57 ms·
All of Oculus’s Rift headsets have stopped working due to an expired certificate
- m_fayer 9y agoI borrow the office Rift every couple of months to play around for a weekend and see how the field is progressing. Unfortunately what I've mostly seen is a bunch of regressions, technical and ux, as they update their platform.
- yobrien 9y agoThe new home 2.0 and especially Dash are leaps and bounds above what home was like before I think. You do have to enable it (still beta) but I think it'll be really nice once it's finally released.
- wand3r 9y agoNot an Oculus user but I couldn't imagine using their beta software if their actual QA'ed release upgrades have brick level bugs in them...
- deleted 9y ago[deleted]
- m_fayer 9y agoI had to leave the beta channel to get the device functional after a recent update. Some kind of error loop about "a recent update has not finished installing."
- legitster 9y agoThey let their certificate expire, essentially bricking all of their devices. And now the app running it won't start, so they can't push an update. Just recently picked up a Rift. I love the hardware and their exclusives are top notch, but this confirms my suspicions that their backend is super goofy. They sell Rifts at Best Buy and want to pretend that it's a consumer-ready product, but here's why I am recommending people stay away for now: - Non-existant repair or service out of Warranty. - Basic things in the platform like changing your name or photo don't exist. - Lots of non-response over other basic features requested by the community. - Questionable future investment in the platform or hardware. It sounds like they are moving their efforts towards "lighter" experiences. In short, it feels like being a legacy customer for a new product.
- sebazzz 9y ago< They let their certificate expire, essentially bricking all of their devices. This also suggests that if the decide they stop supporting it, eventually the software will stop working due to these certificate errors for which will then there be no fix.
- IncRnd 9y agoIt may appear to suggest that, but it doesn't. These are code signing certificates not TLS. The certificate isn't for the executable but for the ability to sign an executable. If you update an executable with a new executable that was signed with a certificate that was expired at the time of signing, then you will encounter the issue.
- whywhywhywhy 9y ago> essentially bricking It's not bricked, bricking means it's as useful as a brick as in the actual firmware is corrupted beyond repair.
- Kudos 9y ago> essentially
- kevin_b_er 9y agoIt will be as useful as a brick if nothing can connect to the headset because it requires a signed communication DLL with a built-in obsolescence timer that must be continually refreshed by the company.
- s2g 9y agoHopefully they fix their stupidity with allowing it to expire.
- ChristianGeek 9y agoIt’s virtually bricked.
- Kikawala 9y agoRemember folks, if code signing, countersign with a timestamping service[1] so when your code signing cert expires, your older signed code will still work. [1]https://search.thawte.com/support/ssl-digital-certificates/index?page=content&id=INFO1119&actp=LIST https://search.thawte.com/support/ssl-digital-certificates/i...
- hughes 9y agoWhat happens when the countersigning service's cert expires?
- Kikawala 9y agoBy adding a timestamp to digital signatures, trust conditions are changed to the following list: * data is not tampered * signing certificate was time valid at signing time: signing time is within signing cert's validity * Neither certificate was revoked before signature generation * both, signing and timestamp certificates chain up to trusted root CAs (regardless of their time validity, just must be in trust store). https://serverfault.com/a/878950 https://serverfault.com/a/878950
- cxseven 9y agoThat's weird. The blog post that answer links to implies that even if the timestamp certificate AND signing certificates are revoked on a date following the purported timestamp, then the signature is still trusted. That doesn't make sense to me: If the certificates are compromised, an attacker could backdate the timestamp to whatever he wanted and sign anything. What's the thinking here?
- Rebelgecko 9y agoIt sounds like the same expired certificate is also used to sign their autoupdater's exe, so they can't just roll out an update using a new certificate.
- StavrosK 9y agoWhy is it possible for a device that is basically a display to stop working because a certificate expired? This future worries me.
- aphextron 9y ago>Why is it possible for a device that is basically a display to stop working because a certificate expired? Because Mark Zuckerberg said so, that’s why.
- omegaworks 9y agoAh, what a world we've made... More relevant by the day: http://locusmag.com/2018/03/cory-doctorow-lets-get-better-at-demanding-better-from-tech/ http://locusmag.com/2018/03/cory-doctorow-lets-get-better-at...
- deleted 9y ago[deleted]
- ThatPlayer 9y agoBecause it was the certificate for the Windows driver, and Windows requires signed drivers.
- wtallis 9y agoThe problem isn't that Windows requires drivers to be signed. The problem is that Windows allows drivers to have an expiration date. If Windows verifies a driver's signature at the time the driver is installed, the driver should be considered trustworthy for as long as it remains installed on that system. There's no reason to re-verify the signature every time the driver is used.
- hesdeadjim 9y agoPerhaps as a malware defense?
- rb808 9y agoHas anyone got a good way of managing certificates in the wild? With no real management and staff turnover I've seen a bunch of expired certificate problems. EDIT: presumably you need your client apps/libraries in the field write back when they use a cert that is <X months away from expiry.
- judge2020 9y agoI'd say someone very high up and "tied to the company", probably the CTO, should make sure a signing certificate is renewed when needed and make sure it's rotated every time it's about to hit expiration. For a company as big as oculus with the backing of Facebook, this is a pretty big issue.
- toomuchtodo 9y agoI’d expect at Facebook’s scale, they’d have a PKI management team, and this would’ve gone through their certificate lifecycle management process.
- epberry 9y agoI think the CTOs role here would probably be to make sure a process or team is in place to do this but not actually do it themselves? (For a company the size of oculus)
- draw_down 9y agoMonitors
- ahelwer 9y agoYou can use secret management systems like Azure Key Vault to auto-roll/renew secrets, but your applications have to be built to use such systems. (disclaimer: work for Azure, but not on Key Vault)
- gambler 9y agoFeudal security at its best.
- AHTERIX5000 9y agoSo it's impossible to use Oculus headset locally without runtime calling home and checking something?
- na85 9y agoIt's a Facebook product... Did you expect any different?
- Rebelgecko 9y agoIt's not phoning home (or at least if it is that's not the issue here). The cert used to sign the actual binaries expired, and Oculus signed the binaries in a half-assed fashion that tells windows not to run the code with an expired cert-- what they should have done is timestamped[0] when the signature was created. Since the binaries were signed before the cert expired, nothing should've broken. This is one of those cases that required a perfect storm of multiple mistakes/oversights. [0] https://msdn.microsoft.com/en-us/library/windows/desktop/bb931395(v=vs.85).aspx https://msdn.microsoft.com/en-us/library/windows/desktop/bb9...
- tritium 9y agoBeside the fact that you should be concerned about whether the controlling company goes out of business, or sells your data, here stands yet another reason to never trust devices that require an internet connection to activate in the first place, or phone home periodically to remain active. This includes phones, cars, self-driving cars, watches, farm equipment, computing devices and anything marketed as an IoT appliance. One glitch, as minor as an improper system time, and you’re dead in the water.
- imtringued 9y agoThe problem here is that kernel drivers have to be signed and drivers will stop working if the signature expires because the vendor didn't use a time stamp server during the signing process. The drivers were clearly indended to keep working so I assume this happened by accident. The big question is why on earth can drivers that have been verified and are already installed in your system can suddenly stop working? If this mechanism is intended to protect against malware disguised as drivers then it's already too late. The malware had several years to exploit your system. Expiration after installation simply doesn't make sense for code signing. The signed executable won't change unlike a website. The driver is always going to have the same file hash, forever.
- tritium 9y agoExpiration after installation makes sense from the perspective of planned obsolescence, and in anticipation of long-term-support sunsets. It makes absolutely no sense to the end user, acting as possessor or potentially a reseller of an object, since the very premise implies that an owner should not be provided total control over their device, that it's never really "theirs", and that a vendor should retain the capacity to take a "sold good" away from the owner, under the guise of expected behavior, built as designed, effectively converting a sale into a rental, in time, perhaps after statutes expire. It's effectively a back door for manufacturers, so that they can count on well-made products not lasting forever, not in museums, not for resale, not for nostalgia.
- r1ch 9y agoThis is not how Windows code signing is supposed to work. Normally you'd get a countersignature from a timestamp server so that the verification process can prove that the certificate was valid at the time of signing. It would appear that Oculus signed their binaries without using a timestamp server, so without a way to verify when signing happened they become invalid as soon as the cert expires.
- lopmotr 9y agoSomething like that. Certificates aren't supposed to stop working just because they've expired! That would destroy all abandoned or poorly maintained software within a couple of years. This problem is deeper than forgetting to update it. It should never have caused a failure in the first place. Just the fact that the device apparently can't function at all without the internet is a problem too.
- technofiend 9y ago>Just the fact that the device apparently can't function at all without the internet is a problem too. Isn't Oculus owned by Facebook? Of course it has internet-based mandatory data collection, er uh excuse me, license something something.
- cheeko1234 9y agoFYI, the Oculus does work without internet.
- plussed_reader 9y agoSo does Steam, but the metrics filter back to the mothership eventually.
- josefx 9y agoCurrently trying to work with the HTC Vive on Linux. Which means I need SteamVR installed, which you only get from Steam. Steam of course nukes a perfectly fine installation with updates the moment you start it, so you need a Linux with just the right versions of packages used by steam. Maybe I should have just given up the day Oculus dropped Linux support.
- jimrandomh 9y agoSaw this, opened Oculus Home, there's a message in the Updates tab saying "An update may not have installed correctly", and indeed, VR apps didn't work. Nate Mitchell of Oculus posted on Reddit saying "We're working on resolving this issue right now. We'll keep everyone posted on progress here." https://www.reddit.com/r/oculus/comments/82nuzi/cant_reach_oculus_runtime_service/dvbsnup/ https://www.reddit.com/r/oculus/comments/82nuzi/cant_reach_o... . Top-level of that thread has a workaround involving setting the clock back or using a utility called RunAsDate to fake the clock for a single application.
- deleted 9y ago[deleted]
- kakarot 9y agoWell, that explains why my Oculus wasn't working tonight. I hope this ends up being as easy to fix as downloading a new binary.
- robmaister 9y agoAt the core of the issue, yeah, they just need to publish the same driver with a different signature. It looks like their auto-updater used the same cert though, so they can't distribute it as a normal update. They're probably figuring out the least sketchy/most automated way to distribute it right now. When this is all said and done, there will be a handful of people who will never, ever forget to use the /t flag in signtool.
- mikeash 9y agoThis seems to be a somewhat common type of problem. I wonder if companies should routinely test on machines with the clock set one year into the future to catch them before they hit customers.
- 0x0 9y agoI think you'd run into other problems then, for example if your test machine needs to communicate with https sites powered by letsencrypt, all those sites will appear to use certs that "expired" at least 9 months ago.
- megaman22 9y agoIt's a mess. At one point we had a backup domain controller that had gotten incorrectly setup as a time server, and was out of sync with the rest of the world, with a slight amount of drift. Randomly, our test servers would end up syncing time from that server at times, and wind up slightly off. When the time got slightly more than around five or ten minutes off, connections (over TLS encryption) from those boxes to our Lync IM servers would start failing, and weirdness would ensue. Reboot the box, or sometimes just sign in and out, and things would straighten out, for a while. Very spooky. This was all years ago, so my recollection may be fuzzy, but I spent entirely too much time futzing with SIP traces and certs. Weird, weird things can result from time inconsistencies is my takeaway, however.
- yardie 9y ago
- intoro 9y agoSomething similar just happened to me. I have a windows computer I only Use for gaming. After the last update My Samsung display is no longer usable. It has a polarized effect now only when using the windows Computer. However the Computer Works fine Connected to another brand monitor. So much money, yet windows still sucks when it comes to most basic things
- taspeotis 9y agoI am doubtful this is it but check that you don't have a color filter [1] configured. [1] http://www.brucebnews.com/2017/11/look-at-the-red-flowers-windows-10-now-includes-help-for-color-blindness/ http://www.brucebnews.com/2017/11/look-at-the-red-flowers-wi...
- khazhoux 9y agoIn 2091, an overworked developer will accidentally let the certificate expire for the Planetary Shield Defense Matrix, and the Zylorts will finally conquer Earth.
- dpflan 9y agoSounds like the work of a double agent...
- saghm 9y agoHanlon's Razor? https://en.wikipedia.org/wiki/Hanlon%27s_razor https://en.wikipedia.org/wiki/Hanlon%27s_razor
- jest3r1 9y agoGoogle will keep distrusting your certs. Forcing you to reissue every couple of weeks.
- smaili 9y agoReviving the age-old question: should we use certs against aliens?
- Edmond 9y ago2091 is just around the corner, push it a bit out :)
- Natsu 9y agoIt's okay, some hacker will save earth in the end by typing commands into a graphical, 3-D version of OpenSSL 1.2.
- maxander 9y agoOne wonders if we've made technology unnecessarily complicated. In order to build something like the Oculus Rift, they obviously needed expertise in hardware design, optics, display technology, manufacturing, user interface design, etc etc. Also, they apparently needed expertise in managing the ins-and-outs of the Windows driver security system. Adding one more subject to their already crowded curriculum wasn't very nice of Microsoft. A lot of applications and environments seem to be built with the assumption that they can add arbitrary complexity to their interface, since they're only going to be used by "experts" who can be expected to know everything of relevance and work through a thick documentation to understand the system. In truth, the "experts" who use your programs are going to also be using a dozen other applications, each with their own piles of documentation (or equal amounts of lack-of-documentation,) and have little brain-space left for the intricacies of your framework. So, they're going to use your system while knowing the minimum possible amount about it; if that system contains traps that cause problems for this kind of user, that's bad design.
- andrewmcwatters 9y agoI was just reading something here about Cairo and how it's easy to fall into slow code paths with it, and if you happened across falling into a slow code path, somewhere along the line, "you fucked up." When I read the comment I was immediately flabbergasted: no, someone else fucked up. It's not my fault someone wrote software that sets up undocumented traps for me to fall into. Or provided three ways to do something and two of them are not recommended OOTB. Or is primarily documented by third parties.
- adrianratnapala 9y agoThe problem in this case is much deeper than their fault / your fault. The problem is that in this industry we do (have to?) lean too much on the power of abstraction. Whether you are writing SQL or graphics code you are constantly told "just express what you want to express directly, and the system is smart enough to do things as efficiently as possible". But that might not be very efficient at all. The people who write "the system" have to write software that does specific things in specific situations and there will be endless cases which cannot be dealt with efficiently. And the more the interface hides the implementation, the less likely it is that those cases will be obvious.
- melvinmt 9y agoMove Fast and Break Things.
- gruez 9y agoor rather, forget to move and break things.
- navium 9y agoThis is what happens when a CTO goes for a programming retreat
- scrollaway 9y agoThis, and many incidents like it, makes me think that running tests 1/10/100 years in the future should be a standard feature of test runners and CI systems. (on by default)
- sdrothrock 9y agoI work with time a lot and have always advocated running practical simulations, especially over year changes, leap year changes, leap year days, etc. with the junior engineer I mentor as well as the hardware company that partners with us -- it's only recently after we got bitten by a time-based bug that people have started listening.
- taberiand 9y agoOf course, if they had listened and therefore never been bitten, they would have seen the work as a waste of time.
- sdrothrock 9y agoThat's the nature of the beast. I have to be the noisy guy about testing and also be the guy who doesn't say "I told you so," but instead continues pushing testing.
- Sylos 9y agoI mean, they would have noticed when a test actually runs into a problem, but yeah, it's not nearly as visible as something actually going wrong in production.
- toomanybeersies 9y agoI had a bunch of tests fail at the start of this year because someone had hard coded 2017 into the tests. Fortunately it was a problem with the tests, rather than the code itself, but these things do happen. At my old job, we had a bunch of tests fail when daylight saving ticked over. For some reason, some things were using local time, rather than UTC. We also had a test that would fail if the minute was the same as the hour. Time is hard
- peterwwillis 9y agoI've pointed out this consequence of "put TLS on everything" before, but people shrugged it off.
- flukus 9y agoIt seems like the commenters here are still shrugging it off. At least facebook and the oculus division are still around to fix the issue, imagine if this was a company that was now defunct, which could easily have been oculus if facebook hadn't purchased them. You're hardware would now be bricked and you would have no recourse because no one is left to create a new certificate. Or imagine if the occulus 2 was out and they decided that they no longer wish to support the old one, this is the ultimate vehicle of planned obsolescence. It's not just people shrugging it off, many are defending this as being a perfectly fine state of affairs.
- unmole 9y agoThis has absolutely nothing to do with TLS.
- peterwwillis 9y agoYou're right, TLS doesn't use certificates. What was I thinking? https://en.wikipedia.org/wiki/Transport_Layer_Security#Digital_certificates https://en.wikipedia.org/wiki/Transport_Layer_Security#Digit...
- aiecompany12 9y agoAustralian Investment Education https://australianinvestmenteducation.com.au/how-to-invest-in-shares/ https://australianinvestmenteducation.com.au/how-to-invest-i...
- 8bitsrule 9y agoI'm -constantly- seeing 'certificate expired' in my browser. This certificate stuff is so hard that they can't pay some Chief Certificate Officer $15/hr. to -do nothing else- but assure that stuff is renewed in a timely fashion? We furry 'self-reproducing' (YMMV) mammals are simply not ready for all of this.
- draw_down 9y agoOn the contrary, these are problems that can be solved easily. Just need a bit of foresight is all.
- lunch 9y agoA driver signed with any certificate that expires after July 29th, 2015, without time stamping, will work on Windows 10 until the certificate expires. https://docs.microsoft.com/en-us/windows-hardware/drivers/dashboard/get-a-code-signing-certificate#code-signing-faq https://docs.microsoft.com/en-us/windows-hardware/drivers/da...
- gambler 9y agoWhat a horrible design decision. Instead of making a system that simply works or doesn't work Microsoft allowed everyone to produce apps which break at random times in the future. It's one of those "what could possibly go wrong?" cases.
- lunch 9y agoIs there a default, or standard TTL for this type of certificate? EDIT: Looks like the standard TTL for these code signing certificates is none, 1, 2, or 3 years. https://www.entrustdatacard.com/products/categories/digital-signing-certificates/compare-entrust-code-signing-certificates https://www.entrustdatacard.com/products/categories/digital-... https://www.globalsign.com/en/code-signing-certificate/ https://www.globalsign.com/en/code-signing-certificate/ https://www.instantssl.com/ssl-certificate-products/code-signing-index.html https://www.instantssl.com/ssl-certificate-products/code-sig...
- Robotbeat 9y agoHa! My dad was just telling me how some of our old SANs had this happen. Just had to change the date to 2017 then do a firmware update.
- FrantaH 9y agoWow, thanks to reading HN headlines in the morning I realized my own cert expired at midnight and I was able to fix it without any damage.
- mattnewport 9y agoOur VR surgical training startup has been working for the last few months towards a big medical conference this week where we're showing multiple training procedures for multiple customers on Oculus Rift, as well as having our own booth. The headsets all stopped working the morning of the conference. Fortunately one of our engineers figured out we could get our demo rigs working by setting the clock back a few days. This could have been a huge disaster for our company if we hadn't found that workaround though. Pretty annoyed with Oculus about this
- fijal 9y agoImagine how terrible it would be for your customers once that happened in the production....
- konschubert 9y agoHe said it's a surgical training startup so I think it would have been fairly okay.
- Piskvorrr 9y agoThose things aren't cheap for simulators, either - not to mention knock-on costs. "What do you mean - I got the doctors in, which alone took a month of herding cats, and now it won't work, just because?" How low has the SW development bar gone, if "it's okay" now means "at least it's not directly killing people"?
- babuskov 9y ago> How low has the SW development bar gone, if "it's okay" now means "at least it's not directly killing people"? I though that was the way ever since OS/2 failed. Getting stuff out to customers has priority over quality control.
- johnchristopher 9y ago
- retromario 9y agoFor those affected, Oculus now has a patch to fix the issue: https://support.oculus.com/217157135500529/ https://support.oculus.com/217157135500529/
- Grollicus 9y ago> If Windows Defender prompts "Windows protected your PC", click More info and then click Run anyway. > If your antivirus software restricts the file from opening, temporarily disable your AV and continue. Good Patch Procedure, 2018.
- Raphmedia 9y agoThe last time I listened to a vendor and turned off my anti-virus to install something, this happened: [Flight Sim Company Embeds Malware to Steal Pirates’ Passwords] https://news.ycombinator.com/item?id=16418837 https://news.ycombinator.com/item?id=16418837
- Angostura 9y agoNote for company communication guys. Please, please don't say: "Our teams apologize for any inconvenience this may be causing you" instead opt for "Our teams apologize for any inconvenience this caused you"
- boobsbr 9y agoWhy?
- crowbahr 9y ago"May have caused" is disingenuous ass covering at best. They soft bricked every single headset worldwide. "Oopsie we may have caused you inconvenience" vs "We're sorry for the damage"
- Angostura 9y agoIn fact, I cocked up my correction. It should be phrased: "Our teams apologize for the inconvenience this caused you" Get rid of the may entirely. I don't know what I was thinking.
- OrganicMSG 9y agoYou are likely to annoy many of your customers even further. Including the word 'may' shifts the sentence from apologising for causing actual inconvenience, to apologising for causing a minor risk of possible inconvenience, which is not what you are trying to convey after selling someone something for a lot of money and then remotely breaking it at no notice. In many customers, it is likely to elicit a response something along the lines of: "Any inconvenience this may be causing? I'll give them may be causing. The fucking thing won't boot. May be fucking causing. I wasn't using the damn thing as a doorstop."
- draw_down 9y agoCome on.
- sneak 9y agoMinor nitpick: “soft-bricked” is like “soft-pregnant”. That’s not what “bricked” means, Techcrunch.
- Piskvorrr 9y agoFrom what I've seen in XDA, soft-brick is a state which is recoverable without physically opening up the device and hunting for JTAG headers ;)
- nottorp 9y agoSo you're saying Rifts and Windows 10 drivers do not work offline? That basically Windows 10 will be functional only while Microsoft keeps the update servers on? Edit: I don't follow Windows, I'm really curious what the consequences for stuff like this can be generally.
- dharmab 9y agoNo. The certificate in question is a code signing certificate, not a TLS certificate. Oculus incorrectly used an expiring certificate instead of a timestamped certificate here; if timestamped certificate was used, then the Rift driver would work offline forever.
- theonewhocanfly 9y agoThe site has aggressive ads
- bakli 9y agoShameless plug: To avoid such embarrassing situations in future, I've made https://monitorcertificates.com/ https://monitorcertificates.com/. It's free to use right now, and sends your reminders on Slack and Email.
- crowbahr 9y agoI mean you'd think with the resources available at Facebook they would've: 1. Automated the certificate process to auto-renew at least a year before expiry. 2. Have counter-signatures 3. Have anyone at all use any sort of calendar system to just check in on it to be sure. But I guess being one of the largest tech companies on earth doesn't mean you don't have massive oversights.
- bakli 9y agoThere are still chances of Human error here as it's very difficult to automate issuing new certificates (unless you're using Let's Encrypt, which they are not).
- detaro 9y agoYour service does not actually seem to be able to monitor this kind of certificate, IMHO moving this from "shameless" to "spam".
- logicuce 9y agoI am yet to find any official statement from Oculus on this. Am I missing something?
- dharmab 9y agoThey have a support article and fix at https://support.oculus.com/217157135500529/ https://support.oculus.com/217157135500529/
- squarefoot 9y agoThis one will hopefully be solved quick by the company, but think of what would have happened if this was a piece of technology sold in hundreds thousands pieces by a company now out of business: instant tons of electronic junk that would be instead perfectly useable if there was a law mandating all software/hardware details to be released if either of these conditions are met: IP owner going out of business, company declaring the product obsolete and stopping any technical support or upgrade, product sales plummeting due to competing or new models. The first two are obvious while the third one would allow some of the devices to be repurposed instead of thrown away. I've saved a good number of old access points / routers from the landfill by installing OpenWRT/Lede where possible o their latest available firmware,pairing them together, adding homemade external antennas (small Wifi antenna enclosed in white PVC pipe plus self bonding tape, silicone sealant and heatshrink, RF240 cable and RP/SMA or N connector: => years exposed to sun, rain and snow with zero problems). I install them at really low prices to customers who need a cheap wifi bridge from point A to B. I would love to do a similar "afterlife" service to old cellphones, but none of them could host a true native Linux install because of how tightly closed the underlying hardware is, and all of them sooner than later are doomed to be thrown away. The problem lays in the IP. It's considered to be a vital asset so that when a company goes belly up it will survive kept years or decades in a safe by law firms in the hope someone will buy it, or just to make profits through litigation against infringers. Unfortunately this has a deleterious effect on products derived from that IP, the people who bought them and the people living where the unusable products will be trashed.
- agar 9y agoOK. The issue arose because the expired certificate wasn't countersigned by a timestamp server. So many comments agree that (a) security is hard, (b) countersigning with a timestamp server is easy to miss, (c) countersigning makes build processes difficult, and (d) they've done or seen similar things in other apps/companies. This sounds like a classic UI/UX issue for developers around a literally mandated and mission-critical requirement of the OS. At the least, MS should provide a validation tool to surface errors or risks before production. Better, signtool.exe should make omissions (like a timeserver) very difficult and make them an override, not a default. Best, they would do both. I don't agree that the OS should reject non-timestamped signatures as faulty per se (and throw an error), as that puts the burden on the user to understand a developer's mistake. Sometimes running without a timestamp may be desirable - ultimately that's the dev's choice. It should just be a choice made explicitly.
- acd 9y agoWhy does a device you own have to have an expiring certificate?
- juanmirocks 9y agoI feel more understandable with Oculus in this one... Recently I also left an certificate, expire... However, this affected only one single customer of ours and we had a fix within a couple of hours. -- I certainly learn from this mistake.
- makecheck 9y agoRotation due to expired keys should be frequent, enough to pretty much require automated methods to handle the changes. (One of the many great things in LetsEncrypt.) If it’s a much longer time scale, people start to forget that it’s even possible for stuff to expire. If my fridge filter can display a little reminder light on a timer every few months, cryptography-dependent devices might need something similar. That way, your customers could know in advance and be asking you for an update.
- rixrax 9y agoOculus says you will receive $15 store credit if you used Oculus between Feb 1st and when it went kaput. I don't see credit on my Oculus account? Am I supposed to have received it already? Or is this maybe because I don't have payment method added to my account?
- boojums 9y agoOculus sent out an email mentioning the $15 store credit. That email mentions it might take up to 7 days to get the credit.
- toomasr 9y agoGoPro Desktop app's certificate expired more than a week ago and no update. I wonder if this will give them a nudge https://community.gopro.com/t5/GoPro-Apps-for-Desktop/Installation-Developer-certificate-expired/m-p/146532#M11495 https://community.gopro.com/t5/GoPro-Apps-for-Desktop/Instal... I thinks IT is used to managing HTTPS certificates, domain name auto-renewals but app level certs are more of a new thing.