#Soylent | Logs for 2015-04-16

« return
[16:57:19] <Bender> [SoylentNews] - WINVote Voting Machines Used in Virginia Elections are Shockingly Insecure - http://sylnt.us - Bzzzt!-Bzzzt!
[17:15:50] <mechanicjay> grr chrome
[17:18:35] <mechanicjay> Chome: "Hi, your valid cert that you generated some time go, well, because it uses SHA-1, we're going to throw a cert warning starting....today!"
[17:19:12] <mechanicjay> When I rule the world, I'm going to ban Chrome.
[17:47:00] <CoolHand> mechanicjay: when you rule the world, I'll expect a lot of good things besides that..
[17:47:14] <CoolHand> don't let me down..
[18:05:54] <kadal> mechanicjay, is that for soylentnews.org?
[18:09:31] <mechanicjay> no, for the day job. At sn we have a good 256 bit encryption key.
[18:10:20] <mechanicjay> though now that I"m looking at sn in chrome, maybe I'm wrong.
[18:13:06] <mechanicjay> chrome now gives a little yellow triangle for https://soylentnews.org. They're bitching because our CA doesn't have public audit records.
[18:13:06] <clippit> ^ 03SoylentNews is secured goatse
[18:13:20] <mechanicjay> This is different from the issue I'm seeing at work though
[18:14:09] <kadal> Chromium says "your connection to this site uses obsolete cryptography". The little icon is nice and green.
[18:15:01] <mechanicjay> yeah, Chrome 42 dropped on Tuesday, information is the same, but the icon is now unhappy.
[18:16:28] <kadal> ah, i see.
[18:16:47] <mechanicjay> the clever part at work, is that I get a big red X on my sites, it's happy about the encryption technology, still bitching about the CA though
[18:17:22] <mechanicjay> no, actually for SN Chrome is suddenly bitching about mixed http/https traffic
[18:24:39] <kadal> i have zero domain knowledge on this. Why would it suddenly start complaining?
[18:25:34] <mechanicjay> Because Chrome likes to change the rules on the fly.
[18:26:15] <mechanicjay> But, because Google can do no wrong, syadmins end up looking like a-holes by not keeping up.
[18:28:54] <mechanicjay> My real issue is that Chrome ends up forcing changes from the client end to serve their own purposes, nevermind that said change may break existing infrastructure or trivial things like that.
[18:30:14] <mechanicjay> The couple of interactions I've had with the dev team have not been positive. Arrogance abounds -- they've achieved market share and they're not interested in deferring to anyone on anything.
[18:30:35] <mechanicjay> Our way or the hiway seems to be the motto
[19:37:39] <mythterj> Re the public audit records... That's not what chrome is bitching about. Even Gmail.com gets that warning.
[19:40:43] <mythterj> Google the words chrome outdated security settings , and take the first hit.
[19:42:08] <mythterj> Deprecation of SHA-1 seems to be the issue.
[20:35:21] -!- kadal [kadal!~kadal@jcbswjm.whoi.edu] has joined #Soylent
[21:08:07] <Cyprus> iirc the obsolete thing is due to feasable attacks on it in the wild?
[21:08:16] <Cyprus> dont know what the audit thing is though
[21:11:26] <Cyprus> it was also announced like a year ago? http://googleonlinesecurity.blogspot.com
[21:11:27] <clippit> ^ 03Google Online Security Blog: Gradually sunsetting SHA-1
[21:12:41] * Cyprus pats clippit on the head
[23:12:48] <mythterj> @Cyprus I think SoylentNews just has to stop advertising sha-1 and the warning goes away. Or, just make sure its not first in the list of advertises encryptions.
