11 ms·
Techcrunch SSL Cert Expired
- raxxorrax 7y agoyeah, digicert is quite expensive.
- csunbird 7y agoI still can not click on techcrunch links because of their massive cookie wall that has no straight-forward way to disable all cookies.
- magicalhippo 7y agoCan't load it right now, but if it's that huge thing that tries to make it seem you need to accept it all, you can go "reject all" and then press the small "leave" link. If you get redirected to some other page, just press back and it should be OK. Though in most cases I just leave the site.
- danielbarla 7y agoIt's a lovely dark pattern lately. I'm also fairly annoyed by another pattern which involves giving the user a "carry on" vs "configure" decision, which when opened shows that only essential cookies are enabled. While this is probably closer to the correct implementation, I'm fairly sure that it's meant to subtly steer people away from the configure option [1], via "see, there's nothing to configure, you should have just picked the other option". You can be sure though, that the other option had everything and the kitchen sink enabled. [1] EDIT: In the long-term, that is, not that individual site's interaction.
- zelphirkalt 7y agoEven better, when those "essential" cookies are actually not essential at all and are just tracking cookies. Personally I hope such people get sued until they manage to adhere to the law in a sensible way, so that it really hurts their business, which is built on unethical treatment of their visitors/users. Wishful thinking probably.
- csunbird 7y agoAlso some other websites employ a similar dark pattern: When you click "Show options", they show a page where every cookie is disabled and they put down a huge "Accept all and continue" button with a small "Save my settings" button. You almost click it instantly because you think the huge button will save your settings, but actually you will be giving consent for all cookies.
- detritus 7y agoI caved in and made a specific container-type in Firefox just for TechCrunch articles, given they pop up so frequently here on HN. My list of containers will become a bit unwieldy in time, I think. I should probably consolidate some types and take the hit a bit on some cookie sharing behind the scenes. What a mess.
- SAI_Peregrinus 7y agoTry the Temporary Containers addon. If a site doesn't have a specific container it opens in a new, temporary container. That container gets deleted 10 minutes after you close the tab, taking all the cookies/local storage/etc with it.
- detritus 7y agoOoh, thanks! That sounds like a much smarter solution.
- nekoashide 7y agoYeah, even with all the reporting in the world at my employer sometimes we sometimes miss one, or a setting. It's hard to be good at certs.
- weavie 7y agoUptime robot (https://uptimerobot.com/ https://uptimerobot.com/) can be set up to alert you about any upcoming cert expiries. It has saved our necks a few times.
- jb775 7y agoIs the free tier for this something that's valuable or do you realistically need the pro version?
- amiraliakbari 7y agoThe free tier doesn't include SSL monitoring, but has many other useful free features.
- yjftsjthsd-h 7y agohttps://uptimerobot.com/pricing https://uptimerobot.com/pricing lists SSL monitoring under paid features.
- heavenlyblue 7y agoCome on, I have failed to update a cert many times before; but the only single reason that happened was because I never bothered to set a calendar reminder to do so.
- michaelt 7y agoImagine, through a series of company acquisitions and suchlike, you've got forty internal web services spread across five different tech stacks, three primary public-facing websites, plus some APIs, and some mail servers, and some secondary sites like a recruiting website built and managed by an external company. At that point, calendar reminders ain't going to cut it. And I imagine that TechCrunch-Oath-AOL-Yahoo-Verizon has at least that much complexity.
- harrisreynolds 7y agoFor posterity and as a general public service announcement I posted a screenshot here: https://www.webase.com/blog/pro-tip-makesure-your-ssl-cert-does-not-expire https://www.webase.com/blog/pro-tip-makesure-your-ssl-cert-d... This is bad, but at least the domain name didn't expire!
- orblivion 7y agoHmm, what about a browser warning that a cert is _about_ to expire? You'd think a major website would have employees looking at it on occasion, they'd catch it.
- progval 7y agoYou don't want this kind of warning to end-users. Just use monitoring with alerts.
- orblivion 7y agoWhat if it's like two days in advance? Probably better than the thing going down. Your monitoring should have caught it by then.
- davidcuddeback 7y agoThat’s a good use case for monitoring tools. There’s a Munin plugin that will measure days until expiration for SSL certs. I use that with an alert threshold just shorter than when Let’s Encrypt auto renews so that I get an email alert in case the auto renew fails for some reason.
- aaronmdjones 7y agoI've never seen a publicly-trusted certificate with a 12-hour validity period before.
- aargh_aargh 7y agoI'd expect this to be some kind of self-damaging public statement regarding the news that Safari will start blocking sites with certs valid for >1 year.
- panarky 7y agoTechcrunch is a hot mess lately. Most TC links get uBlocked completely now with adtech run amok.
- nimbius 7y agoyup. It routinely winds up in my pihole lists as well.
- cpach 7y agoPerhaps they will now switch over to automatically provisioned certificates :)
- Macha 7y agoAt least historically, they did. Wonder what went wrong
- currysausage 7y agoVerizon maybe?
- jrockway 7y agojrockway's law of monitoring: All companies will eventually gain an alert for TLS cert expiration.
- aogl 7y agoWhat's happened to TC recently..
- jb775 7y agoI must say, seeing this makes me feel a little less embarrassed from my own expired SSL facepalms
- llacb47 7y agoSome sysadmin is getting chewed out on the phone right now...
- robbyt 7y agoOr they're being praised for "fixing the website"
- GuyPostington 7y agoYou're funny.
- rvz 7y agoThey seem to have now updated and fixed the expired cert and all links work again with SSL on. techcrunch.com Issued by: DigiCert SHA2 Secure Server CA Expires: Wednesday, 2 March 2022 at 12:00:00 GMT
- mholt 7y agoIs this a good opportunity to plug an open source project I've been working on for 5 years that basically solves this problem? https://caddyserver.com https://caddyserver.com will keep your certs renewed for free, automatically, without extra tooling, dependencies, or moving parts. I really hope more sites will use it because this stuff happens. If you've heard of Caddy but haven't used Caddy 2 yet, we've made some huge improvements with it, and it's capable of managing tens of thousands of certificates at a time. As of next week's beta it can handle certificates with lifetimes as short as a few minutes. It works as a load balancer, in a cluster behind load balancers, and with Docker with its new dynamic config API. There's no technical reasons I know of why sites like TechCrunch can't use it.
- vinaypai 7y agoWhat does it do that certbot doesn't? Personally, I don't see the benefit of bundling certificate renewals with the HTTPS server.
- mholt 7y agoA quick perusal of the Let's Encrypt forums will reveal a few issues. For one, it's easy to misconfigure. There's a lot of surface area it has to cover in the web server and there's a lot that can go wrong. It can also be tricky to install since it is separate from your web server and has a number of complex depeneldency requirements (like many large Python programs). And because it's an external dependency, there's no way the server can react to errors in CertBot, only CertBot can control the server, so you don't get the benefit of duplexed interactions. Caddy is written in Go, a memory safe language. I cannot overstate how significant it is that most servers like ngixn, Apache, and HAProxy are written in C and cannot offer the same security guarantees. Caddy will also staple OCSP, in the most robust way compared to other servers. It has weathered outages that took Apache and NGINX sites down (in Firefox). We've also seen CertBot consume high amounts of resources at scale, whereas Caddy can handle thousands of certs no problem. That's why some companies have talked to me about why they switched. Caddy can coordinate cert management in a cluster. This happens automatically when configured with the same storage backend. CertBot doesn't do that. Caddy works great behind reverse proxies, or as the reverse proxy. Perhaps most importantly, Caddy is the only server to use HTTPS by default without needing any explicit configuration. You simplify your deployment workflows and have less room for things to go wrong. There's also a values statement here... If you think privacy and security are important, you choose software that enables privacy by default because it aligns with your values. Sure, any number of solutions can get you TLS and a few even get you TLS via ACME, but Caddy (2) is highly optimized to handle the edge cases and scaling requirements a lot of sites have these days.
- ck2 7y agoThis is why I do not like the "every 90 days" on Let's Encrypt Even if automated, actually especially if automated, that's four times a year you can have complete site failure if something goes wrong. ps. would be nice if firefox could easily override expired certs for advanced users like self-signed certs
- cpncrunch 7y agoEven though the certs are 90 days, the script renews the cert 30 days before it is due to expire. Typically you will run the script once per week via crontab, so you'll get emailed once a day with a message saying either it has renewed the cert, or it isn't ready for renewal. IMO Let's Encrypt is the best way to manage an SSL cert these days.
- karatestomp 7y agoFor my hobbyist-tier and personal web stuff I'm pretty annoyed at how active webserver management is becoming, largely over SSL stuff. No more setting up Apache and enabling auto-security-updates for your package manager then not touching the server for years. I get why but it still kinda sucks.
- cpeterso 7y agoTechCrunch's new cert expires in two years. Who at TechCrunch will remember to renew that cert in February 2022? If they had to renew certs every 90 days, they most likely would not have forgotten. Cert renewal would be automated or part of regular quarterly planning.
- praveenweb 7y agoNow Safari will no longer trust certs valid for more than 13 months. Recent discussion thread about it https://news.ycombinator.com/item?id=22398063 https://news.ycombinator.com/item?id=22398063
- GuyPostington 7y agoYou know you could monitor your certs to verify that your client is functioning correctly. There's also notification emails if you provide your email address at issuance time.
- mirages 7y agohttps://crt.sh/?id=2500908236 https://crt.sh/?id=2500908236 12h long certificate was used
- 0x0 7y agoThat's just the precertificate
- cm2187 7y agoAlso the expiry date of a cert I think is based on local time of the browser, not utc. So the website might work for the owner of the site while being unaccessible to someone from a different time zone.
- GuyPostington 7y agoWays to monitor for cert expiry in no particular order: 1) Prometheus + blackbox_exporter https://www.robustperception.io/get-alerted-before-your-ssl-certificates-expire https://www.robustperception.io/get-alerted-before-your-ssl-... 2) Sensu/Nagios https://github.com/sensu-plugins/sensu-plugins-http/blob/master/bin/check-https-cert.rb https://github.com/sensu-plugins/sensu-plugins-http/blob/mas... 3) Openssl in a crontab: echo | openssl s_client -connect ${DOMAIN}:443 -servername ${DOMAIN} -verify_hostname ${DOMAIN} 2>/dev/null | openssl x590 -noout -startdate -enddate