3 ms·
You're right. I looked into this a little further. The data is encrypted with Github's private key (thus decrypted with their public cert). I then wondered h
by deaps 8y ago
You're right.
I looked into this a little further. The data is encrypted with Github's private key (thus decrypted with their public cert). I then wondered how he got a copy of Github's private key...but as it turns out, the IP does belong to Github.
In either event, definitely misconfigured, but I added an exception as it all seems legit in the end. It looks like he's just hosting his site (with his own DNS) on github's server and didn't get an ssl cert yet.
- incomplete 8y agodisclaimer: i work for berkeley EECS, but have no association w/these faculty or class. TL;DR: they probably wanted to save some money by not paying our instructional group to do the hosting, and instead are (most likely) paying github for hosting. because they're doing this themselves, it means that things like real, working SSL certs are their responsibility, and most likely were "too hard" or would take "too long" to set up properly. ¯\_(ツ)_/¯
- zeusk 8y agoGithub is free for open source
- Lurker397412 8y agoThe whole hosting package wasn't always
- incomplete 8y agopoint.
- mirajshah 8y agothanks for sharing... It's crazy that Berkeley (such an awesome institution) has come to this... The US/CA govt's owe it to the university to increase funding.
- setr 8y agoI really have my doubts that a university as big as Berkeley has any trouble with the costs of hosting video lectures. And afaik the UC's are also already very well funded
- jolmg 8y ago> The data is encrypted with Github's private key (thus decrypted with their public cert). I don't think that's how it works, because then anyone could decrypt the data since the decryption key is public. Rather, I think how asymmetric crypto works is you pass your public key to them so they can encrypt stuff with it and send it to you to decrypt with your private key. Then, to send stuff to them, you use their public key to encrypt the data for them so they can decrypt with their private key. That said, I think TLS works differently by using asymmetric crypto only to negotiate a symmetric key for the actual encryption of data. EDIT: made wording more precise