The most secure system imaginable is for your users to shut their computers and go outside. If you can’t provide security without usability, your system is worthless.
The truth is that users want products that feel secure, rather than products that are secure.
Unfortunately, the browser security nerds don't understand human psychology, and are more scared of the fact an expired cert can't be revoked (a nearly pointless edge case) versus users ignoring all cert warnings entirely, which they do now. A classic example of engineers who don't understand their users.
Of course it is - it depends on Capital-C-Context.
Sure, for the bank, the site you are supplying your credit card details, your email, etc - security is non-negotiable.
For hackernews, for reddit, and for similar sites, then security is something to sacrifice, once again depending on context.
I've trusted this certificate for the last 2, maybe 3 years. It's unreasonable to assume that 5 minutes past midnight on the expiry date, the cert turned from "completely trustworthy" to "100% certainty that this is a phish, scam or similar".
We live in the real world. Things happen.
But I agree with that comment. The one I disagreed with is:
> Security is not something to sacrifice to gain less angry users.
Maybe I should rephrase (I'm a notoriously poor communicator) ...
Sometimes (like in the cases I pointed out), the security messages and warnings must be sacrificed because the practical security either doesn't matter (like hackernews) or hasn't been compromised (like the 5m after midnight example).
That being said, I've never liked how certificates are designed to begin with. They're overly complicated for very little gain IMO.
On the other hand, if my e-mail provider's certificate is expired, there's a little more at stake, and there are other services where the HTTPS security being broken can cost me money. Those I do care about.
> There's even less at stake when it comes to the cryptographic security of some blog.
This would only be the case if ISPs were not adversarial. In the US - for most people - They are, though.
The layers of bureaucracy is a barrier to adoption of better security practices, and is all of our problem because at some point, you are using someone's website or api that is insecure because someone had to get one more approval or get someone to click one more button and did not.
- you're two minutes late, your appointment has been canceled
- but I am here for the chemio. I drove 100 miles to be here.
- Get your shit together or fuck off for the sake of everyone else. Nobody cares about all the layers of bureaucracy between you and being on time. That's your fucking problem
- Your doctor let their medical license lapse. They are legally not allowed to practice medicine until they renew it.
or a
- The hospital did not pass its mandatory inspection. We are not allowed to practice medicine here until we redo the inspection and pass it.
?
Renewing certificates isn't exactly rocket science. It's not an oopsie-whoopsie, it is a pretty massive ops failure and should be treated as such.
medical licenses don't arbitrarily expire every 3 months.
But anyway it's funny that medical licenses expire in some place.
Once a doctor, you're always a doctor, unless you do something wrong with your license and it gets revoked.
An expired license doesn't make your skills useless or you less capable.
If I had a stroke on the streets I would certainly trust a doctor to help me, even if the his license is expired (again, who let medical licenses expire? not even in USSR medical profession was so bureaucratic!)
Who gave the issuer of the certificates and the browser's vendors the right to decide if I can or can't _visit a website_ that has an expired cert?
and what's the matter?
we accept E2E encryption on chats that use TOFU, but we should "fuck off" web sites with an expired cert that hasn't changed, it's not been revoked, is exactly the same as before, providing the same level of security of before?
I don't understand this fixation, unless a lot of people make a lot of money out of this madness.
I mean , we all know that rotating passwords don't improve security, but suddenly making cert expire does?
silly.
> Renewing certificates isn't exactly rocket science
people make mistakes, problems arise, if I need that website now and it's not available because CHROME or FIREFOX or SAFARI chose so, it's a problem for me.
I'm not a baby, I'm an adult.
I can't count how many times that particular piece of information I was looking for was hosted on an old website that's only accessible via HTTP (another thing security zealots don't want you to use) or had an expired certificate.
Let me take my risks and give me a way to disable your bike wheels, I'm not Google's son.
And seriously, the entire f*king HTTPS business cannot rely on a non profit USA org, sponsored by all the usual suspects.
certs are not malpractice insurances though, they simply say that who you say are is who you say you are, which doesn't change when the cert expires.
Ids expire only to remind people to update their personal data and the picture on them.
And to remind the State to do a bit of background check once in a while, but even passports last 10 years.
I really want you to show me how this is "not rocket science". Till then kindly "fuck off".