I use it and forget Let's Encrypt is so critical to my website.
I use it and forget Let's Encrypt is so critical to my website.
The biggest concern is old Android devives. By "old", I mean devices using a version of Android from the Obama administration. Android 7.1 is the oldest version that will work, and it was released on October 4th, 2016.
At this point, roughly 6.1% of Android devices are running a version of Android that will be impacted by this change. It's likely that most of these devices are in relatively low-income countries, so depending on your audience this may be much lower or much higher. (If your primary audience isn't in a developing country, it's likely much higher.)
This change will affect you at some point after February 8th, 2024. (Specifically, you'll be affected the first time your LE cert renews after that point. If you're using one of the common clients, it will be up to 60 days after that point.) If you want, you can configure your client to support legacy devices longer, but only up to June 6th, 2024. After then, if you truly need to support very, very old Android devices, you would need to switch from Let's Encrypt to a different (possibly paid) CA.
Only you know for sure if you need to support these very old devices. Most web sites don't.
I’d be nice if this community weren’t so quick to defend planned obsolescence, especially at a 2-3 year pace.
Theres really no reason that can't be done, it's not like phones have the amount of variety as PCs and MS and Linux have both managed to handle some much older hardware.
I don't believe android apps are locked to HTTPS as a rule, though obviously a lot of them likely don't have fallbacks.
Don't get me wrong, I really don't like the whole 'disposable hardware' culture, but you can't deny there has been a huge leap in tech over the last ~7 years.
It works perfectly fine for her, it runs the two apps that she uses: Camera and WhatsApp. And the price was reasonable, only half of her weekly pension. There’s no way she could afford an iPhone 14, that’s a whole month’s income.
She doesn’t know the specs of her phone, or care.
EDIT: However, I don't suspect that iOS15 will be supported for much longer, iOS14 last update was back in Oct 2021.
Not to be too salty but that cake must have tasted worse than the video looked terrible.
About a year ago a friend of mine complimented me on a new phone, until I told him that it's my old LG, I just stopped using the case. He seemed annoyed after that. Must be because I got funny looks and giggles years back when I said I'll never buy a phone without a replaceable battery.
My laptops are both 2015 MacBook Pros.
I’m sure there’s plenty of use cases where the gains are valuable. If you’re a photographer, developer, gamer, or web browser without an Adblocker, I’m sure it’s immense. For me personally, the gains are questionable.
I have an iPad mini that's only a year or two older than that and software upgrades aren't supported, nor are there many (any?) apps available for that version of iOS
Same with my mid-2014 13" MBP. While my M1 MBP is a lot faster for things like building complex C++ code bases, for stuff like web browsing the old Intel Mac doesn't feel much different.
Compared to the incredible hardware progress between 1995 and 2005 (where a 2x increase per year was quite normal) it definitely feels like we're on a plateau since around 2010.
iPhone 7 is still a perfectly usable device but bricked now.. Stuck in iOS.
Iphone 7 got an iOS update to 15.7.7 in 2023 and its truststore contains the ISRG Root X1 certificate: https://support.apple.com/en-gb/HT212773 I am unsure which apps you cannot install but a quick look in the app store indicates that Zoom, LinkedIn, Notability, 1Password, Disney+ and Netflix all support iOS 15.7. And in my anecdotal experience I could find no app with a minimum OS requirement greater than 15.7. As far as I can tell you need to go back to iPhone 4S to find an iphone which does not support the LetsEncrypt root certificate. That device is only 11 years old, so still worse than your Android device. And I do not think there is a workaround by using a different browser like for Android.
Or they should if they are web facing. For security reasons at least.
Something like this is needed for mobile phones, and probably other electronics as well.
This "huge" difference is only at the top. If anything, the software has gotten worse... my parents hate the "new" gestures... if they didn't give the option for the old bottom row buttons it would be doubly worse.
There are many low cost Android devices about whos processing power hasn’t really improved much over the same timespan
And although iPhones have got much better it’s worth remembering how much their price has increased too (SE excepted)
For all the talk this “disposable hardware” and “planned obsolescence” issue is much more a problem on Android.
It's planned obsolescence, plain and simple. It's just surprising how frequently they obsolete things now. I fully expect them to "train" all the good little consumers out there to replace their phones every year lest most of the web stop working on them.
There is a difference between "planned obsolescence" and "not wanting to spend a disproportionate amount of development time making sure old devices work".
If 6% of Android users globally are on an ancient OS version, how many man-hours would it be sensible for my to spend testing that our systems work for them? How many of those 6% are likely to be paying customers for us?
Where could we source enough Android devices with pre-7.1 OS versions? How much time and money would that cost?
Most people don't care about having the latest specs, they want the latest features. If new features only ship to devices that are < 2 years old (like Android updates), older devices will quickly become obsolete. The hardware is still fine - I'm writing this on an almost exact 7 year old OnePlus 3 running a barely year old version of Android and the vast majority of things perform perfectly fine. Even the camera is perfectly fine even for modern standards now that I've switched to a modern camera app by tricking it into thinking my phone is a Pixel.
If we stop making old devices obsolete, dealing with old devices will be a lot easier.
> If 6% of Android users globally are on an ancient OS version, how many man-hours would it be sensible for my to spend testing that our systems work for them? How many of those 6% are likely to be paying customers for us?
From a purely financial point of view, I agree. But it stills sucks for the 6% and indirectly this is one of the reasons for electronic waste.
In a way there is a long tail of consumers with smaller incomes and living in countries with weak currencies that benefit from computer hardware and software and services that are developed targeting wealthier consumers but still have to deal with the fact they aren't really the target market.
If so, I hope they're covering both hardware and software and configs.
That certs eventually expire is obvious to me now that someone raised the issue. But I wouldn't have foreseen the problem on my own. So I imagine policy makers will need to be informed too.
Yes, there is legislation for this that mandates a number of OS updates and security updates. I'm hoping Android manufacturers will stop shovelling new SKUs and concentrate on a few they can actually keep up to date.
It is cheap Android handsets stuck on Android 6 Marshmallow or worse that never have received an OS upgrade.
Still works.
Phones from 2016 are ancient and you can buy newer phones dirt cheap. The Samsung A series costs almost nothing, same with all the cheap Redmi phones and Oppo and whatnot.
Throwing away a phone whose hardware may be perfectly working, but its manufacturer decided to be too cheap to use anything but walled-garden components, feels like an utter waste of resources.
(By walled-garden components, I mean chips whose suppliers make it difficult or impossible to develop an open-source driver.)
But good luck using it
https://www.intel.com/content/www/us/en/products/sku/75203/i...
Like, if I find a knife from 150 years ago, it still cuts cheese. Sure - it isn't the most modern tech, but it still does the job it was made for. Even though cheese recipes have changed, they are still compatible with an old knife.
Yet a phone in 150 years will be 100% useless. Not only useless because other things have moved on, or because the hardware has degraded, but useless by design because root certificates expire.
We shouldn't be putting anything into consumer electronics with an expiry date.
Lets try something appreciably more complex and do an equivalently tricky task. Lets use an 1873 steam train to travel from London to Derby.
We run into more or less the same problem. Functionally, this can work, you'll have to buy the coal from somewhere and hire tankers to move the water where it's needed since there is no longer provision for that- but much harder you'll need to secure an extraordinary amount of special case paperwork to make this happen, because obviously your 1873 steam train isn't authorized to use this route, you will need to retro-fit safety equipment that an 1873 steam train was never designed to work with, and you will need to re-train people to operate it.
Don't worry though, you have preserved the important part - your 150 year old train is still ludicrously unsafe compared to its modern equivalent like the phone. Relatively minor impacts will turn the passenger compartments into kindling, with passengers still inside, because they're basically just a wooden box resting on a simple metal platform, not a monocoque design and even after fitting mandatory safety equipment the train can't effectively stop anywhere close to fast as modern trains if things go wrong.
The tricky part about PKI and signed TLS certificates has little to do with the encryption and a lot to do with networks of trusted parties. People die and are born, relationships evolve, and so these networks are inherently dynamic.
Certificate expiration is a feature by design, and it's included for a reason.
So you wouldn't have half the consumer electronics we have because nobody would be able to afford them.
We should be making consumer electronics with reasonable life expectancies. 150 years in the future I don't want to use something from 150 years ago that "still works", I want something that is new with more capabilities, that is cheaper, that does the thing better. Why create undestructible phones that will last 150 years when nobody other than vintage collectors will want them after ~10 years due to other problems with material degradation, fashion etc.
The optimal point is to not create discardable things, but it's also realising that if you're making something forever you're going to use up way more resources and people will still stop using those devices for other reasons, so you just created more waste.
Too short life = too much waste due to replacement needs.
Too long life = too many wasted resources per-device which will be abandoned for other reasons.
In 150 years you could as well not have anything new on par with the currently available devices.
Even if that computer had up-to-date certificates, basically nothing about it would be compatible with the modern internet. It's not just a question of of "expiry dates", it's that you cannot make any forward progress if you have to maintain backwards compatibility forever.
Internet protocols, file formats, hardware standards... all these things need to be able to change over time. Hell, with the old phone example, your biggest problem with a sufficiently old phone is whether it can even connect to the network - I recently tried using a retro Nokia as a backup phone, but realised that the SIM card I'd put in it was for a network which didn't offer 2G coverage. Phone couldn't even make calls or send texts because it wasn't 3G compatible.
Solutions will come and go. Hell, what's stopping someone from building an on-device VPN that does the SSL translation itself?
Well, not exactly web browsing, but somewhat using API... yes :) https://www.dialup.net/wingpt/tls.html
Not that it would be necessary
Should be noted that the new design (Android 14) is to allow certificate updates to be separate from operating system updates. Not sure if this is done via a standardized API or something proprietary, so the problem of servers going down forever might remain.
Because the root issue is just that — no root certificate in the system.
https://www.urbandictionary.com/define.php?term=spicy+pillow
TIL!
In addition to LE, there’s other CAs like sectigo, digicert, and Google Trust Services that support it. A few are listed here: https://www.acmeisuptime.com/#CA-Software
Also in practice, Google's policies strongly resemble Mozilla's. Mozilla's root programme is overseen by mozilla.dev.security.policy, a public group. So, to some extent the answer to "Who governs that list?" is you do, much as (if you live in a democracy) it's your fault that your government is terrible. You could work hard to improve things. But, you probably won't.
It was 50% when they announced the plan initially. :-|
If so, what would make them suggest such a plan in the first place?