest of the time being locked up safer than Fort Knox?


The thing is even the most secure facilities need ingress and egress points.

Those are weaknesses. It’s also that a root rotation might be needed for completely stupid vulnerabilities. Like years later finding that specific key was generated incorrectly.


Chrome root policy, and likely other root policies are moving toward 5-years rotation of the roots, and annual rotation of issuing CAs. Cross-signing works fine for root rotation in most cases, unless you use IIS, then it becomes a fun problem.


What an absolute pain in the ass for a mediocre increase in security.


And your clients are right. The "security" community's wanton disregard for backwards compatibility is abhorrent.


Well, how the vendor was going to apply other security updates if they cannot update their basic security trust store?

If the vendor is really unable to update, then it's at best negligence when designing the product, and at worst -- planned obsolescence.


1. Ship the product with automatic updates delivered over https

2. Product is a smart fridge or whatever, reasonable users might keep it offline for 5+ years.

3. New homeowner connects it to the internet.

4. Security update fails because the security update server's SSL cert isn't signed by a trusted root.


The real solution is making your shit modifiable by the client.

We do car recalls all the time. Just send out an email or something with instructions of what to put on a USB, it's basically the same thing.

Yes it's inconvenient for consumers and annoying but the alternative is worse. Essentially hard coding certificates was always a bad idea.


Yeah, participation in web tls requires the ability to regularly update your server and client code.

Nothing stays the same forever, software is never done. It’s absurd pretend otherwise.


there was an ad, or a presentation in a conference keynote, from when microsoft built phones, showing a user leaving the house and continuing what was he doing in the car in a very futuristic way. I can't find it now, but was something crazy by then, the continuum idea was also a good one, but here we are, walled gardens and nothing smart about them.


I know exactly which one you're referring to!

(it's a woman, presumably just arrived on a flight, catching a taxi to her hotel)

https://www.youtube.com/watch?v=9FpO-G5die4


Look up the AT&T "You Will" advertising campaign sometime. This ran beginning in 1993, and I remember seeing at least a few of the spots at the time.

What these ads (and much speculative fiction, say, Arthur C. Clark particularly the "newspads" (tablet computers) in 2001 and "minisecs" (smartphones) in Imperial Earth) portrayed was capabilities without consideration of commercial and market imperatives. Capabilities promised empowerment and enablement. Markets delivered enshitiffication and enclosures of commons.

And as Timothy B. Lee noted, "the ads were mostly wrong about one thing: the company that brought these technologies to the world was not AT&T". AT&T's networks deliver much of the content and messaging which was portrayed, but the services themselves are not rooted in AT&T, either the original firm or its remonopolised successor organisation.

<https://www.vox.com/2014/9/6/6113853/we-live-in-the-future-a...>

Microsoft's vision was portrayed as well in the Bill Gates book The Road Ahead, published about the same time (1995). Again, it envisioned much, but little of that vision was delivered directly by Microsoft (though much of it was in fact experienced on computers running Microsoft's operating system, at least until the smartphone revolution supplanted it).

<https://en.wikipedia.org/wiki/The_Road_Ahead_(Gates_book)>


maybe it doesn't do everything postman does, but I'm very happy using the rest client extension in vs code, the http files with the api calls are commited to the source code repository along with the code is easy to use, does what i need, and is easy to share with my colleagues.


I don't have a problem with the notch, I have a problem with the icons not showing in the status bar and there isn't a *** way to show them. It's so difficult to add a overflow button that shows the hidden icons?


the main reason is probably that the chip is already outputting the image in a lossy format, and if you reorder the pixels you must reencode the image which means degrading the image, so it's much better to just change the exif orientation.


> the chip is already outputting the image in a lossy format

Could you explain this one?


JPEG can be rotated losslessly. `jpegtran` can do it, for example (and comes with a script called `exifautotran` to automatically normalise the orientation of a bunch of JPEG files at once).


Image sensors don't "output images in a lossy format" as far as I know.


That’s why you have an vpn or the rdp gateway instead of exposing the machines directly to internet.


I was on the real state listing site side long time ago, we were trying to block scrapers from getting our data, at the en we loss, and now we pay them to send us users instead of paying Google ads because it’s cheaper. Fun times


That kind of search is already available in many portals. You can actually find the shape of a polígon with the places you can reach in 1h of conmuté easily, as there is a google maps api for it (distance matrix) and finding the properties in a polygon is a solved problem. (


Almost as easy as cropping the center. Doing it well automatically is another kind of problem


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: