5 ms·
While I appreciate your detailed answer it reads more like a inditement of Mozilla and doesn't actually address why my answer is wrong. I never said pinning cod
by throwaway2016a 2y ago
While I appreciate your detailed answer it reads more like a inditement of Mozilla and doesn't actually address why my answer is wrong. I never said pinning coding the certificate is a good idea, you are attacking a straw man. I was simply answering the original commenters question which was:
> Why can't they release a new certificate?
And nothing in your reply indicates why my answer to the question that is actually asked is incorrect.
Also, Certificate Pinning, which is the technique used here is not exclusive to Mozilla. I agree it's brittle but it's not an unusual practice. They also appear to be using certificate chaining (which is often considered best practice for pinning) since they say it is the Root certificate that expired so it doesn't appear to be a naive implementation. And again, even if it was: that's a straw man, I was not arguing for the technical merits of what they did, only answering the question asked.
Do you not remember when Let's Encrypt had a similar issue when a CA Root certificate expired and the certificates stopped working on old devices?
> the sentiment and statement you made is misplaced and false
What "sentiment", I was not making a political statement, I was answering question. And your entire post is attacking the use of certificate pinning and an open source project, which is something I was not arguing for (hence, a straw man) and does not actually refute my answer to the question asked. Furthermore:
> common knowledge at a professional level, which you may not be aware of
ROTFL, this is an anonymous account but I've been in this industry for over 25 years. You are almost definitely running code on your computer that I wrote. Never make assumptions on who you're talking to and use it for a personal attack. It's not a good idea. Also, never make assumptions that something is "common knowledge" -- you must have never managed anyone and if you have a feel sorry for your reports. But regardless, not a single thing you said in your post was new information to me, except maybe that down stream projects may be using Mozilla code for certificate pinning to run Mozilla add-ons and DRM... and if they are, that's on them because a browser is an app not a library.
- trod1234 2y agoYou asked why you may have been downvoted and I responded in good faith with my opinion based on what you communicated, that opinion is based on principle. The statements I made are mostly an indictment of Mozilla, but it does include why your statement was wrong if you look carefully at what you wrote, its not about what you were responding to. Here is the statement you made: > There is no point in pulling down the certificate, it's only used by Firefox and there shouldn't be any valid use case to patch an old version to use the new certificate, you would just update your whole browser (it would be easier and safer). Break this down. # AND #. One of the legs doesn't hold. Making this false. There is no difference in meaning between "should not be" and "no" here aside from marking it as an opinion (should/ought) which can be contradicted by real use-cases. A strawman argument is where you attack a lesser flawed argument than what was said with the implication or claim that it is the same as the first. This wasn't a strawman argument, it was about exactly what was said despite the gymnastics needed to parse your statements. The quoted statement was your opinion, and opinion is "sentiment" you relayed. I don't see why you think opinion/sentiment here is associated with politics. It can be misplaced and false at the same time and unrelated to politics. The information in the post was attacking the fact that Mozilla is attacking and removing resilient design, which is the first thing any operations person will look for. Single points of failure. Nothing said aside from the fact that you were mistaken in that one small statement you made, can possibly be construed as attacking you. Even then it is pretty wild to consider observations/statements that serve as basis for a proof by contradiction as a personal attack. > ROTFL You asked why, because you missed something. I answered and I really didn't have to. There are SOP's in professions that are common knowledge. There is no assumption in these cases, and its standard practice to tag or preface statements that are common knowledge for those that may not have it. On the developer side of the house, it is not unheard of to be siloed and not have common operational knowledge, what was said was reasonable. Hopefully this sufficiently clarified for you why you may have been downvoted. > if they are, that's on them because a browser is an app not a library. The GPL has the intent and obligations spelled out. When you make and demonstrate a pattern of abuse through destructive or diminishing changes contrary to the GPL over time, you may risk violating it. Taking actions that create the imposition of cost on legally protected rights within the GPL or inducing torturous interference through vexatious behavior is highly problematic and a question for the lawyers (IANAL). Sentiment that its on the downstream maintainers to fix issues created upstream is highly problematic.
- throwaway2016a 2y agoThe fact you not once in your reply acknowledge that certificate pinning and bundling trusted root CA public keys is actually common knowledge in desktop and mobile app community makes me thing you didn't even consider my reply. I was simply explaining why for a desktop app pulling down the new certificate doesn't make sense because updating an app to update the pinned certificates is SOP for apps that use pinning. > A strawman argument is where you attack a lesser flawed argument than what was said with the implication or claim that it is the same as the first. This wasn't a strawman argument, it was about exactly what was said despite the gymnastics needed to parse your statements. No it literally was not. It was so much not what I said I wonder if you are replying to a completely different post. And rather than acknowledge you may have misinterpreted me, you are doubling down. Also, that definition of straw man is wrong. It can also be -- as it is in this case -- attacking an argument the person never even made in the hopes it will bring the debate onto your terms. But, I'm not attacking the straw man back, once again, at no point did I advocate for certificate pinning in open source apps nor make any comment on GPL or Mozilla. My post was simply a statement on how to update apps that use certificate pinning. Reading any more into it than that is you injecting context that is not there. Have a good day. My post is net positive votes now. I will not be replying to this conversation further.
- nofunsir 2y agoCite your sources, please. So far you're incorrect.
- throwaway2016a 2y agorolls eyes sure bud Tell me, how exactly else are you supposed to update an app with a pinned certificate without defeating the whole purpose of pinning? How about Google? https://chromium.googlesource.com/chromium/src/+/main/net/data/ssl/chrome_root_store/faq.md https://chromium.googlesource.com/chromium/src/+/main/net/da... > The Chrome Root Store contains the set of certificates Chrome trusts by default. Google also bundles some certificate fingerprints with their browser. You can see right here where they are in their source code: https://chromium.googlesource.com/chromium/src/+/main/net/data/ssl/chrome_root_store https://chromium.googlesource.com/chromium/src/+/main/net/da... But according to trod1234 it is "common knowledge" you shouldn't do that... so Google and Mozilla must both be idiots. In fact, Google's Android network article has a section specifically on how to add it to their mobile apps[1]. Any app that follows that article and has a root key expire will need to push an update if they don't have backup pins. And the only way to do that is... as I said in my original reply up top... update the entire app the cert is pinned too. There are literally hundreds of sources I can find. Including the other reply to the post I replied to... which says the same thing as me but for some reason isn't being trolled. [1] https://developer.android.com/privacy-and-security/security-config#CertificatePinning https://developer.android.com/privacy-and-security/security-...