4 ms·
What happened to personal freedom of letting people choose for themselves how long a certificate should last? Not really liking this trend of large companies ma
by aestetix 2y ago
What happened to personal freedom of letting people choose for themselves how long a certificate should last? Not really liking this trend of large companies making decisions for others and then forcing them on everyone.
- RedShift1 2y agoAnd making ourselves completely dependent on those certificate authorities handing out certs. Dystopian, a couple of mega corps deciding who gets a cert and who doesn't.
- bawolff 2y agoNothing is stopping you from using different certificate authorities or one you made yourself. Other than getting other people on board of course.
- eesmith 2y agoMy site is http-only because I prefer to not be dependent on those certificate authorities handing out certs, because it's been that way for 25 years, because there is zero confidential data on it, and because the issues concerning snooping and ad insertion by intermediates is not a real threat to my limited readership. However, there is the https-only movement to prevent web browsers from viewing my website, because it it not https and therefore not 'safe'. This movement overlaps pretty well with the people who don't accept other different certificate authorities.
- bawolff 2y ago> However, there is the https-only movement to prevent web browsers from viewing my website, because it it not https and therefore not 'safe'. Like i said, nothing is stopping you from doing whatever you want other than the fact that other people might not like it, and might choose to treat your website differently. Just like you can choose not to use https, other people can choose not to like sites that don't use https. Freedom goes both ways.
- eesmith 2y agoI thought you were too dismissive with your use of "nothing is stopping you." There is a big difference between "nothing is stopping you from starting an exercise program" and "nothing is stopping you from being the ruler of the planet" even though the construction is the same.
- bawolff 2y agoSure, but we are talking about open source software you can fork and change however you like, the difficulty level is a bit in the middle. I'd put it more on the level of - if you dont like the food a resturant serves, nothing is stopping you from opening your own. Yes its hard, but certainly not impossible.
- tzs 2y agoThe point is that if the browsers make it hard enough to actually use HTTP sites then it doesn't really matter if the user is OK with that. Same with self-signed certificates or private CAs. Certificates are particularly painful because it sometimes seems that every program that needs them has its own way to find them. I can't just install in one OS-wide store and say that it should work just like the certificates from the major certificate authorities. No, I have to install it in Chrome and Firefox. Oh and I've got some Python scripts and some Perl scripts and some PHP scripts that need it, so I've got to put it where they want. And let's not forget curl and wget. And how about thing I'm running in a VM or under Docker? Or database clients.
- appendix-rock 2y agoHuh? How do you see that this aspect of the PKI has at all changed with this change?
- chippiewill 2y agoAnyone can create a certificate with any duration they like. Getting others to trust that certificate is the tricky bit. These "large companies" put restrictions on what certificate authorities are allowed to do so that they can keep their users safe.
- aestetix 2y agoSafety at the expense of personal freedom to choose for yourself? What if I do not want the "safety" that these "large companies" claim to provide?
- nolist_policy 2y agoSpin up your own (possibly private) CA.
- nightpool 2y agoYou're welcome to compile your own Firefox or Chromium build if you disagree with the trust decisions the default ones make.
- rightbyte 2y ago[flagged]
- aestetix 2y agoAlso in this case, "safety" can be defined as protecting American companies from lawsuits while ensuring they continue to make lots of money from extorting SSL certificate sales.
- gruez 2y ago>while ensuring they continue to make lots of money from extorting SSL certificate sales. Which IaaS/PaaS providers are doing this? Most of the popular ones I know (ie. not some shady shared hosting reseller using whmcs solutions) lets you upload whatever certificate you want, or has certificates for free/included in the monthly price. In other words they're not going to benefit from shorter lived certificates. In the worst case you can set up cloudflare "flexible SSL" in front of your site and get it for free.
- bawolff 2y agoSame reason you cant choose the expiry on your passport or drivers license.
- aestetix 2y agoSo large companies are now government agencies?
- growse 2y agoWhat do you think passports and signed TLS certs have in common? (Hint, it's nothing to do with "the government").
- aestetix 2y agoPassport/ID document expiration dates are decided by law. Therefore it is in fact "the government." Do you think there should be a law limiting the lifetime duration of an SSL cert to 45 days?
- gruez 2y ago>Do you think there should be a law limiting the lifetime duration of an SSL cert to 45 days? No such law is being proposed. The cops aren't going to bust down your door for generating a 3650 day certificate using openssl.
- appendix-rock 2y ago[flagged]
- bawolff 2y ago> Passport/ID document expiration dates are decided by law Passport max validity length is set by the ICAO not the government.
- bigfatkitten 2y ago
- growse 2y agoNothing stopping you running your own CA and issuing your own certs. Your actual problem is that the browser vendors (who decide which certs should live in the root store) have certain criteria which CAs need to meet in order to be trusted. Why should Firefox / Chrome / etc. have to honour your desire that your arbitrary-length lifetime certs are trusted by default in their browsers? You still have the personal freedom of installing your own CA root if you like.
- aestetix 2y agoI find it interesting that all of the arguments seem to be about the merits of whether pushing this on everyone is good or not, and they all take for granted that personal freedom does not matter anymore. I dislike not being able to choose my SSL lifetime for the same reason I do not like a web browser deciding for me if I can use my own CA. In both cases choices are being made for me, whether I like them or not.
- Y_Y 2y agoBig tech paternalism is the worst. "You can't install that, it might be a virus!"
- SahAssar 2y ago> I do not like a web browser deciding for me if I can use my own CA What browser does not allow you to load your own trusted CA?
- bananapub 2y agoyou can do whatever you want, this is about what browsers and SSL cert issuers will agree is reasonable and will indicate to users is "secure". other decisions they've made on this topic that you can disagree with if you care: - ciphers - hashes - CAs - revocation systems etc
- nickf 2y agoI'm not sure how you think certificates work? It's not for 'yourself' - the certificate is an assertion to billions of users worldwide, called relying parties. If you don't care about those, then you can use a private CA. If you do care (and want anyone's browser to work) then it's not a 'personal freedom'.
- remram 2y agoYou're free to not use CAs. What about their freedom? Or even not use TLS. And what about the right for users to privacy and security, when there's no drawback on the host other than their misguided sense of "freedom"?
- foul 2y agoThe networked environment of today is rapidly phasing-out anything not passing through big bulky systems (most of the time these are for-profit firms). While we wait for the moment one of them (like Let's Encrypt or Sectigo or some BS from FAANGs) will become a SPoF and mess up services anywhere, you can always roll a private CA, use SSH tunnels or SOCKS proxies.