3 ms·
People went ballistic on me a few months ago for bringing this up, but this is exactly the kind of outage that makes me really, really worried about extremely s
by kyledrake 8mo ago
People went ballistic on me a few months ago for bringing this up, but this is exactly the kind of outage that makes me really, really worried about extremely short lived certificates. https://news.ycombinator.com/item?id=46118371 https://news.ycombinator.com/item?id=46118371
- codys 8mo agoI'm not sure I follow. This outage seems like it occurred for less than 1 day. The post you link to is about having certificates expire after 45 days. What's the connection you see?
- TwoNineFive 8mo agoYou didn't read it or understand it.
- jeroenhd 8mo agoSome CAs are experimenting with shorter, 7 day certificates as well. still not an outage that would endanger anyone's ability to renew in time, but for small or extremely shitty CAs (and there are a lot of those) such an outage may take enough time to cause issues in theory I guess?
- shabloney 8mo agoIt doesn't have to be small or more shitty than average. If Google has a compliance issue and can meet it in 8 hours then its a pretty clear one. They could have an issue that needs round trips of discussions with auditors before resuming. etc. I'm not familiar with 24/7 auditor services.
- philprx 8mo agothat's roughly 1/45th probable downtime window = 2.22% downtime probability (yeah, it's a figure not a real proba ;-) ) compared to say, roughly 1/365 probable downtime window for a 398 days cert lifetime = 0.25% downtime probability let's pray you don't need to rotate when it's down... Dan Geer famously said: "Dependency is the root cause of risk"... PS: even stricter shortlived durations in some context: Internal/Private 1 – 7 days Corporate VPNs, Internal apps Ephemeral 5 mins – 1 hour Docker containers, CI/CD runners
- kmm 8mo agoThat's only if you delay renewal until the last day of the lifetime of the certificate. If you renew at day 30 you'd only get in trouble if there's more than two weeks of downtime.
- Analemma_ 8mo agoYou’re supposed to renew your cert way in advance of the expiration time. For 47-day certs the general expectation is that you renew them monthly, so in the worst case you’d need more than two weeks of CA outage before anything went wrong.
- TwoNineFive 8mo agoYour license to website has been revoked.
- jacquesm 8mo agoYou're joking, but still: that's one very possible outcome of both requiring centrally issued certificates for security reasons and browsers refusing to display websites without. Effectively certificates are now a license to publish.
- devsda 8mo agoOn a PC we atleast have an out. On mobile, user certs are pretty much ignored unless opted in by apps. Even firefox allows user certs (for now) but only via an obscure hidden config. This means we cannot use self-hosted services even using a VPN with official apps without getting a signed cert.
- dns_snek 8mo ago> This means we cannot use self-hosted services even using a VPN with official apps without getting a signed cert. What do you mean by this? Any service that is designed to be self-hosted will have an app that accepts user-installed CAs. HomeAssistant, for example.
- aaomidi 8mo agoYou know there’s more than one CA?
- jofla_net 8mo agobut only one browser