Slashdot Mirror


Chrome 70's Upcoming Security Change Will Break Hundreds of Sites (techcrunch.com)

When Chrome 70 arrives on October 16th, it will drop trust for a major HTTPS certificate provider, putting hundreds of popular websites at risk of breaking. "Chrome 70 is expected to be released on or around October 16, when the browser will start blocking sites that run older Symantec certificates issued before June 2016, including legacy branded Thawte, VeriSign, Equifax, GeoTrust and RapidSSL certificates," reports TechCrunch. From the report: [D]espite more than a year to prepare, many popular sites are not ready. Security researcher Scott Helme found 1,139 sites in the top one million sites ranked by Alexa, including Citrus, SSRN, the Federal Bank of India, Pantone, the Tel-Aviv city government, Squatty Potty and Penn State Federal to name just a few. Ferrari, One Identity and Solidworks were named on the list but recently switched to new certificates, escaping any future outages.

HTTPS certificates encrypt the data between your computer and the website or app you're using, making it near-impossible for anyone -- even on your public Wi-Fi hotspot -- to intercept your data. Not only that, HTTPS certificates prove the integrity of the the site you're visiting by ensuring the pages haven't been modified in some way by an attacker. Most websites obtain their HTTPS certificates from a certificate authority, which abide by certain rules and procedures that over time become trusted by web browsers. If you screw that up and lose their trust, the browsers can pull the plug on all of the certificates from that authority.
For these reasons, Google stopped supporting Symantec certificates last year after it was found to be issuing misleading and wrong certificates, as well as allowing non-trusted organizations to issue certificates without the proper oversight.

122 of 177 comments (clear)

  1. This not about security, because it does not help by gweihir · · Score: 4, Interesting

    None of the still-accepted certificates are any better. The CA system is fundamentally broken and what Google does here is not doing anything for security. It does create a false sense of security though (making things actually worse) and it does inconvenience a lot of people.

    --
    Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  2. Piss on it ... by CaptainDork · · Score: 3, Funny

    ... I'm going back to IE on my XP.

    --
    It little behooves the best of us to comment on the rest of us.
    1. Re:Piss on it ... by freeze128 · · Score: 1

      Good luck rendering HTML5.

    2. Re:Piss on it ... by Cmdln+Daco · · Score: 2

      You can run current SeaMonkey on XP.

    3. Re:Piss on it ... by bobby · · Score: 1

      Most videos including HTML5, Flash, etc., play very well on Opera 12.18 including in XP. Much less of a pig than Chrome. Starts up fast, fans generally stay quieter. Shame they stopped developing it, but it still works.

    4. Re:Piss on it ... by hcs_$reboot · · Score: 1

      ...on a 80286?

      --
      Slashdot, fix the reply notifications... You won't get away with it...
    5. Re:Piss on it ... by hcs_$reboot · · Score: 1

      IE6 is great if you need to retrieve some old pages of the y2k zone from web archive.

      --
      Slashdot, fix the reply notifications... You won't get away with it...
    6. Re:Piss on it ... by jez9999 · · Score: 1

      You're joking, but I do find myself using Pale Moon a lot because Chrome is so damn fussy and prescriptive. For instance I purposely run my iptables wrapper's web interface on a high port number to make it less likely hackers will try and hit it, but Chrome just flat out refuses to load the site on a high port number unless you pass a commandline argument in each time you run it. Ludicrous.

    7. Re:Piss on it ... by JackieBrown · · Score: 1

      I have stiff in the 8000 range and have no problems.

    8. Re:Piss on it ... by jez9999 · · Score: 1

      I think it's because I'm running it on one of the ports that Chrome considers to be "really dangerous" because it's used by another common protocol, as specified in this list:

      http://tech-stuff.org/which-po...

      It's really rather annoying that they assume they know better than me when I explicitly specify the port in the address bar. We're not talking about XSRF here.

    9. Re:Piss on it ... by CaptainDork · · Score: 1

      Changing subject, Y2K was a once-in-a-lifetime event, as I think you know.

      The most entertaining part, for me, was all the trees killed on CYA boilerplate we (law firm) sent out to any address we could find and we didn't even vet to see if people, businesses, persons were even alive.

      That cost thousands of dollars in postage, paper, toners, and time.

      Me, I just made sure the system didn't go off the rails while they processed all that shit.

      On the flip side, we demanded reciprocal letters of (legally binding) assurances from any address we could find and we didn't even vet to see if people, businesses, persons were even alive.

      That whole crowd pre-defined "problems" as being due to some technical fault beyond any sender's/receiver's control.

      Management came up with a neat idea for me, "Captain ... just set the clocks back to the future; see what fails; roll back the clocks, and fix stuff."

      Some people actually did that.

      Servers went nuts because timing on desktops didn't agree, licenses expired (my favourite) and backups were looking at some NTP server and failed.

      It was a hoot.

      I had applied all the best practices available and spent New Year's Eve and part of Jan 1 babysitting the system.

      Absolutely nothing went wrong except ...

      We had a Novel 4.1 server (legacy) that didn't make the jump, but it was damned near dead by then, anyway.

      Good times.

      --
      It little behooves the best of us to comment on the rest of us.
    10. Re:Piss on it ... by CaptainDork · · Score: 1

      Pale Moon makes me break out in a rash.

      I'm not saying that to piss you off.

      There's something about it that just doesn't seem right.

      I'd agree with you if your position that it's just me, OK?

      I could run it while Network Monitor is up (I have WireShark but like NM better) so I could maybe see what's up, but I'm a retired and tired IT guy and I'm not in the mood to do a deep dive.

      I use DuckDuckGo, Firefox in Private Browser, NoScript, ADBlock Plus, uBlock Origin and No Coin.

      I erase all temp files, including browser history (that's not supposed to be there, right?) the auto-run ccleaner.

      Here's my .bat file (look at the RunDll32.exe):

      taskkill /f /im iexplore.exe
      taskkill /f /im firefox.exe
      taskkill /f /im chrome.exe
      taskkill /f /im MicrosoftEdge.exe
      taskkill /f /im MicrosoftEdgeCP.exe
      RunDll32.exe InetCpl.cpl,ClearMyTracksByProcess 4351
      cd\
      cd C:\Program Files\CCleaner
      ccleaner64 /auto

      exit

      --
      It little behooves the best of us to comment on the rest of us.
    11. Re:Piss on it ... by CaptainDork · · Score: 1

      I used Opera back in the days when Moby Dick was a minnow *and it's still in my toolbox) because I could open shitloads of instances because the footprint was small.

      We have tabs for that, now.

      --
      It little behooves the best of us to comment on the rest of us.
  3. Re:This not about security, because it does not he by thoughtlover · · Score: 4, Insightful

    ...not doing anything for security. It does create a false sense of security though (making things actually worse).../p>

    A valid assessment... and, Google's being quite the hypocrite by delivering THEIR OWN search results via http. Seriously... I wish I was joking. My personal domain with my artwork isn't viewable via Chrome or Safari because it doesn't have (or need) a cert.

    FF FTW, but even they're getting wonky. Pale Moon??

    --
    No sig for you! Come back one year!
  4. That's rich by ArhcAngel · · Score: 1

    Google forcing "security" on people it has already stolen identities from.

    --
    "A person is smart. People are dumb, panicky dangerous animals and you know it." - K
    1. Re:That's rich by Cmdln+Daco · · Score: 1

      Google is protecting the 'security' on identities that it wants to be the sole exploiter of.

    2. Re:That's rich by Ol+Olsoc · · Score: 1

      Google forcing "security" on people it has already stolen identities from.

      Annnnnnnd? Holy hell - you are correct! I never thought of it this way, but Got-Damn, get that post to +5

      --
      The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
  5. Re:This not about security, because it does not he by tepples · · Score: 5, Insightful

    Do the world a favor, get a certificate for your site, even if it's just the free one from let's encrypt.

    I agree for a public site. But it's not quite free for a private web server behind the firewall of a home LAN. Like other CAs that web browsers trust by default, Let's Encrypt requires a fully qualified domain name, not an IP address in 192.168/16 or a hostname within a reserved TLD like .internal, and many dynamic DNS providers aren't on the Public Suffix List and/or don't support TXT records. Should it be expected for every householder to buy a domain name so that the web interface of his router, printer, and NAS can be issued a certificate for HTTPS?

  6. Rent-seeking behavior by macraig · · Score: 1

    Certificate issuance has become yet another excuse to indulge rent-seeking behaviors. Just burn it all down.

  7. Re:This not about security, because it does not he by msauve · · Score: 3, Insightful

    Google is a net newbie, and although they think and act (incorrectly) like they know what they're doing, they want to be a (bad) nanny to everyone. What ever happened to "don't be evil?"

    --
    "National Security is the chief cause of national insecurity." - Celine's First Law
  8. It eliminates Blue Coat by Anonymous Coward · · Score: 5, Insightful

    I sort of semi-agree. But...

    Lest you forget, Symantec gave root authority to Blue Coat, an firm selling network sniffing software.

    https://www.theregister.co.uk/2016/05/27/blue_coat_ca_certs/

    Which let Blue Coat fake certs for websites and browsers that did not authorize it. In effect Symantec authorized this man in the middle attack on their behalf.

    This was after an incident where Symantec were caught issuing fake Google certificates, which they claimed was 'testing/accidentally released'.

    This was after the Snowden reveal that some unnamed certificate authority had been issuing fake Google certs to NSA for intercepting Google's internal communications.

    So, it DOES help security, but yeh, the basic problem is you're trusting a third party to verify a website as real, and that third party is not trustable. Trust should be built up over time, which means you cannot permit silent revokes of certificates or silent changes to certificates. Every browser should track every certificate and scream blue murder if the certificate is ever changed : "alert alert alert, this website you've been dealing with for 3 years suddenly has a new certificate from a new authority, go see WTF is happening".

    1. Re:It eliminates Blue Coat by cascadingstylesheet · · Score: 1

      but yeh, the basic problem is you're trusting a third party to verify a website as real, and that third party is not trustable. Trust should be built up over time, which means you cannot permit silent revokes of certificates or silent changes to certificates. Every browser should track every certificate and scream blue murder if the certificate is ever changed : "alert alert alert, this website you've been dealing with for 3 years suddenly has a new certificate from a new authority, go see WTF is happening".

      Except that nobody has come up with a better way.

      Sure, they've come up with theoretically better ways, but none that are workable.

      We should come up with one of those checkbox lists like used to circulate for spam solutions ... "your plan to replace third party certificate authorities is interesting, but will not work because ... {crap ton of checkmark points}"

  9. Re:This not about security, because it does not he by youngone · · Score: 1

    Should it be expected for every householder to buy a domain name so that the web interface of his router, printer, and NAS can be issued a certificate for HTTPS?

    I shivered when I read that. why would you even want your router or NAS web config accessible from outside your LAN?

  10. Re:More than 99.88% of sites are ready for Chrome by youngone · · Score: 1

    And if they don't they get what they deserve.

  11. Squatty Potty

    Not Squatty Potty!

    --
    (-1: Post disagrees with my already-settled worldview) is not a valid mod option.
  12. Name != connecting; using NAS over Internet by tepples · · Score: 2

    Even if one cannot open a connection to the device from the Internet, the CA still has to be able to resolve the device's name through the Internet in order to issue a certificate. Otherwise, you're stuck using self-signed certificates, and some mobile and set-top devices reportedly don't let the user examine the fingerprint of a self-signed certificate that a device presents to ensure that it is the intended certificate.

    Besides, there are plenty of legitimate reasons to access network-attached storage over the Internet. You might trust it more than Google Drive or Microsoft OneDrive, for instance, or the storage connected to your single-board server might be bigger than the 2 GB that Dropbox gives you.

    1. Re:Name != connecting; using NAS over Internet by duke_cheetah2003 · · Score: 1

      Besides, there are plenty of legitimate reasons to access network-attached storage over the Internet.

      This is what VPNs are for. Use one.

    2. Re:Name != connecting; using NAS over Internet by tepples · · Score: 1

      Even when connecting through a VPN, all browsers require an HTTPS origin in order to view a site that uses Service Workers.

  13. How does Let's Encrypt rent-seek by tepples · · Score: 2

    What's so "rent-seeking" about, say, Let's Encrypt? It issues trusted domain-validated certificates without charge to just about anyone who owns a domain name.

    1. Re:How does Let's Encrypt rent-seek by macraig · · Score: 1

      That's an exception. You can spare it the flames.

  14. Re:This not about security, because it does not he by hairyfeet · · Score: 4, Insightful

    Not just that but the whole "HTTPS equals security" is a fundamentally flawed concept because not only as you point out the CA system is a mess but there are so damned many sites where it makes ZERO sense to have it encrypted in the first place!

    I mean is there a reason I should give a single flying flipping fuck if someone knows I'm looking at a simple website serving only .txt and .jpg of ancient CPUs designs like 8088 and AMD K2? Or the bazillion other websites that again only serve static .txt and .jpg images that haven't be updated in forever (and probably won't be) that were made before the whole HTTPS kick? The only excuse I've heard is "it keeps "teh gubmint" from listening in"...but they are in the backbone so I really don't see that making a diddly dick of difference and do I REALLY need to give a shit if some damn spook knows I like looking at ancient tech on some website made when Geocities was a thing?

    Finally with the CAs seeming to get pwned at least a couple times a year I don't even know if this should count as security theater anymore, maybe security karaoke? As in "pretends to be security but is about as good as your average barmaid trying to sing Patsy Kline on karaoke night?". So unless this is a way for GOOG to slurp down more data than a drunk at a free mini-bar (which really wouldn't surprise me) I'm really not seeing a big selling point for any of this, hell especially not from GOOG who just got who knows how many users pwned with their GOOG+ fiasco...whats the upside of this whole mess again?

    --
    ACs don't waste your time replying, your posts are never seen by me.
  15. Re:More than 99.88% of sites are ready for Chrome by hairyfeet · · Score: 1

    Sounds EXACTLY what we had in the early 00s with IE...and we all remember what a clusterfuck that turned out to be. Protip: Having only ONE corp control the way sites are rendered on the net? Is a BAD THING because if its one thing we should all know by now is that ALL of these corps are run by sociopath douchenozzles that will happily tilt the scales to give themselves a bigger slice of the pie.

    Maybe its about time we start talking about slamming GOOG with an antitrust and hopefully break them up? Because APPL and MSFT don't seem to have enough of the pie to be a real threat but with GOOG? Starting to look a little scary,little too much like MSFT of the late 90s.

    --
    ACs don't waste your time replying, your posts are never seen by me.
  16. Re:This not about security, because it does not he by Anonymous Coward · · Score: 5, Insightful

    google isn't a net 'newbie' they're a net 'bully'. trying to force their way upon everybody.

  17. 1 in 878 sites = many? by RhettLivingston · · Score: 1

    1 site in every 878 not working with a browser doesn't seem like much. Have things actually gotten that stable?

    I don't think slashdot has been up 1/100th of the last year. Wasn't there an outage of several days less than a year ago?

    Even Amazon has had significant outages this year. Netflix was down some. No site seems above having an outage. And even if they are, there are still many times a year that my own internet goes out - certainly more often than my electricity goes out.

    The internet is not a stable, always up environment and likely never will be. Electricity distribution is over a century old and not yet stable. Water distribution is older than that and still goes out.

    Why do people insist on making a big deal out of an outage for a tiny few irresponsible sites?

    1. Re: 1 in 878 sites = many? by edris90 · · Score: 2

      Because it's the tiny obscura sites these days that tend to hold unique or useful information. Ever since the internet went mainstream you've had to dig deeper and deeper to get uncensored data doesn't wrongfully imply that there isn't a way to do what you're trying to do. Civil disobedience is the last recourse against malignant rules and Order. is important the people free access to information so that they may make a law irrelevant, it is the last defense of freedom .the ability to disobey At will. If we lose that then we lose any chance at a life worth living.

    2. Re:1 in 878 sites = many? by RockDoctor · · Score: 1

      TFS : Security researcher Scott Helme found 1,139 sites in the top one million sites ranked by Alexa,

      RhettLivingston on 2018-10-09 3:55 (#57449150) : 1 site in every 878 not working with a browser doesn't seem like much.

      Very much my first thought - a relatively small number of incompetents or recalcitrants.

      The really depressing thing about it is, the first actual examination of the numbers comes about 90% down the list of Slashdot comments.

      --
      Birds are not dinosaur descendants;birds are dinosaurs, for all useful meanings of "birds", "are" and "dinosaurs"
    3. Re:1 in 878 sites = many? by RhettLivingston · · Score: 1

      Though "many" doesn't mean a majority when used as an adjective, it does mean majority when used as a noun and carries a connotation of something closer to that than not over to the adjective case because of that. A number that is much less than 1% just doesn't rise to the normal usage of the word and ends up being misleading (as likely intended in this case).

  18. Re:Actually by Cmdln+Daco · · Score: 1

    People will just route around the problem by using a different browser. On an XP machine at work the 'Chrome' browser refuses to upgrade past a certain point and throws a warning banner on the top of the screen. So I installed SeaMonkey. I use the old version of 'Chrome' solely for the gmail account on that system. So any browsing I do there is not logged-onto a google account.

  19. Re:This not about security, because it does not he by The+MAZZTer · · Score: 4, Insightful

    A valid assessment... and, Google's being quite the hypocrite by delivering THEIR OWN search results via http.

    Uh, google.com has been HTTPS only for some time now. Not sure what you're talking about,

  20. Ads and your internet by AHuxley · · Score: 1

    A company wants to make the internet safe for its own ads.
    Find a better browser.

    --
    Domestic spying is now "Benign Information Gathering"
  21. Re:This not about security, because it does not he by AHuxley · · Score: 2

    Re "Imagine someone coming to your site is in a country where your content is illegal because thoughtcrime?"
    Such governments will have fully upgraded to tech that can track all their nations users browser uses.
    A VPN would be of more help than a browser.
    Let the rest of the world enjoy the internet and "that" country can have its users discover the better security of a great VPN.

    --
    Domestic spying is now "Benign Information Gathering"
  22. Re:This not about security, because it does not he by Pinky's+Brain · · Score: 3, Insightful

    Google's policies impose an opportunity cost for any CA issuing false certificates. CA's can still be abused, but that abuse turns a CA into a very expensive weapon which can only be used for a very limited time and then becomes useless. By showing that no CA is too big to fail they provide a valuable service. When abuse becomes more expensive, it's reduced ... capitalism works.

    Now I'd rather they support DANE, but even what they are doing now does improve matters.

  23. Re:More than 99.88% of sites are ready for Chrome by Pinky's+Brain · · Score: 1

    Apple owns almost half the mobile phone market in the US and probably over 3/4 of the ones owned by middle class and up consumers. They have just as much sway to force changes in CAs as Google, they are also distrusting Symantec BTW.

  24. Lesson by hcs_$reboot · · Score: 1

    Let's hope that will help those people who bought hyper-expensive Verisign certs understand that for 1/10 of the price, they had a better working alternative.

    --
    Slashdot, fix the reply notifications... You won't get away with it...
    1. Re:Lesson by hcs_$reboot · · Score: 1

      Or even free (Let's encrypt), though the 3-months renewal period is a bit a pain (even when automatized).

      --
      Slashdot, fix the reply notifications... You won't get away with it...
    2. Re:Lesson by hcs_$reboot · · Score: 2

      January + February + March == 90 days ; with a 75% probability.

      --
      Slashdot, fix the reply notifications... You won't get away with it...
  25. Don't be evil was changed by bursch-X · · Score: 5, Funny

    Google changed the "don't be evil" line a while ago, it's now:

    "Welcome to my underground lair."

    --
    There are two rules for success:
    1. Never tell everything you know.
  26. Re:This not about security, because it does not he by hcs_$reboot · · Score: 1

    What ever happened to "don't be evil?"

    They removed that line for legal reasons. They could have been attacked on this, even in the past, "being evil" is too vague and subject to interpretation.

    --
    Slashdot, fix the reply notifications... You won't get away with it...
  27. Re: This not about security, because it does not h by houghi · · Score: 1

    I have a domainname. Why would I be forced to use https://toaster.example.com/ when I browse to my Linux toaster, when just typing 'toaster'?
    It is in no way connected to the internet.

    Or try the domain hackme.houghi.org and see how that is connected. Excluding local IP addresses should be standard.

    --
    Don't fight for your country, if your country does not fight for you.
  28. Re:This not about security, because it does not he by Bert64 · · Score: 1

    For an internal network you typically control all the endpoints, so you can create and trust your own CA...

    --
    http://spamdecoy.net - free throwaway anonymous email - avoid spam!
  29. Re:This not about security, because it does not he by Bert64 · · Score: 1

    Even if the site is mundane and harmless, it can still be used to perform mitm attacks against the client.

    On the other hand, HTTPS sites break the captive portal system used on a lot of wifi networks.

    --
    http://spamdecoy.net - free throwaway anonymous email - avoid spam!
  30. Re:This not about security, because it does not he by AmiMoJo · · Score: 1

    If it's your internal network you can just create your own cert and add it to your local machine(s). That's how it's supposed to work.

    --
    const int one = 65536; (Silvermoon, Texture.cs)
    SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
  31. Re:This not about security, because it does not he by AmiMoJo · · Score: 4, Interesting

    Actually Firefox is the same. Mozilla have been pushing for this change too.

    And Google is somewhat ahead of the curve regarding CAs and security. They know the limitations, that's why Chrome now doesn't display information from enhanced certs. Google knows they are worthless and don't identify the owner of a site reliably, do they don't display them in a little green box next to the address bar any more.

    It's actually pissing off a lot of CAs. Now that Let's Encrypt offers basic certs for free, and there is no real difference between basic certs and enhanced certs, they don't have anything to sell.

    --
    const int one = 65536; (Silvermoon, Texture.cs)
    SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
  32. CAs are a protection racket by DrXym · · Score: 2
    At the end of the day I would trust a site more if I recognised who bestowed trust onto it.

    Why can't banks have other financial institutions sign their certs? Why can't Google, Facebook, Apple et al, hold a key signing party? Why can't lawyers get their certs signed by their bar association? Why can't government websites have certs signed by their governments, which in turn might be signed by other governments?

    It doesn't stop CAs from being signatories too if somebody pays $$$ for them to do it. But when ONLY CAs are allowed to sign certs, the security of sites is brittle and expensive. And often the signature is worthless other than it makes some scary box go away on the browser.

    1. Re:CAs are a protection racket by thegarbz · · Score: 1

      Why can't banks have other financial institutions sign their certs?

      Why can't each person individually verify and determine the trust of every request they send to the internet in order to determine their exposure and level of security? Oh wait I know the answer to this: It's fucking stupid.

    2. Re:CAs are a protection racket by DrXym · · Score: 1
      Yup. Nothing to stop CAs selling their service as auditors, but if someone doesn't want a CA cert, or prefers to have other signers instead of or inaddition to the CA, then they should be allowed.

      At the end of the day even an unsigned cert is better than nothing at all. At least it affords encryption to the website. Coupled with a service like SSL lighthouse, it would be resistant to MITM style attacks too.

      I'm sure browsers could produce some relatively simple way to describe the trust and assign it a score.

  33. Re:This not about security, because it does not he by thegarbz · · Score: 1

    None of the still-accepted certificates are any better.

    Citation Required. The system has a set of rules that are followed. The remainder of the still accepted certificates have been shown to be issued in good faith, which makes them better than those issued in bad faith.

    The CA system is fundamentally broken and what Google does here is not doing anything for security.

    By punishing people who don't live by the rules the system is self regulating. Google not doing anything would undermine / break the CA system which otherwise is working just fine.

    It does create a false sense of security though (making things actually worse) and it does inconvenience a lot of people.

    I would call this horseshit, but to be honest that's an insult to horseshit.

  34. Re:This not about security, because it does not he by thegarbz · · Score: 4, Informative

    My personal domain with my artwork isn't viewable via Chrome or Safari because it doesn't have (or need) a cert.

    Err. no. If your personal domain isn't viewable then you fucked something up that is completely unrelated to certificates or not.

  35. Re:This not about security, because it does not he by AmiMoJo · · Score: 1

    That's bad op-sec. Any and all metadata that can be collected about you is dangerous, even if it seems trivial now. Everything should be encrypted by default, you should need a really really good reason to use plaintext.

    Also consider the potential for interference via MITM attack on HTTP. You could be getting served malware. Some ISPs have injected their own ads and tracking headers.

    --
    const int one = 65536; (Silvermoon, Texture.cs)
    SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
  36. Re:This not about security, because it does not he by thegarbz · · Score: 1

    Should it be expected for every householder to buy a domain name so that the web interface of his router, printer, and NAS can be issued a certificate for HTTPS?

    Why is this relevant in a discussion about a public site?
    Why is this relevant when discussing a browser that still happily shows unencrypted communication?

  37. Re:This not about security, because it does not he by thegarbz · · Score: 1

    Uh, google.com has been HTTPS only for some time now. Not sure what you're talking about,

    No one is sure about what the GP was talking about. To quote a really shit movie: "Amazing. Everything you just said was wrong."

  38. Re:This not about security, because it does not he by thegarbz · · Score: 1

    I mean is there a reason I should give a single flying flipping fuck if someone knows I'm looking at a simple website serving only .txt

    To you? No. Sounds like you're not in the position for being persecuted for a thought crime. I however would recomment against browsing innocent text in some coutries, certainly not anarchists_cookbook_v1.0.txt.

    And that's just it. It's not up to the content creator to determine if the viewer needs the expectation of privacy when viewing the content.

  39. I think you're missing the point by Viol8 · · Score: 1

    The browser belongs to the user. If he wants to see the site he should be able to do so regardless of what some google security "expert" thinks is appropriate. However the "I don't care if the cert is bad, just show me the damn site NOW!" option seems to be disappearing in browsers or if its still there you have to click through half a dozen patronising Are you sure? links first.

  40. Re:This not about security, because it does not he by hairyfeet · · Score: 1

    How EXACTLY is some spook knowing I like ancient arches "dangerous" to me? Cuz I really want to hear this, it ought to be some grade A logic hoop jumping. What are they gonna do, point at me and scream "NEERRRRDDD!"? OMG, the NSA knows I like old CPUs and bad 70s and 80s TV, why my life is ruined!...Oh wait everybody already knows that.

    And as far as a MITM? I have my browser locked down with Ublock AND Privacy Badger, the DNS automatically blacklists malware addresses (thx Comodo DNS, you work great) and I can literally push one button and have it restored to a previous state, oh and now everything but my gaming box is running Zorin OS and the only thing the gaming box has is Steam so...yeah GLWT.

    Meanwhile many of the old sites I go to haven't changed in 20 years, haven't gotten any malware in said 20 years, hell they don't even support the level of Javascript required to spread modern browser based junk so...yeah I smell security karaoke. Oh and 1 final note...considering GOOG got its start up funding in part from the NSA? Frankly I trust anything GOOG does about as far as I can throw their server farm, 5 will get you 10 there is some way in this that will let them increase their spying, because lets face it that is all they've really been up to the past few years, seeing how much data they can slurp and resell.

    --
    ACs don't waste your time replying, your posts are never seen by me.
  41. Re:More than 99.88% of sites are ready for Chrome by hairyfeet · · Score: 1

    Uhhh just looked at the latest figures and Apple's share is...11.9%, in fact according to Motley Fool they have been losing share worldwide for more than 6 months. Their market cap is so good frankly because they sell last year's tech at next years prices which gives them a hell of a profit margin.

    And honestly the USA is a teeny tiny slice of the worldwide pie, with countries like BRIC making the USA look like small potatoes and its in those markets of tomorrow that GOOG is setting up a stranglehold that frankly MSFT of the 90s wishes it had. Its ironic too as they are using the same tactics MSFT did in the 90s with nasty contracts requiring the bundling of GAPPs and hiding more and more behind the Playwall thus making it harder and harder to have a functioning system without connecting it to GOOG.

    So I'm not really worried about APPL, they like their profit margins too much to give up their high end niche status to go mainstream globally while GOOG is much more nerfarious in that they don't want your money, YOU are the product they intend to sell. So...yeah maybe about time for a good old antitrust, although frankly we'd have better luck with the EU as the DoJ has been toothless in the USA for the better part of a decade now.

    --
    ACs don't waste your time replying, your posts are never seen by me.
  42. Re:This not about security, because it does not he by jez9999 · · Score: 1

    Do the world a favor, get a certificate for your site, even if it's just the free one from let's encrypt

    Yeah, and I'm sure you're happy to install their trojan on your machine and giving it write access to your cert store so it can keep replacing the cert because they're too stubborn to issue certificates that last a year!

  43. Certs - you have to trust someone else by FeelGood314 · · Score: 1

    If you don't like the current system of certificate authorities and certificate transparency (which google championed), please tell me a better way for me to trust a site on the internet?
    CAs are now audited and the auditing is getting much better. With certificate transparency I can check, near real time, every EV cert a CA issues. If they issue one in secret there is a high probability they will be caught.

    Symantic should have been dropped a while ago, as they proved to be untrusted. They were just too big to drop immediately. (disclaimer. I worked for Entrust)

  44. Solution to the second issue is certificate pinnin by raymorris · · Score: 1

    > > Every browser should track every certificate and scream blue murder if the certificate is ever changed : "alert alert alert, this website you've been dealing with for 3 years suddenly has a new certificate from a new authority, go see WTF is happening".

    > Except that nobody has come up with a better way

    The better way is called "certificate pinning" and it works just the way the GP described. Your browser won't accept a Symantec certificate for Google.com because it knows Google gets its certificates from a different CA.

    Certificate pinning is opt-in for web sites, sites can decide if they want their certificate pinned, because they may want to change CAs in the future.

  45. Re:This not about security, because it does not he by mujadaddy · · Score: 1

    Security Karaoke

    Nice. Stolen.

    --
    Populus vult decipi, ergo decipiatur...
    "Force shits upon Reason's back." - Poor Richard's Almanac
  46. Re:This not about security, because it does not he by SuperKendall · · Score: 1

    How EXACTLY is some spook knowing I like ancient arches "dangerous" to me?

    Because some people will base passwords around stuff like that, or it can be used to craft highly tailored phishing attacks.

    Probably it will not matter but it costs nothing in practical terms to live like it does.

    --
    "There is more worth loving than we have strength to love." - Brian Jay Stanley
  47. Re:This not about security, because it does not he by JesseMcDonald · · Score: 1

    On the other hand, HTTPS sites break the captive portal system used on a lot of wifi networks.

    I think you meant to say "captive portal systems break HTTPS sites, along with every other non-HTTP protocol".

    Anyway, there has been a standard workaround in place for this problem for a while now. Devices detect captive portals by querying a well-known URL over HTTP; if they get an unexpected response they prompt the user to sign in to the network.

    --
    "The state is that great fiction by which everyone tries to live at the expense of everyone else." - Bastiat
  48. Re: This not about security, because it does not h by edris90 · · Score: 1

    What is the US Military has not stayed within the bounds and scope of our national borders four years US military is out of control. We have no claim to influence on events in the rest of the world. Every Act of military force by the usa, outside our borders is an act of undue aggression upon territories which we do not and should not have any legitimate opinion or interference with. U. S. Military is a bully because when it comes time to back the fuck off cuz it's not US Territory they continually trespass and murder natives within their own countries

  49. Re:This not about security, because it does not he by gweihir · · Score: 1

    I have put a free (and worthless) "let's encrypt" cert on my page to get around this problem.

    --
    Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  50. Re:This not about security, because it does not he by gweihir · · Score: 1

    You think certificates prevent state-actor MITM in actual reality? They do not and have not for at least a decade.

    The CA system was a somewhat reasonable idea with a horrible execution and utter naivety on side of its architects. It is broken and cannot be fixed.

    --
    Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  51. Re:This not about security, because it does not he by gweihir · · Score: 1

    Spot-on. They even try to "fix" TCP, apparently completely unaware that lots of really smart people have failed to do so before them. Not good. They are a Dunning-Kruger company by now.

    --
    Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  52. Re:This not about security, because it does not he by gweihir · · Score: 1

    Indeed. A https-connection is very much _not_ a VPN tunnel, even if naive people may think so.

    --
    Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  53. Re:This not about security, because it does not he by gweihir · · Score: 1

    You are lazy and uneducated. Find your own citations, the relevant research has been around for at least a decade.

    --
    Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  54. Re:This not about security, because it does not he by Xtifr · · Score: 1

    I mean is there a reason I should give a single flying flipping fuck if someone knows I'm looking at a simple website serving only .txt and .jpg of ancient CPUs designs like 8088 and AMD K2?

    You may not care if someone knows you're looking at that site, but you should care that you only recieve .txt and .jpg of ancient CPUs. Without https, a man-in-the-middle can inject whatever they want into the data, and hijack your system. Not a good thing.

    Basically, it's the same reason that Linux vendors use crypto on their packages. Except they just use signatures rather than encrypting the actual data--but nothing in the w3c standards supports just using signatures, so full encryption is the only available solution.

    So, no. I don't care how old and static and simple your site is. You should be using https for the safety of your users.

    (And no, it doesn't help Google collect data. It does, however, reduce the number of DDoSes and the amount of clickfraud they experience from pwned systems.)

  55. Re:This not about security, because it does not he by duke_cheetah2003 · · Score: 1

    Should it be expected for every householder to buy a domain name so that the web interface of his router, printer, and NAS can be issued a certificate for HTTPS?

    I shivered when I read that. why would you even want your router or NAS web config accessible from outside your LAN?

    For that matter, why the heck would you do HTTPS on internal LAN? Wasting CPU cycles on something that shouldn't even be accessible from the outside world at all. Hell, if you want HTTPS on your LAN addresses, just generate your own certs and install your own root cert on client machines.

  56. Re:This not about security, because it does not he by Xtifr · · Score: 1

    And as far as a MITM? I have my browser locked down with Ublock AND Privacy Badger, the DNS automatically blacklists malware addresses

    First of all, none of that helps with a MITM attack which modifies the data coming to your system. It may help if the only thing injected is a url where the malware is located, but it doesn't help one bit if the malware is injected directly. The whole point of a MITM attack is that the data seems to be coming from the main host you're connected to.

    Second, even if those were effective protection, they're only used by a tiny percentage of the population, and that's unlikely to change anytime soon. So the fact that your system wouldn't become part of a hostile botnet (if your protections were effective, which, again, they're not) doesn't mean that hostile botnets would become less common.

  57. Re:This not about security, because it does not he by dissy · · Score: 2

    Google is a net newbie, and although they think and act (incorrectly) like they know what they're doing, they want to be a (bad) nanny to everyone. What ever happened to "don't be evil?"

    You say this as if Google de-trusting this CA in October is a Google choice.

    FireFox limited trust for this CA back in May already, and will be revoking it in October as well.

    May 2018 (Firefox 60): Websites will show an untrusted connection error if they have a TLS cert issued before 2016-06-01 that chains up to a Symantec root.
    October 2018 (Firefox 63): Removal/distrust of Symantec roots, with caveats described below.

    Only Microsoft hasn't announced intent to do so for IE/Edge, in violation of the certificate authority standards I might add.

    There are clear rules CAs must follow and they are not ignorant of this.
    Symantec knew full well they would have all of their CA certs revoked from all web browsers the second they sold wildcard certificates for traffic interception systems.

    This is no ones doing other than Symantec.

  58. Re:This not about security, because it does not he by tepples · · Score: 1

    For that matter, why the heck would you do HTTPS on internal LAN?

    Because a growing number of JavaScript APIs specify that they are available on HTTPS origins and http://localhost/ only, and nowhere else. One such API that is both limited to secure contexts and relevant to streaming a video from a home NAS is the Presentation API.

    Hell, if you want HTTPS on your LAN addresses, just generate your own certs and install your own root cert on client machines.

    Not all client machines make it practical to install a private root certificate, particularly mobile devices or set-top devices. Nor is it advisable to install a private root certificate on devices belonging to visiting friends and relatives if they want to watch a video that's on your NAS.

  59. Visitors invited to view internal resource by tepples · · Score: 1

    For an internal network you typically control all the endpoints, so you can create and trust your own CA...

    Say you invite a friend or relative into your house and then invite him or her onto your guest network to view a video on your NAS. Is it typical in that case to install your root certificate on his or her machine? Because if so, that would let you MITM his or her traffic later on.

    1. Re:Visitors invited to view internal resource by Bert64 · · Score: 1

      I doubt i'd ever do that...
      I would either send the video to them, or invite them to view it on one of my existing devices.

      In any case, my NAS devices are not reachable from the guest network, and a NAS would typically be accessed over SMB or NFS anyway.

      --
      http://spamdecoy.net - free throwaway anonymous email - avoid spam!
    2. Re:Visitors invited to view internal resource by tepples · · Score: 1

      I would either send the video to them

      And it'd then have to fit onto the device's storage. A lot of especially budget phones are strapped for flash space.

      or invite them to view it on one of my existing devices.

      Unless said "existing devices" are already in use by another member of the household for (say) playing a video game.

  60. Re:This not about security, because it does not he by tepples · · Score: 1

    Please see my reply to Bert64, who suggested the same thing.

  61. Re:Solution to the second issue is certificate pin by SilentChasm · · Score: 1

    Except that certificate pinning is being deprecated in Chrome:

    Certification Authority Authorization (CAA) seems to be the replacement for preventing misissuance.

  62. Re:This not about security, because it does not he by DarkOx · · Score: 1

    Its all political at this point. How many times did COMODO screw up and they are still Trusted. Lets not talk about LetsEncrypt which passes out DV validated certs and does not even check there is some kind of payment method tied to them. Stupid

    --
    Repeal the 17th Amendment TODAY! Also Please Read http://www.gnu.org/philosophy/right-to-read.html
  63. Re: This not about security, because it does not h by Curunir_wolf · · Score: 1

    Or try the domain hackme.houghi.org and see how that is connected. Excluding local IP addresses should be standard.

    Exactly this. More specifically, IANA defines 3 private subnets for internal use:

    • 10.0.0.0 to 10.255.255.255
    • 172.16.0.0 to 172.31.255.255
    • 192.168.0.0 to 192.168.255.255

    These should be automatically excluded from the strict TLS rules that browsers impose, especially the ones that give you no option to bypass their built-in blocking mechanisms. Would that really be so hard??? IE doesn't even tell you when they've decided to block a page due to a TLS issue - you just get a generic "Page can't be displayed" error. Good luck figuring out why. A recent update started blocking some Internal sites, so on a guess I decided to upgrade the SSL cert (it was valid, but still using the old SHA1). That fixed it, but IE would not tell me why.

    This crap has to end. Yea, maybe I want in-motion encryption for my internal network, just to make sure there are no plain-text credentials exposed on the wire. That's cheap and easy with self-signed or internal CA techniques. AP5.floor2.local isn't on the Internet, that IP isn't publicly routable, and that wiring closet is still locked. WTF are you questioning my certificate?

    --
    "Somebody has to do something. It's just incredibly pathetic it has to be us."
    --- Jerry Garcia
  64. Re:This not about security, because it does not he by Curunir_wolf · · Score: 1

    My personal domain with my artwork isn't viewable via Chrome or Safari because it doesn't have (or need) a cert.

    Err. no. If your personal domain isn't viewable then you fucked something up that is completely unrelated to certificates or not.

    It's probably viewable. But Chrome puts this scary "Not secure" banner at the top of the page. Prompting visitors to leave right away that don't know what's going on.

    --
    "Somebody has to do something. It's just incredibly pathetic it has to be us."
    --- Jerry Garcia
  65. To be removed after replacement, yes by raymorris · · Score: 1

    Thanks for the reminder. I had seen that before but forgot.

    You are correct, it is slated foe removal after it is replaced with Certification Authority Authorization and Expect Certificate Transparency. High risk sites such as banks can implement both pinning and Expect-CT, along with HSTS, to be protected both now and in the future.

    Before implementing pinning, one should consider the potential problems that can occur if you lose your key and make darn sure there is a secured off-site backup of the key.

  66. Re:This not about security, because it does not he by Curunir_wolf · · Score: 1

    Some ISPs have injected their own ads and tracking headers.

    Ding ding! That's the real reason Google is promoting this crappy https everywhere propaganda. To get rid of any and all competition.

    Also consider the potential for interference via MITM attack on HTTP. You could be getting served malware.

    TLS is NOT going to stop that. Google's blacklist is what stops that. And, sites serving malware can be detected MORE QUICKLY if they are not encrypted.

    --
    "Somebody has to do something. It's just incredibly pathetic it has to be us."
    --- Jerry Garcia
  67. Re: This not about security, because it does not h by threephaseboy · · Score: 1

    These should be automatically excluded from the strict TLS rules that browsers impose, especially the ones that give you no option to bypass their built-in blocking mechanisms.

    Cool, so when I'm at a coffee shop, and someone hijacks the DNS and redirects my bank's site to 192.168.0.3, doing a MITM with a self-signed cert, that should be accepted by the browser? It's OK because it's a private subnet!

    --
    .
  68. At that point I move to Edge or FF by JohnStock · · Score: 1

    Google had fucked me over a few times in the last 18 months I've had enough

    1. Re:At that point I move to Edge or FF by Tony+Isaac · · Score: 1

      Because, of course, Microsoft is so much more respectful of privacy than Google!

    2. Re:At that point I move to Edge or FF by JohnStock · · Score: 1

      No they aren't. But that's only a small part of the reason why I'd move personally. Wrong place to explain, but Google has shafted me on YouTube, Google Maps Contributions and the Nexus 6P

  69. Re:More than 99.88% of sites are ready for Chrome by threephaseboy · · Score: 1

    Apple owns almost half the mobile phone market in the US

    Uhhh just looked at the latest figures and Apple's share is...11.9%

    40% of shipments in 2018 Q2

    53.7% based on browser data (?)

    --
    .
  70. Re:This not about security, because it does not he by squiggleslash · · Score: 1

    And as far as a MITM? I have my browser locked down with Ublock AND Privacy Badger, the DNS automatically blacklists malware addresses (thx Comodo DNS, you work great) and I can literally push one button and have it restored to a previous state, oh and now everything but my gaming box is running Zorin OS and the only thing the gaming box has is Steam so...yeah GLWT.

    That's great, but none of that will stop a MITM attack.

    --
    You are not alone. This is not normal. None of this is normal.
  71. Re: This not about security, because it does not h by Curunir_wolf · · Score: 1

    These should be automatically excluded from the strict TLS rules that browsers impose, especially the ones that give you no option to bypass their built-in blocking mechanisms.

    Cool, so when I'm at a coffee shop, and someone hijacks the DNS and redirects my bank's site to 192.168.0.3, doing a MITM with a self-signed cert, that should be accepted by the browser? It's OK because it's a private subnet!

    If you think these browser "features" can protect your data from capture when you're on a public wifi connection, I've got some bad news for you...

    --
    "Somebody has to do something. It's just incredibly pathetic it has to be us."
    --- Jerry Garcia
  72. Re:This not about security, because it does not he by squiggleslash · · Score: 1

    Also consider the potential for interference via MITM attack on HTTP. You could be getting served malware.

    TLS is NOT going to stop that

    Yes, it is. SSL is as much about authenticating a site as it is about preventing the conversation from being listened to. That's why you get warnings for invalid certificates - the entire point of the warning is that the browser can no longer be confident that there isn't a MITM. It's also why Google is deprecating this CA, because Google can not be confident there's no MITM for certificates the CA in question has signed.

    The only ways to perform a MITM trick with an SSL site are:

    1. Steal the target website's certificate.
    2. Somehow hack the victim's computer and install a fake CA on it.
    3. Use a dubious CA to sign a fake cert.

    And this article is an example of web browser makers preventing (3) from happening.

    --
    You are not alone. This is not normal. None of this is normal.
  73. Re:This not about security, because it does not he by Curunir_wolf · · Score: 1

    Or, just use one of many numerous exploits to install malware on the real site. It's a lot easier. It's not going to prevent you from getting malware. Sure, it may stop one of these specific MITM attacks, but they aren't really very common anyway, are they?

    The really easy way is to set up a real site with a real cert and start advertising on Instagram. You can push out a lot of malware that way.

    This is just security karaoke (yea, I stole it).

    --
    "Somebody has to do something. It's just incredibly pathetic it has to be us."
    --- Jerry Garcia
  74. Re: This not about security, because it does not h by threephaseboy · · Score: 1

    TLS itself as well as browser enforcement are designed to protect against the same kind of threats on your home network as on public WiFi. It's assumed that the network link can be monitored and modified at will, so there shouldn't be a difference.
    My point is weakening those restrictions for "private" subnets will have much greater consequences than just your home network, and doing that because a power user can't or won't use a FQDN to access an internal network resource will have a much larger impact on regular users elsewhere.

    --
    .
  75. Re: This not about security, because it does not h by Curunir_wolf · · Score: 1

    TLS itself as well as browser enforcement are designed to protect against the same kind of threats on your home network as on public WiFi. It's assumed that the network link can be monitored and modified at will, so there shouldn't be a difference. My point is weakening those restrictions for "private" subnets will have much greater consequences than just your home network, and doing that because a power user can't or won't use a FQDN to access an internal network resource will have a much larger impact on regular users elsewhere.

    That should by my call, not some faceless corporations' focused on their bottom line.

    --
    "Somebody has to do something. It's just incredibly pathetic it has to be us."
    --- Jerry Garcia
  76. Re:This not about security, because it does not he by gweihir · · Score: 1

    Stupid indeed. And from a security point-of-view, almost worthless.

    --
    Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  77. Re:This not about security, because it does not he by gweihir · · Score: 1

    Can't say I disagree.

    --
    Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  78. Re:This not about security, because it does not he by tepples · · Score: 1

    I thought the network security config in the Google Chrome and Mozilla Firefox APKs was set to opt in to user certificates.

  79. Re:This not about security, because it does not he by tepples · · Score: 1

    Why is this relevant in a discussion about a public site?

    It is intended as a reminder that not all sites are public, and not all parties involved in this policy change have adequately addressed the effect of this policy change on private sites.

    Why is this relevant when discussing a browser that still happily shows unencrypted communication?

    A browser doesn't "happily show[] unencrypted communication" if it involves a JavaScript API that is reserved for secure contexts.

  80. Re:This not about security, because it does not he by slothman32 · · Score: 1

    I did several searches on Google and couldn't find anything.
    What are good terms to use?

    As for a real answer, the burden of proof lies on the accuser, not just, "I'm right, you prove it."
    That wouldn't go to well in a court.
    You're the one who seems lazy.
    Ad hominem attacks don't help, I only used the lazy word because you did.

    P.S. I wasn't reading the comments too carefully and may agree with you , I just noticed your way of saying it.
    It's actually possible I was wrong but even if I am your comment still seems off.

    --
    Why don't you guys have friends or journals?
  81. Re:This not about security, because it does not he by thegarbz · · Score: 1

    Don't use that Javascript API then. Seriously 99.99% of users will be completely affected by this. The use of secure_contexts is basically non-existant.

    This will mostly affect developers. You know, the kinds of people who are capable of setting up a CA to self sign certs and add their root certificate of their dev machine to their browser anyway.

  82. Re:This not about security, because it does not he by thegarbz · · Score: 1

    But Chrome puts this scary "Not secure" banner at the top of the page. Prompting visitors to leave right away that don't know what's going on.

    Oooooooh scary, some text in a banner advert. ... But are you providing a secure sevice?
    I will straight up say bullshit. Users haven't been scared by "Not Secure" text ever. It's been an uphill battle to prevent people from simply handing over their CC information in such pages.

  83. Re:This not about security, because it does not he by thegarbz · · Score: 1

    You are lazy and uneducated. Find your own citations

    Educate me. I want to learn, but if you're going to make extraordinary claims then you best be able to back them up.

    There's plenty of evidence that has been around for a decade, and that is evidence that shows misbehaviour of the CA process is appropriately punished and frequently able to sink entire certificate authorities. The system is working as designed.

  84. Re:This not about security, because it does not he by tepples · · Score: 1

    Don't use that Javascript API then.

    If you treat secure context gated APIs as if they do not exist, then your NAS's HTTP interface won't be able to use the Presentation API, which allows streaming videos stored on the NAS to second screen devices such as a Chromecast. Nor will your NAS be able to include an app that allows offline editing with sync once you return home, as Service Workers are for secure contexts only. There are even hints that the Fullscreen API itself will be made for secure contexts only in order to plug a phishing vulnerability.

    You know, the kinds of people who are capable of setting up a CA to self sign certs and add their root certificate of their dev machine to their browser anyway.

    A manufacturer of a network appliance containing a web server, such as a router or NAS, would need to automate the provision of a domain name and certificate to each person who buys such an appliance. A developer who makes a web application available for download and installation on a user-owned single-board computer, such as a Raspberry Pi, would need to automate the provision of a domain name and certificate to each person who installs said web application.

  85. Re:This not about security, because it does not he by gweihir · · Score: 1

    This is not an extraordinary claim at all.

    Try google(Certificate system broken), for example, gives you lots of hits.
    Here you can see a reputed expert not even commenting on why the system is broken, because everybody knows it:
            https://www.schneier.com/blog/...

    --
    Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  86. Re:This not about security, because it does not he by gweihir · · Score: 1

    I did several searches on Google and couldn't find anything.

    Try "certificate system broken", maybe? You Google-Fu seems very weak....

    As for a real answer, the burden of proof lies on the accuser, not just, "I'm right, you prove it."
    That wouldn't go to well in a court.

    You are badly wrong. This is not an "accusation", it is a statement of fact and the fact is well established. You would not require a proof or reference that water is wet, would you? As to court: That is a collection of non-experts. What they do is pull in an expert (or several) and then believe what they say.

    Here is a reputed expert that does not even think he needs any explanation when stating the fact (and he is right):
    https://www.schneier.com/blog/...

    --
    Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  87. Re:This not about security, because it does not he by gweihir · · Score: 1

    You are arrogant, lazy and uneducated and, on top of that, out of contact with reality. The CA system is broken. It does not give you any assurances anymore because it is utterly compromised.

    Incidentally, I learned how the CA system works around 30 years ago and at that time, there was some expectation that it could actually work. These have proven to be overly optimistic as greed, stupidity and arrogance has made it very simple to get compromised certificates (even EV ones). You can even buy them as a service: https://www.deepdotweb.com/201...

    --
    Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  88. Re:More than 99.88% of sites are ready for Chrome by threephaseboy · · Score: 1

    That's probably worldwide market share, where Pinky's Brain (#57449228) was talking about US market share, as I quoted.

    --
    .
  89. Oh look, someone took SSL seriously. How cute. by Seven+Spirals · · Score: 1

    One group of asshole corporate-feudalists are saying another group of asshole corporete-feudalists aren't trustworthy? Well, did it ever occur to folks that the whole system SSL established is based on one group of bean counting weasels telling other weasels about "trust". Mother fucking corporations shouldn't be even allowed to utter or write the word "trust". There is nobody I trust less, and their mewling about "Hey, they aren't trustworthy!" means four fifths of five-eighths of fuck all to me. The whole system of trust in SSL is fucking BROKEN. I don't trust any CA to do proper due-dilligence. They are all cheap and don't do a good job (as someone who has done an awful lot of CSRs). They don't even do an adequate job. Crowd sourcing trust from someone other than a corporate jackbooted firm like Verisign/Symantec would be welcome.

  90. Re:This not about security, because it does not he by thegarbz · · Score: 1

    then your NAS's HTTP interface won't be able to use the Presentation API, which allows streaming videos stored on the NAS to second screen devices such as a Chromecast

    Good. Users need to be protected from themselves. Seriously, you need a web based javascript API to stream content? Who the hell designed your NAS.

    Nor will your NAS be able to include an app

    Apps? Since when does Chrome's implmementation of the API matter for apps? Or do I need to question who designed the damn app too?

    A manufacturer of a network appliance containing a web server...

    Should have not problems working around the manufactured examples you gave. I think you'll find most fully functional and capable devices pre-date all your fancy Javascript APIs. If anything it may resolve this stupid obsession with "have API, must write code" that seems to infect so much software these days.

  91. Re:This not about security, because it does not he by thegarbz · · Score: 1

    Thanks for pointing out that example.

    It's two sentences long but it shows a lot. It shows that experts don't comment on things or backup their claims, while appealing to authority (a logical fallacy).
    It also shows how experts can be very wrong citing a case of a "broken" system where a CA did something shady and instantly had their trust certificate revoked.

    i.e. System worked as intended. CAs punshied, users are secure.

    Can you provide examples for your side of the arguement two, or are you only going to provide good examples for my side? Quite frankly you're helping me a lot here. If you don't realise this then maybe you should watch who you call uneducated.

    However I don't think you're this stupid. You're just trolling.

  92. When browser video controls are inadequate by tepples · · Score: 1

    Seriously, you need a web based javascript API to stream content? Who the hell designed your NAS.

    When a web browser's video controls are inadequate, then yes, you need a player script to present controls that let the user send a video into the full screen or onto a second screen.

    Apps? Since when does Chrome's implmementation of the API matter for apps?

    I didn't mean "app" as in native application; I meant "app" as in web application. Chrome's implementation of an API designed for web applications obviously matters to developers of web applications.

  93. Re:This not about security, because it does not he by hairyfeet · · Score: 1

    Feel free as I believe in free as in freedom so all my comments? Are licensed under BSD so do as you will and HAND!

    --
    ACs don't waste your time replying, your posts are never seen by me.
  94. Re:This not about security, because it does not he by hairyfeet · · Score: 1

    Yay! We should make "Security Karaoke" the new definition of beyond useless "security" beyond security theater, after all you CAN have good theater....ever seen good karaoke in a bar on any given night? I know it makes me think of some drunken barmaid trying to sing Crazy by Patsy Kline and butchering that high note so bad it sounds like a kitten in a blender!

    So forget Security Theater, when security ideas get THIS stupid? There really is only one description...Security Karaoke!

    --
    ACs don't waste your time replying, your posts are never seen by me.