9 ms·
F-Droid site certificate expired
- Bender 1y agoLicaon_Kter @licaon-kter 4 hours ago Maintainer Looks like while we have new certificates ( https://monitor.f-droid.org/services/tls-certs https://monitor.f-droid.org/services/tls-certs ) rotation failed. :( They acknowledge rotation failed but it is still failing [1]. Perhaps something to do with how certs are rotated on their CDN? [1] - https://www.ssllabs.com/ssltest/analyze.html?d=f%2ddroid.org&latest https://www.ssllabs.com/ssltest/analyze.html?d=f%2ddroid.org...
- xantronix 1y agoWould not surprise me. Although it looks like F-Droid is hosted with Hetzner, I have encountered more than one failure to rotate certificates on account of Linode API changes, requiring manual update of the Python Linode API client to resolve.
- jimmaswell 1y ago> API changes This should be an oxymoron. We've forgotten the point of an API as a profession and it's downright shameful when something this important breaks needlessly. Would it have been that hard to just keep supporting whatever API calls were in existence as e.g. "v1" and put their new stuff in "v2"?
- gethly 1y agoBecause those ephemeral LE certificates are such a great idea...
- jffry 1y agoCertainly with yearlong or multi year certs nobody of note ever forgot to renew them, right? https://hn.algolia.com/?dateEnd=1416268800&dateRange=custom&dateStart=946684800&page=0&prefix=true&query=cert%20expire https://hn.algolia.com/?dateEnd=1416268800&dateRange=custom&...
- shaky-carrousel 1y agoIt is, if your objective is to closely centralize the web. If you make https mandatory, via scare tactics, only people with certificates will have websites. If you make ephemeral certificates mandatory by taking advantage of a monopoly, then only big SSL providers who can afford it will survive. Then, when you have only two or three big SSL providers, it's way easier to shut someone off by denying them a certificate, and see their site vanish in mere weeks.
- KetoManx64 1y agoGreat explanation and very apt for out time when we regularly hear of people being banned/debanked/jailed for their political views in western countries.
- octoberfranklin 1y agoYeah WebPKI is basically perfectly designed to facilitate deplatforming.
- schoen 1y agoThe web PKI is certainly a potential point of failure in online communications, but fortunately there is almost no history of certificate revocation over content disputes. The biggest targets have been domain name registrars and CDNs. Let's Encrypt has emphasized that it doesn't have the resources to investigate content disputes (currently, it's issuing nearly 10 million certificates per day, with no human intervention for any of them) and that having to adjudicate who's entitled to have a certificate by non-automated criteria would throw the model of free-of-charge certificates into doubt. Meanwhile, encrypting web traffic makes it harder for governments to know who is reading or saying what. (Not always impossible, just harder.) Without it, we could have phenomena like keyword searches over Internet traffic in order to instantly determine who's searching for or otherwise reading or writing specific terms! I'm very aware that it's still easy to observe who visits a particular site (based on SNI, as someone else mentioned in this thread). But there's a chicken-and-egg problem for protecting that information, and encrypting the actual site traffic is at least the chicken, while the egg may be coming with ECH. Overall, transit encryption is very good for free expression online, and people who want to undermine or limit online speech are much more likely to be trying to undermine encryption than to promote it. The biggest thing that Let's Encrypt in particular does to mitigate the risk of being unable to serve particular subscribers is to ensure that ACME is an open protocol that can be implemented by different CAs, and that it's very easy for subscribers to switch CAs at any time for any reason. The certificate system is more centralized than many people involved with it would prefer, but at least it's avoiding vendor lock-in.
- kelvinjps10 1y agoIdk if it's related but this week when I tried to use it fdroid on my phone it wouldn't resolve I had to reinstall the app
- mysteria 1y agoTheir CF mirror is still up. https://cloudflare.f-droid.org/ https://cloudflare.f-droid.org/
- tiahura 1y agoPerfect timing.
- NewJazz 1y agoImperfect timing
- rig666 1y agoI was just trying to learn how to use dfroidcl last night on termux and kept running into this error. I thought I was doing something wrong.
- keysdev 1y agoWhat is dfroidcl? Nevermind. Found it. https://fazlerabbi37.github.io/blogs/fdroidcl.html https://fazlerabbi37.github.io/blogs/fdroidcl.html Couldnt find in ddg though.
- qingcharles 1y agoFixed now.
- SillyUsername 1y ago[flagged]
- tomsmeding 1y agoHonestly, someone coming in unasked and trying to get you on the free plan of their own product, is kind of rude.
- bstsb 1y agoehh i think it's different when they're offering an otherwise paid service specifically for open-source projects. like Cloudflare with Project Alexandria
- deleted 1y ago[deleted]
- echelon 1y agoF-Droid is on a free tier of an open core, but not fully FOSS product. A product that is publicly listed on the stock exchange, at that! They're throwing stones in a glass house. It's not like their purity gets them anywhere. Google is kicking open software (already hidden and scare walled) off their platform soon and nobody will have F-Droid without permission from Google. It's better to be pragmatic and focus on the battles that matter. Like the one against Google.
- pas 1y agoThings are "scare walled" because things are scary. Just because something claims to be OSI-fucking-open-source doesn't mean anything. It's better to be pragmatic. Agreed. The developer community needs to get its shit together if it wants to have carvouts compared to the other ~99.9999% of users.
- echelon 1y ago> Things are "scare walled" because things are scary. It's 100% about power. Imagine if websites were scare walled. If Microsoft had owned the Internet, that might have happened. Websites can do "scary" things, after all. You can buy guns and knives and drive 60 miles per hour. You can give your banking information away. So many things scare the user less than Google does. Not to mention you have to go five settings deep to untick a setting to even enable it. Again, I reiterate: It's 100% about power. We should stop being afraid, we should stop trying to "protect the children", and we should stand up for our rights.
- snvzz 1y agoKind reminder you soon won't be able to install anything from f-droid anyway, without Google's signature, due to the new restrictions on "side loading".
- its-summertime 1y agoOnly applies to Google certified devices
- Citizen_Lame 1y ago"Only"? Isn't this most of the Android phones?
- snvzz 1y agoAnd all of the ones that work with banks and other apps people absolutely need to have, in order to function in society. It's bad.
- its-summertime 1y agoThere are bank apps that work on non-certified devices
- greyw 1y agoThats great but I need my bank app to work not some random one
- its-summertime 1y agoYes, but worth noting, "device" in this context means hardware and software combined. Custom ROMs et al make a device not certified