23
SSL Certificate Validity Reduced to 47 Days After Apple Proposal
(securityonline.info)
c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.
THE RULES
Instance Rules
Community Rules
If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.
Learn about hacking
Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub
Notable mention to !cybersecuritymemes@lemmy.world
There is an arguably much worse security issue which could potentially be caused by this change: If users become more likely to encounter expired certificate warnings, then they are more likely to have to click through those warnings and develop warning-fatigue, making them more vulnerable to accepting invalid certificates during an actual attack on their system.
It will be interesting to see whether CAs are capable of increasing their capacity by the 10x necessary just to serve the same number of customers. Presumably they will need to raise prices to accomplish this. Outages with certificate renewal systems will be almost inevitable - it's only a question of how frequently we see it.
Letsencrypt already renews all of their certificates every 60 days. Not much will change for the largest CA.
And as most admins are getting used to free certificates, paying for certs will become even less a thing.
Let's see what the reduced funding from US gov will do.