6 ms·
Let's Encrypt is switching to a different root certificate (their own root certificate), which means that extremely outdated devices will no longer be able to a
by profmonocle 3y ago
Let's Encrypt is switching to a different root certificate (their own root certificate), which means that extremely outdated devices will no longer be able to access servers using Let's Encrypt certificates.
The biggest concern is old Android devives. By "old", I mean devices using a version of Android from the Obama administration. Android 7.1 is the oldest version that will work, and it was released on October 4th, 2016.
At this point, roughly 6.1% of Android devices are running a version of Android that will be impacted by this change. It's likely that most of these devices are in relatively low-income countries, so depending on your audience this may be much lower or much higher. (If your primary audience isn't in a developing country, it's likely much higher.)
This change will affect you at some point after February 8th, 2024. (Specifically, you'll be affected the first time your LE cert renews after that point. If you're using one of the common clients, it will be up to 60 days after that point.) If you want, you can configure your client to support legacy devices longer, but only up to June 6th, 2024. After then, if you truly need to support very, very old Android devices, you would need to switch from Let's Encrypt to a different (possibly paid) CA.
Only you know for sure if you need to support these very old devices. Most web sites don't.
- thrdbndndn 3y agoA LOT (like, most of them) of commercial Android simulators use Android 7.1 (some even Android 5). Granted most people usually only use them to play games, but it's great that at least this aspect is covered.
- NoZebra120vClip 3y agoMan, to think my prior device ran Lollipop (5.x) and it only died (spicy pillow) about two years ago.
- danparsonson 3y ago> (spicy pillow) https://www.urbandictionary.com/define.php?term=spicy+pillow https://www.urbandictionary.com/define.php?term=spicy+pillow TIL!
- sbergot 3y agoThis happened to a dell laptop provided by work. After contacting support I had a new battery the next day and the laptop survived.
- M3L0NM4N 3y agoI had a Fire Phone (Kit-Kat based) that spicy pillowed like 5 years ago. I've had about 4 phones since then though.
- 1over137 3y agoHilarious how 2016 is "*extremely outdated*". Only in tech does anyone think this. :)
- minikomi 3y agoFashion industry would like a word
- rhaksw 3y agoThat explains how they merged.
- singlow 3y agoI have lots of clothes that I wear that are much older than that. And most that are newer than that use designs from long before 2016. They are only newer because the older ones wore out from use. I can only think of a few articles in my closet that could be identified definitively as newer than 2000 by appearance. I imagine this is true for many men, less often for women I suppose.
- duckmysick 3y agoA lot of perishables (food, medicine, gasoline) get "outdated" pretty fast. Sure, as a concept, lettuce will stay with us for a long time. But an individual Bibb head won't last long, even under perfect conditions.
- oarsinsync 3y agoAnd yet lettuce can still outlast officials in government!
- Anthony-G 3y ago:) For anyone who doesn't get the reference: https://en.wikipedia.org/wiki/Liz_Truss_lettuce https://en.wikipedia.org/wiki/Liz_Truss_lettuce
- 3y ago
- rlaager 3y agoI think you could manually substitute in the old chain—up until the point the signature expires. That would get you until the September date. I wouldn’t recommend it, but that could be useful to buy just a little more time if one was desperate.
- Traubenfuchs 3y agoWhere do low level (eg Android platform) devs pull root certificates from? Who governs that list?
- ZiiS 3y agoAndroid itself (I.e. Google) maintain thier own list; they manage it well IMHO but made a catastrofically bad desision to never update it outside OS versions (they have fixed this in the next release).
- tialaramex 3y agoIn principle whoever is building the Android system can choose whatever roots they want. In practice the Android Project is a Google project, and follows Google's policies. Also in practice, Google's policies strongly resemble Mozilla's. Mozilla's root programme is overseen by mozilla.dev.security.policy, a public group. So, to some extent the answer to "Who governs that list?" is you do, much as (if you live in a democracy) it's your fault that your government is terrible. You could work hard to improve things. But, you probably won't.
- yread 3y agoThanks for the summary. Are there paid CAs that provide tooling like certbot (or work with it)? I don't particularly care about LE or it being free but I like the tools and people using old devices who are easily scared by warnings should be able to use my website...
- mcpherrinm 3y agoThe protocol used by Certbot is called ACME, and is supported by a bunch of CAs, both free and not. In addition to LE, there’s other CAs like sectigo, digicert, and Google Trust Services that support it. A few are listed here: https://www.acmeisuptime.com/#CA-Software https://www.acmeisuptime.com/#CA-Software
- londons_explore 3y agoI'm disappointed that we can't come up with a way for encryption to work forever. Like, if I find a knife from 150 years ago, it still cuts cheese. Sure - it isn't the most modern tech, but it still does the job it was made for. Even though cheese recipes have changed, they are still compatible with an old knife. Yet a phone in 150 years will be 100% useless. Not only useless because other things have moved on, or because the hardware has degraded, but useless by design because root certificates expire. We shouldn't be putting anything into consumer electronics with an expiry date.
- pteraspidomorph 3y agoAny solutions for the problem would still only exist in new devices. And the announcement does indeed mention that new devices will be able to update their certificate store.
- vasco 3y ago> We shouldn't be putting anything into consumer electronics with an expiry date. So you wouldn't have half the consumer electronics we have because nobody would be able to afford them. We should be making consumer electronics with reasonable life expectancies. 150 years in the future I don't want to use something from 150 years ago that "still works", I want something that is new with more capabilities, that is cheaper, that does the thing better. Why create undestructible phones that will last 150 years when nobody other than vintage collectors will want them after ~10 years due to other problems with material degradation, fashion etc. The optimal point is to not create discardable things, but it's also realising that if you're making something forever you're going to use up way more resources and people will still stop using those devices for other reasons, so you just created more waste. Too short life = too much waste due to replacement needs. Too long life = too many wasted resources per-device which will be abandoned for other reasons.
- klntsky 3y ago> 150 years in the future I don't want to use something from 150 years ago that "still works", I want something that is new with more capabilities In 150 years you could as well not have anything new on par with the currently available devices.
- Aardwolf 3y agoSo even encryption encourages planned obsolescence!
- plorg 3y agoYou can add a root certificate to Android, but if you're not a superuser (haven't "rooted" your phone, different usage) you can only add it as a "user" certificate, not a "system" certificate. After I believe Android 7 apps will by default not trust "user" certificates, so this would not help you, but since newer devices should include the LE root cert this just might be a viable solution. It's still not perfect. It's confusing and (probably by design) somewhat difficult for a lay user to do. And Android will give you a scary message every time it starts, saying your phone may be compromised.