The Impending Doom of Expiring Root CAs and Legacy Clients
scotthelme.co.uk
scotthelme.co.uk
My last TV worked great for about 12 years. No way Panasonic would've kept supporting it that long.
Honestly, the thing I hate most about smart TVs, especially budget-conscious ones like the one I bought, is they have terribly slow processors so just to turn on the TV takes like 12 seconds. My old TV had a picture up within 3 seconds of turning it on.
Does any manufacturer make a good TV, or are they all smart now?
As long as you're using binaries that were compiled by Google I wouldn't trust them one bit.
If you use LineageOS on your TV you might be a little better off.
On the plus side, it was possible to disable many of the smart features once I discovered the telnet capability. :D
On the plus side, my 10 year-old laptop still finds a use as an access point/firewall for all those things. :D
Needless to say, I’ve been incredibly frustrated with my search.
They also support CEC so if the devices you're plugging into them support CEC you can just put the TV remove into a drawer and not worry about ever accidentally triggering the SMART features.
You may want to be careful with this. On Amazon Kindles when you connect to WiFi it downloads ads and will keep showing those same ones forever if you never reconnect and let it fetch newer ads. Seems the TV doesn't do it yet, but it could be added in a firmware update.
Unrelated, what do you even need firmware updates for on what is effectively a dumb TV?
Also: the new smart TV bootloops if it can't connect to the internet for more than a couple weeks at a time (it wants to refresh its screensaver ads).
You can run, but you can't hide.
That said, when companies price the ad-free premium at 1000x the expected ad revenue, it gets aggravating again.
There's also the funny issue where people who can afford to pay extra for the no-ads option are exactly the people that advertisers want to show ads to. If the no-ads option is $5, then you're left selling ads with a target market of people who can't afford or don't want to spend $5, and that ends up driving down your ad revenue. A large gap between the expected ad revenue and the price of the no-ad option helps mitigate this effect.
What kind of support does it need? Isn't it just an HDMI cable?
I wasn't alone in having this problem -- the support forums were overflowing with outraged threads about this. Support would give non-answers, wait for someone to say something objectionable, and then use it as an excuse to lock and delete the thread. Rinse, repeat. They had it down to a science.
To address your question, I think they’re all “smart” now. I ended up getting a low-end Samsung 4K a few months ago and it’s been good so far. It starts up very quickly, maybe 1-2 seconds. We use it exclusively with an AppleTV because of privacy / advertising concerns that have been raised. I’m just waiting for the day when all TVs require a working internet connection and we have to start hacking their hardware and software to protect our data.
Also, watch out for clueless^helpful friends and relatives who try to “fix” your TV’s WiFi.
I'd probably say ~helpful~clueless instead though
Couldn't you just change the wifi password?
1. Normal Traffic
2. Guest
3. Security Devices (Camera's, and other Home Automation)
4. Media Devices (Roku, FireTV, Smart TV's, etc)
media devices only have access to my home Plex server and the internet nothing else
What about factory reset?
You know, I've wanted something like this as well for a while. I know next to nothing about startups or companies, but I wonder how hard it would be to create a hardware startup around this. On one hand, you arent really designing anything new, you're more or less creating a version of an existing product, with existing technologies, except removing undesirable parts. On the other hand, I have mo idea how someone could get started without previous experience in TV design / manufacturing.
If the hardware is a commodity and the market is for a bare-bones, self-serviceable “just a TV”, then the startup should have significantly lower engineering costs and benefit from the low component costs. Given that people on this thread are stating that they would pay a premium for such a product makes it seem even more viable.
Maybe other people have different “serviceability” definitions, but I once replaced the main board of a broken Vizio smart TV —- there were only two components —- a power board and the main electronics board. The hardest part was tracking down a replacement board, but $35 and a few screws later and I had a working TV again. That met my definition of self-service.
Suppose end consumers think fixing this is worth $50 but not worth $100. If the outfit selling a "SmartTV" gets $80 lifetime value from the "SmartTV" features like forced advertising and margins are slim you probably find you can't offer this "dumb TV" for $50 extra without losing money, and you have no customers and go out of business.
On the other hand, it could go pretty well. We know advertisers see people who buy premium products (which such a "dumb TV" would be since it costs extra) as more valuable in a lot of categories, so maybe you charge $50 extra for the dumb TV and - as it takes off - that undercuts the advertising income of the existing products, so they have to raise prices to remain profitable and that actually improves your affordability compared to the market. Or else they make advertising even more intrusive and pervasive to keep the revenue up, and it makes your $50 premium appear a bargain by comparison for those sick of advertising.
* You can't compete on price because the TV guys are selling access to the data they collect for ad targeting / attribution.
But don't let anyone stop you from doing it. None of us thinks this is worthwhile, so you might be on to a Thiel Truth.
I do not understand why so many other markets have a number of luxury/craftsman brands and in computers we only have Apple. Cars have tons. Even woodworking has 2 built-to-last brands and 2 others that like to flirt with that moniker.
You will have to pay though, if you want the company to stick around. If you buy something that lasts 3x as long then they get less revenue from you, and the smaller volume means every sale includes paying off the initial R & D.
I recall when Lian Li first came onto the scene and the notch-up in ergonomics of computer cases that followed. Maybe we need something like that for consumer electronics.
The problem is that people like small and clean, which is where Apple excels (to the exclusion of accessibility), so I wonder what bomb-proof consumer electronics built for modification would look like.
Starfleet technology. Sleek and sturdy, but opens up when pressed the right way, and generally can be completely disassembled with ease, have pieces of it replaced, and then put back together.
It's fictional, but it shows the way.
Personally I'm trying to get my hands on the SDK for the software that runs in the driver chip (does the OSD and the scaling and everything else), because I think there's a lot of potential there. But boy it's like pulling teeth.
Similarly, the Exploiteers (née GTVHacker) have done quite a bit of reverse-engineering of the stock boards, so you can just fix the broken-ass firmware they ship with.
Ultimately I'm picturing something like the WRT54G, a single modem that the community coalesces around, to the point that a decade later, third-party firmwares have become such a force that manufacturers build hardware specifically to run it.
Do these boards support HDCP?
Is this something that is practical and commonly done, or only theoretically possible?
I have an older model Sony 4K TV (pre-Android) that is so slow now after its recent firmware updates that it responds to button presses only after 2-3 seconds. It's unbearable!
I'd love to be able to just pop in a new driver board and refresh the TV, but I've never heard of anyone doing this kind of thing before.
Right now I'm working on a project with some M315DJJ-K30 and MV238QUM-N20 panels, but parts are still in shipping so I don't have anything to show for it yet.
I've stumbled into a pile of panels and I have several orders of different driver boards on their way to me from Shenzhen, but nothing in-hand to say if they work yet.
We're not there yet, but we're on our way. My Philips Ambilight TV pops up a warning every few weeks to remind me that I should connect the TV to the network to benefit from all the smart apps it has bundled. Immensely frustrating.
I have -up2now- not seen 1 device, where the combination of HW/SW was capable of offering ethernet to the Device OS.
AFAIK, no (mainstream) PC/Embedded/Mobile graphics chip/firmware/driver combination supports this. Please do indicate a counter-example, if you know of one.
I consider that unlikely to change too, since Ethernet is limited to 100Mbit over HDMI. Gigabit (Wifi) ate that lunch.
Outside of "Device-Collections" from e.g. B&O, that might use that comm-channel to have a "guaranteed communication backend" available, I see no real (commercially) interesting reason for implement it.
Having said that, I'd be very happy, if GFX-card/TV vendors started implementing the optional parts of the HDMI spec, like CEC,ARC, and Ethernet. I'd find use for it.
But the average person wouldn't, and "fickle hacker news user" is not a wide open market.
Despite the common trope, "selling data" doesn't lower the price of consumer devices. You only see price-less-than-cost plays when companies are trying to buy market share (think Alexa, Google Home, early Kindle, etc).
"The greater strategy is I really don't need to make money off of the TV. I need to cover my cost."
and
"It's not just about data collection. It's about post-purchase monetization of the TV."
[1] https://www.theverge.com/2019/1/7/18172397/airplay-2-homekit...
[2]https://www.businessinsider.com/smart-tv-data-collection-adv...
In practice I suspect many of these systems barely function, each is a special snowflake, and that any bad input from controller could result in fire or water damage to your house.
So maybe TVs and fridges are a good place to start and we should give washing machines a while to figure it out.
These days won't come. What will happen instead is TVs will start coming with embedded SIM cards for cellular data connection (prepaid or otherwise negotiated between TV vendors and telcos), and then we won't have any choice in the matter as consumers, short of opening the box up and snipping the antenna (and losing warranty in the process).
These days are already here. My TCL bootloops if it doesn't have an internet connection to download ads from, and if you call support, they'll happily walk you through getting it connected to the network.
At the time they were dumb panels, not sure if that is still true today. You had to understand what you were buying, as some of these displays are designed to show static content.
You might want something like a Philips BDM4350UC then [1] - brought from the 'large monitor' section of your favourite IT retailer. No smart features whatsoever (and no tuner and no remote).
Unfortunately, they only go up to 43-inch - large for a monitor, but not exactly Frank's 2000-inch TV.
[1] https://www.philips.co.uk/c-p/BDM4350UC_00/brilliance-4k-ult...
To all the folks reading at home... I would remind everyone that a TV is not a monitor.
I got a relatively inexpensive LG 43in TV to use as a desktop monitor. I've had issues. Beyond the usual "make sure your graphics card actually supports 4K" and such, you also need to take some time to dig through the TV settings when you are using it on a PC.
In particular, you definitely want to turn on "game mode" or whatever it will be called. This turns off the internal image processing that can add hundreds of milliseconds of lag to the display output. You'll also need to find the settings to turn off the overscan. Many TVs will, by default, zoom into the center of the image, cutting off the edges a little.
I've mostly gotten over the other issues with using a TV as a monitor (color settings and such), but if you want to save yourself some hassle, just get an actual monitor.
For my computer, I use a 32" LG 4K monitor, and it's great. No 'smart' features found there.
But I can't find a 4K monitor in the 42-50" range that has multiple HDMI inputs that is not incredibly pricey (e.g. broadcast/commercial realm) I could use in my living room.
I'm wary of using HDMI AVRs today because they add input lag.
My receiver is older and doesn’t have HDMI in, but this solution works well with the TV I have. When a device is turned on, the TV wakes up and switches to that input. If the PS4 is on and I turn on the Apple TV, it will auto-switch. I never need to touch the TV remote at all since the devices go to sleep automatically, which is nice. Apple TV remote handles the receiver volume, and the audio input never changes on the receiver, so I don’t need the TV or receiver remotes at all.
It has 4 HDMI inputs and a USB-C with display port. It even has a remote.
It's an IPS panel though. From what I hear not everyone loves those.
Amazon has it in France for around €600.
[0]https://www.lg.com/us/monitors/lg-43UD79-B-4k-uhd-led-monito...
The technology is still new enough that getting the cheapest 4K screen you can find is still a really bad deal.
I really think he's massively exaggerating. His statements might be more rationalisation because people hate it, but they just want to squeeze more money out of people. But I can't believe that showing some ads and fingerprinting content would net them more than $100 over the life of an average TV. I'm sure there are plenty of people who would pay more than that for a no-ads, no network connection required version.
At most they come with a QAM tuner. Some are a display only. None have smart TV spyware from my browsing their offerings.
Fixed a typo
For example, I am using an LG LG43UD79 currently. This is a 42.5" IPS 60hz 4k "monitor" at a decent price (I think I paid $399 at costco.) it has HDMI and USB-C inputs, but no smart functionality at all, no tv tuner, etc. The color and picture are pretty good after calibration. I normally use the monitor for programming, web browsing, chatting, etc but also do some very light gaming and it is fine for that.
I recommend this monitor and am hopeful that there are some more modern equivalents of it when I inevitably upgrade in a few years as I love the large monitors for getting work done.
I have a Samsung smart TV for work tasks that has the most annoying behaviors built into it. It always insists on "identifying" an HDMI source which it can't do because I've never put it onto my network. Roku doesn't appear to do this kind of data exfiltration.
Buy a tv, then in 5 years when I need more functionality I simply upgrade the "smart module" for $50 instead of having to replace the entire TV
Of course they would then probably try to make a "as a service" subscription bullshit and it would be worse than we have now so never-mind I retract this comment
I’m guessing they have a decently powerful processor to power WebOS in there.
Servers, as Scott explains, are supposed to present a "chain" of certificates, in practice it's one leaf and then just anything else that might be useful for clients to assemble a trust path. If you do this everything works.
But lots of servers are misconfigured and present only the leaf certificate, not least because a lot of older software makes configuring the chain needlessly confusing/ complicated and it often "seems" to work anyway in some client software.
Given just a leaf, and a set of roots it trusts, a client can't make a useful trust decision, there's a gap. One option in this circumstance is to just give up and just tell the client's user this isn't secure. That's a poor UX.
Another idea is called AIA Chasing, many popular web browsers do this. When it can't get from the presented certificates to a trusted root the browser inspects the Authority Information Access field of a certificate to find a URL, hopefully this URL points to an intermediate certificate that plugs the gap. A problem with AIA chasing is that it reveals information about your browsing to the CA who otherwise have no reason to know. This privacy concern led Mozilla to reject AIA Chasing.
Yet another idea is to cache intermediate certificates for some period of time, then use that cache to fill any "gap" when making a trust path for other servers you connect to. This causes hard-to-predict errors for users, maybe the funny cat video site you enjoy works fine... unless you try to visit it first thing after turning on the PC. It can potentially represent a privacy risk within a session.
So ultimately Mozilla's workaround in current Firefox is to give Firefox a fairly complete set of intermediates, just as if it had cached them already. Essentially that right hand "embedded in browser" part of the diagram extends left to the intermediates too.
It made that happen through two means: Firstly m.d.s.policy required all root CAs to tell it about all unconstrained intermediates they had ever created, which was itself a revealing process because there sure are a lot of (mostly older) garbage intermediates that clearly are untrustworthy and shouldn't exist. More recently Certificate Transparency means any intermediates still in use must be in the CT logs because otherwise the leaf certificates won't be accepted by those logs, so Mozilla can "just" fetch that data.
I've certainly expirenced the missing "missing intermediate cert" problem before. It is a bit of a nightmare to debug.
1. Had issue, raise support ticket: TLS not working
2. Ticket closed as can't reproduce
3. Try myself again locally, also can't reproduce. Hmpf!
4. 2 months goes by..
5. Experience same issue. Debug more carefully locally, use openssl go get proof of missing intermediate
6. Raise support ticket with platform team, then try to convince them that just because most people are not affected, it still needs to be fixed!
https://www.ssllabs.com/ssltest/
Also this lets you out-source the decisions about what's important versus what really doesn't matter to somebody else, and unless you've got (or can hire someone who has got) hours per week to read and digest work in this area that's likely going to mean better security in practice.
The challenge in my experience is to resolve the issue for internal sites, the thousands of internal tools and test domains from every department. None of the public tools can reach them.
Much more intel, better performance and a better UI.
No affiliation, just a fan since day one.
The ecosystem needs to become a lot more robust and user friendly in general. Unfortunately, I’m just a user of certificates not a cryptographer, so I’m not really qualified to design security critical aspects of the system, but here are some rough features that I’m looking for:
- certificate warning date: a time period defined like expiry date that indicates that clients should warn of impending expiration but still click though
- Make it easier for people to acquire and renew certs. Let’s encrypt is an amazing start here, but it’s not a universal solution yet
- Formalize a way to solve the key distribution problem described in the article. Again, I’m not a security expert, but perhaps embedding a “replaces” concept into a certificate would work.
> certificate warning date
If this is user-visible then for most companies this would be nearly as bad as expiry, and if it's not user visible then it's not useful.
> Make it easier for people to acquire and renew certs
Let's Encrypt pretty much solves this problem. The places where it doesn't work are companies that lock down the use of that sort of software. I don't think there's an easy way around that.
> Formalize a way to solve the key distribution problem described in the article
This problem isn't just the problem described in the article, it's _THE_ Key Distribution Problem. It has a Wikipedia entry, it's a chapter in most security textbooks, it's a lecture in most cryptography modules at universities. It's a _hard problem_. The practice of including Root CA certs on devices is the best thing we've come up with yet that has the security and scalability trade-offs necessary.
If the "replaces" concept was viable in the general case I think we'd have likely implemented it, but I suspect it's too vulnerable, and likely only pushes back the problem.
Let's encrypt is definitely in this vain, however I think it needs to be the point where software defaults to user friendly behaviors like auto-renewal unless explicitly told not to. This seems like it could be address in standards making process, but maybe that's the wrong venue.
I've worked at startups with fully functional PKI. It's almost trivial to achieve, as long as you've got configuration management over all the servers (ansible, salt and assimilated).
On the other hand. I've worked at a large bank trying to make TLS work across the firm and it was a mess. There was no motivation to have any automation around certificates management and no control over server configurations. One simple issue for example, CA on linux are managed by the ca-certificates package, all it takes to keep TLS working is to upgrade that package every couple years "apt-get upgrade ca-certificates". Some servers haven't had upgrade since 2015. It wasn't particularly difficult to get 10k servers from 5 departments upgraded after handing them instructions to do so, but of course a few other departments won't act until things break (and sometimes still won't act in spite of active incidents).
Any Internet-connected device is, in fact, a server, and must be seen and managed as one. This means strict control of installed services and, first and foremost, regular updates of all its software components (including firmware). If you acquire and install such a server which either can’t be updated or one which you know, realistically, won’t get any updates six months after installation, that’s asking to lose.
But coming back to TLS again: even if the old devices have an up-to-date root store, they typically have an outdated TLS stack which does not support TLS 1.2 ¯\_(ツ)_/¯ and this one is probably even harder to update. And since most of the companies want to drop TLS 1.1- support on their servers soon, this should also doom those outdated devices apart from the root stores issues.
Of course in some cases like domains it's necessary since the domain can be transferred, but this is solvable by DNSSEC+DANE.
If it's compromised, and you know, then it should be revoked -- if your only mechanism to revoke it is waiting some amount of time (several days, months, or even a decade) you have a pretty big problem.
If you don't have a way to detect if it's compromised, rotating a precaution almost makes sense -- but then the valid time should be very short. I'm not exactly sure how short, but definitely the decade or two used for CA certs is too long. Make it shorter than a year and automated renewal becomes necessary, but if you have that mechanism why not check for revocations?
The only other reason I can think of to expire non-compromised certificates is to force them to be regenerated to use newer signature algorithms, but even that's difficult to predict. We're currently using SHA-2 for PKI, but is that still going to be reasonable in 5, 10 years? Someone could figure out a potential weakness at any time, which would start the move to something else.
Actually the correct mental model is a graph of public keys and the lines between them (joining two nodes directionally) are the certificates.
So although we traditionally handle the root trust set as a bunch of self-signed certificates, those certificates are largely unimportant, what's vital is the public keys baked inside them.
As a result what makes older roots obsolete is not a signature algorithm, but the type and size of key chosen when they were created, that key is in a very real sense the root.
This AddTrust root for example was 2048-bit RSA. You can use that size of RSA key today for your funny cat video site, no problem, but it's clearly an inadequate choice for a CA root. Fortunately roots like this are gradually expiring.
If I figure out how to build a machine that can break 2048-bit RSA keys for $10M per key it makes no sense to target your cat videos. But a CA root is an attractive target. So we'd like to have more margin for the roots not the same or less.
Some years ago Mozilla finally prohibited 1024-bit RSA keys in roots. Some of the oldest roots in the business were 1024-bit RSA, which today would not be considered acceptable even on your cat video site, but when those roots were created 1024-bit RSA seemed safe enough.
In 5-10 years you'd probably want as much as possible for roots to be the more compact elliptic curve public keys, maybe there will be some better (more secure) curves in use by then, maybe not.
Again, roots are already cross-signed and the article points out they still take 2+ years to pass other validity checks for root adoption. Even if they "virally" propagated in this manner after all those checks passed, there are plenty of devices that are only powered on once a year or less; there are a lot of devices whose support lifetimes for any upgrades at all are less than 2 years (that's a specific call in the article: we need security support lifetimes extended to decades at least, probably).
If they propagate "virally" you have a lot of questions of whether or not a device will even see that there is an updated certificate. Not every user or device visits a web page in a certificate chain to any given root routinely much less ever.
Comments to this article even point out that there is a semi-viral update process already in place in most browsers called AIA chasing, where certificates may point to URLs to look up their parent authorities, and Mozilla intentionally doesn't AIA chase because it's very definitely a privacy risk, even if you don't agree that it is a security risk (bad certificates sending you to bad URLs). The security risk is why the browsers that do AIA chasing only allow it for intermediate certificates and will not trust new roots found by AIA chasing.
For embedded devices - it's not just smart TVs but all IoT devices! - I think that the solution is a legal requirement: a condition of a device being able to be sold on the EU / US market must be the commit of the whole source tree and build chain including any and all key material for signing firmwares to the national library or other government-run secure escrow, to be released to the public once the manufacturer discontinues the product support. Similar to like you can't sell a product without adhering to the CE and electrical safety standards, manufacturers should not be able to sell products without having them certified for IT safety and e-waste/"planned obsolescence" issues!
Report URI should lead with this (it's not even mentioned on the front page)! It's super useful for every site, I can't think why anyone wouldn't want this. CSP monitoring on the other hand, which seems to be their focus, is a much harder sell, a pain to setup and maintain, and a bit questionable value in my opinion.
https://w3c.github.io/network-error-logging/#introduction
https://developer.mozilla.org/en-US/docs/Web/HTTP/Network_Er...
By definition you have to run such a service entirely separate from your own infrastructure: you should use a different CA than your other site(s), a different domain name for sure, preferably a different infrastructure host etc. It makes a lot of sense to use something like the Report URI service for it.
This fits the prevailing narrative, and for all I know it's true, but Scott does not in fact illustrate it.
The "similar data" to a table of all Android API versions versus popularity turns out to be a chart of recent iOS versions in which everything that isn't current is just grouped as "Other" at 16.28%
Maybe if we ungrouped "Other" it would prove Scott's point, maybe not, we shan't find out answers in his article. If those "Other" iOS users are all running 10.3 it's a very different story than if they're on iOS 6...
"iOS 13.3",27.03
"iOS 12.4",16.19
"iOS 12.3",14.2
"iOS 13.1",10.22
"iOS 12.2",7.89
"iOS 12.1",4.16
"iOS 13.4",4.02
"iOS 13.2",2.68
"iOS 10.3",2.31
"iOS 11.4",2.14
"iOS 9.3",1.94
"iOS 11.2",1.03
"iOS 12.0",0.86
"iOS 13.0",0.82
"iOS 11.0",0.81
"iOS 11.3",0.72
"iOS 6.0",0.45
"iOS 10.2",0.4
"iOS 11.1",0.32
"iOS 7.1",0.18
"iOS 13.5",0.17
"iOS 10.1",0.17
"iOS 9.1",0.15
"iOS 7.0",0.15
"iOS 10.0",0.14
"iOS 6.1",0.13
"iOS 5.1",0.12
"iOS 9.2",0.12
"iOS 8.4",0.11
"iOS 8.1",0.1
"iOS 8.3",0.06
"iOS 9.0",0.06
"iOS 5.0",0.04
"iOS 8.0",0.03
"iOS 4.3",0.03
"iOS 8.2",0.02
"iOS 3.2",0.01
"Other",0.02Devices from 10 years ago are _already_ useless online.
Not only are the root certificates completely expired, but let's see which protocols does an openssl 0.9.8 build from a decade ago have in common with, say, current Gmail's IMAPS server: NONE.
Of course, we still have people working on our stuff. If it were some abandoned hardware product I could see this being a disaster.
I'm pretty good with TLS, but could use more hands-on time with openssl and PKI, especially a deeper understanding of certificate chaining issues. Would be interesting to know if the training is targeted at "total beginner" or "intermediate looking to be advanced"
Does it? Because that is the cause of the 'impending doom' from TFA
https://en.wikipedia.org/wiki/Certificate_revocation_list
https://en.wikipedia.org/wiki/Online_Certificate_Status_Prot...
I'll just mention glassfish here in case someone in the near future wonders why this or that application is failing: it has it's own cert store (different from the JVM one), and it is a bit out of date. Yes, I just ran into a github project whose last commit was 3 months ago (march 2020) and that wouldn't work with LE certificates, all because deep down the docker matrioshka, there was a glassfish with outdated certs.
Modern TVs really seem to ruin the video even though they are perfectly capable of just showing a color adjusted signal, quickly becomes obvious when you plug in a computer.
https://www.tvlicensing.co.uk/check-if-you-need-one
(Edited to add: Conversely, merely owning a TV does not require a license; if you're only using it as a computer or gaming monitor, and not watching [online] TV programmes on it, you should be fine.)
Maybe root certs need to expire more often so implementors have to do OTA updates.
Tin foil hat: To me, it smells more like CA’s wanted to make some cash by forcing their customers to buy certificates every so often instead of actually solving the problem and are now being bitten by their own rules.
When are people going to learn that centralized cert authorities are just for commerce and only hurt the non-commercial web?