logoalt Hacker News

dmitrygrtoday at 3:47 PM7 repliesview on HN

So what? They keep shortening the validity length of these certificates, making them more and more of a pain to deal with.


Replies

lynndotpytoday at 4:24 PM

Not applicable in this case. This was a certificate issued March 20th 2025 and which expired March 20th 2026. Also concerning are the instructions written in broken English instructing visitors to ignore all SSL warnings.

show 1 reply
gslepaktoday at 3:54 PM

Using old compromised certificates is a legitimate MITM attack vector.

show 1 reply
hhhtoday at 3:48 PM

because you need to automate it

show 1 reply
SAI_Peregrinustoday at 4:01 PM

And in turn making revocation less & less of a pain. Since that was more of the pain, overall it's getting easier.

k33ntoday at 3:57 PM

DNSSEC+DANE will fix it. Soon we will have self-signed certificates once again!

show 1 reply
koakuma-chantoday at 6:04 PM

I also don't get it, why do certificates need to expire?

show 3 replies
fidotrontoday at 3:52 PM

On the one side all the users will need to prove their ID to access websites, and on the website side the site will have to ask permission to continue operating at ever increasing frequency.

That is the future we have walked into.