7 ms·
Honest Ahmed (2011)
- begueradj 2y agoAchmed, not Ahmed ...
- virtualritz 2y agoYes as far as the title on the Mozilla page goes but: Ahmed is pronounced Achmed (if your first langues is e.g. English). Among my Arab friends with that name the spelling that omits the 'c' is more common. Another common form is Ahmad which is still pronounced the same. The version with 'c' is one that contains a pronunciation hint for people whose native language is not Arabic (but probably English). As is the one with the 'e' vs the 'a' as last vowel. I.e. Ahmad == Ahmed == Achmed.
- Narishma 2y ago> The version with 'c' is one that contains a pronunciation hint for people whose native language is not Arabic (but probably English). What hint would that be? There's no 'c' sound in the Arabic version.
- TazeTSchnitzel 2y ago“ch” like in Scottish English “loch” is closer to the “h” in “Ahmad” than the normal English “h"
- Narishma 2y agoNo, it's not. It's a soft 'H' sound in Arabic, the same as in Muhammad. It's closer to the English 'H'. The Scottish 'ch' is a different letter entirely in Arabic and doesn't appear in this name.
- foldr 2y agoThis sound, to be precise: https://en.wikipedia.org/wiki/Voiceless_pharyngeal_fricative https://en.wikipedia.org/wiki/Voiceless_pharyngeal_fricative It is indeed closer in terms of its place of articulation to English 'h' than either variant of the German 'ch' sound.
- 998244353 2y agoI suppose the point is that it's not the voiceless glottal fricative? To my ears [ħ] sounds closer to [x] and [χ] than to [h] (even though the place of articulation is closer to [h]), but I'm sure it's different for people who (natively) speak a language with all three.
- foldr 2y agoYeah, I imagine it's an interesting question which of these sounds is more perceptually similar to the target sound. It may well depend to some extent on the native language(s) of the person who is listening.
- ludwigvan 2y agoHint as in “Bach”
- Narishma 2y agoBut that's not how it's pronounced in Arabic, see my other comment.
- ahmedalsudani 2y agoI carry a knife specifically to stab people who pronounce my name that way (the Achmed way). ... yes, this is a joke.
- sshine 2y ago... the knife is very dull and purely for ritualistic purposes! ( https://en.wikipedia.org/wiki/Kirpan https://en.wikipedia.org/wiki/Kirpan )
- ahmedalsudani 2y agoAnother variety: https://en.wikipedia.org/wiki/Jambiya https://en.wikipedia.org/wiki/Jambiya
- deleted 2y ago[deleted]
- Dragging-Syrup 2y agoThe best part is the website hxxps://www.honestachmed.dyndns.org/ is still up.
- cr3cr3 2y agoYeah, and http only :) It would be hilarious if it had invalid cert.
- agumonkey 2y agopardon the side question, what is this trend of rewriting http in hxxp ? a reflex from platforms that don't allow sharing urls ?
- batch12 2y agoI do this to defang the url to prevent unintentional clicks or automatic previewing when working and reporting on security events. Sometimes the habit bleeds over.
- agumonkey 2y agoha, makes total sense :) I might get into this habit too (and it's somehow funny how ~ergonomics can backfire)
- sshine 2y ago(2011)
- deleted 2y ago[deleted]
- lionkor 2y agowhy trust the others and not Achmed?
- ithkuil 2y agoHe's too honest
- cpach 2y agoAFAIK, major browser vendors trust any Certification Authority that follows the Baseline Requirements of the CA/Browser Forum. https://cabforum.org/working-groups/server/baseline-requirements/ https://cabforum.org/working-groups/server/baseline-requirem...
- emmelaich 2y agoSee comment 13.
- hulitu 2y ago> why trust the others and not Achmed? Because, "trust us". Seriously, Google, Microsoft, Cloudfare, etc. at the same level as Achmed. The only thing Achmed lacks is marketing.
- rich_sasha 2y agoI get the sense it's not serious, but is there any more context?
- nindalf 2y agoFrom the thread it seems like they’re poking fun at browser vendors adding untrustworthy CAs to their trust store and not removing them even for egregious violations. Their point is that Honest Achmed is at least as honest as some of the other CAs they’ve allowed in. This issue was closed a few times because Honest Achmed hadn’t completed an external audit. It was reopened each time by users who pointed out that audits were redundant if Achmed quickly issued a tonne of certificates and became too big to remove. In other words, this issue is an implicit critique of browsers certificate policies.
- viraptor 2y agoIt was written around the time one of the CAs got dropped for signing certificates they shouldn't. (I wanna say it was DigiNotar, but that was a long time ago) Edit: it was Comodo https://en.m.wikipedia.org/wiki/Comodo_Cybersecurity https://en.m.wikipedia.org/wiki/Comodo_Cybersecurity who allowed an affiliate to grant 9 bogus certs. (Which is probably the "cousin" part of the joke)
- deleted 2y ago[deleted]
- ramon156 2y agoAm I the only one that understands 10% of what's going on? Obviously they won't add his CA, and there seems to be some other links to joke requests, but what am I missing?
- nilsherzig 2y agoThey are poking fun at the seemingly random (and non-trustworthy) companies which are allowed to issue root CAs and how hard it is to remove them if they reach the "too big to fail" status.
- bilong 2y ago[flagged]
- deleted 2y ago[deleted]
- resonanttoe 2y agoFor those looking for more context - If memory serves it was in response to https://en.wikipedia.org/wiki/Comodo_Cybersecurity#Certificate_hacking https://en.wikipedia.org/wiki/Comodo_Cybersecurity#Certifica... and the various controversies around it. Honest Achmed has been one of my favorites for as long as its been around.
- fmajid 2y agoAnd also Symantec, and now Entrust. All of these CAs have incredibly sloppy vetting procedures and/or control over their resellers. In many cases they didn't even check CAA records to see if they'd be authorized to issue new certs, even though it has been a requirement for years. They had one job, and failed abysmally at it, relying on their too big to fail status. You can feel the frustration of people like Adam Langley at Google over his inability to bring the banhammer to bear fast enough on those clowns.
- deleted 2y ago[deleted]
- burgerrito 2y agoMeta question: where do people find these kinds of funny stuff??
- lionkor 2y agoUsually sharing between friends, communities, etc.
- TazeTSchnitzel 2y agoFront page of Hacker News
- cpach 2y agoI’d say this one is a classic.
- imadj 2y agoPreviously: Bug 647959 – Add Honest Achmed's root certificate - https://news.ycombinator.com/item?id=2463762 https://news.ycombinator.com/item?id=2463762 - April 2011 (114 comments) Bug 647959 – Add Honest Achmed's root certificate (2011) - https://news.ycombinator.com/item?id=10839315 https://news.ycombinator.com/item?id=10839315 - January 2016 (68 comments) Add Honest Achmed's root certificate (2011) - https://news.ycombinator.com/item?id=35490740 https://news.ycombinator.com/item?id=35490740 - April 2023 (25 comments)
- axus 2y agoThis was closed as a duplicate of https://bugzilla.mozilla.org/show_bug.cgi?id=233458 https://bugzilla.mozilla.org/show_bug.cgi?id=233458 , which was the predecessor to LetsEncrypt
- netsharc 2y ago[flagged]
- deleted 2y ago[deleted]
- deleted 2y ago[deleted]
- savs 2y ago[flagged]
- fancyfredbot 2y agoIt would have been funnier if they implied the dodgy CA was racist. If the joke itself is racist then a typical reaction would be to consider it less funny.
- savs 2y agoThe ability to find humor in taboo topics is actually a sign of cognitive flexibility and social intelligence.
- salviati 2y agoIt's not like people condemning the choice of the name are unable to find the humor. We do find it. We are briefly entertained. Then we pause and ponder. Is it a good idea to use a negative stereotype in a joke? Don't we run the risk of confirming the stereotype even more? We then find out that our answer to that question is "no". And we bring up the issue with other people. There is no "inability to find humor" at play here.
- fancyfredbot 2y agoFinding humour in racism may indicate any or all of: 1) cognitive flexibility 2) social intelligence 3) racism ;-) Dodgy Dick would have been funnier.
- deleted 2y ago[deleted]
- m3047 2y agoI'm getting warnings on an old Macbook Air that the Firefox CA certs are going to expire... except the OS is too old to update to a newer version. Oh noes! Do I really care? That would imply I trusted CAs in the first place... all of them.
- hulitu 2y ago> Do I really care? Firefox will not connect to web sites when certificates are expired.