Re: [Inkscape-devel] Vectors Meeting - Tomorrow - Possible Postponement

Ryan Gorley via Inkscape-user <[email protected]> Thu, 9 May 2019 20:10:48 -0600
Newsgroups gmane.comp.graphics.inkscape.user,gmane.comp.graphics.inkscape.devel
Organization Freehive
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--===============8817854945952484313==
Content-Type: multipart/alternative;
 boundary="------------DA73375C7DFA93CCDBEAB3C9"
Content-Language: en-US

This is a multi-part message in MIME format.
--------------DA73375C7DFA93CCDBEAB3C9
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable

Offering a website connection over an encrypted HTTPS path isn't just
about protecting credit card numbers or passwords anymore. Encryption
protects a visitor from unwanted snooping and tampering by anyone along
the worldwide network between that user's computer and the website's
host. To illustrate, my ISP began injecting popup notices on my screen
without my consent during casual web browsing (only on HTTP sites) when
I was approaching their monthly usage limit. I'm sure they are scraping
and selling every bit of information about me that they can whenever I
visit and interact with an unencrypted site. No doubt the dozens of
others(ISPs, employers, governments) who handle my information are doing
the same. I don't think there is a great argument to be made for /not/
offering this protection to our visitors if we can--which we do.

To the issue at hand, our TLS certificate for chat.inkscape.org is
issued by Let's Encrypt. The certificate is offered free-of-charge, but
it expires more frequently than alternatives. Fortunately it's pretty
easy to set such certificates up to renew automatically. When they are
about to expire the Let's Encrypt organization will automatically email
a notice to the admin so they can renew manually if necessary. In this
case the automatic renewal must have failed (or wasn't setup yet) and
the email notification went unnoticed. It was a perfect storm. I don't
expect this is something that will happen frequently. If it hadn't
happened the day prior to a planned meeting, it wouldn't have been
noteworthy. Browsers make a big deal about certificates being invalid in
one way or another. Many people don't know how to even circumvent these
notices, because in most cases they probably shouldn't. The Rocket.Chat
app simply became inoperable when the certificate expired.

Recena, Bryce, and others have been doing fantastic work on our new
infrastructure. The chat service has been up for months, and renewed
many times, without issue. I don't think we need to worry too much about
it. On the bright side, it gave me a chance to complain about Comcast in
this email. I think that alone offset the inconvenience of moving a
meeting. Though, now that I think about it, this email is also traveling
unencrypted. Who knows what may happen before it reaches you. ;)

Ryan

On 5/9/19 6:33 PM, brynn wrote:
> I'm just saying it's a relatively new thing to think of SSL as
> something that users expect of any website.=C2=A0 A few years ago, most=

> people never saw an untrusted certificate warning.=C2=A0 Now they see t=
hem
> (and they're worded way too strongly, in my opinion) and it's like the
> end of the world, when just a few years ago, we never had this kind of
> security.=C2=A0 We depended on our local security, rather than the webs=
ite
> we visit.
>
> When all websites across the internet provide SSL security, then I
> think we better make sure we do too.=C2=A0 Until then, we do our best.=C2=
=A0 But
> I don't think we need to panic, or take any kind of excessive
> measures.=C2=A0 I mean, that was your original question, wasn't it, whe=
ther
> we need to do more?=C2=A0 Or whether we need to worry?
>
> I don't think we need to do either.=C2=A0 The certificate had a problem=
,
> not the website.=C2=A0 (Thus my concern about how the warning is worded=
=2E=C2=A0
> It leads you to think the website has a problem, when it didn't.)
>
> At least with my own website, I haven't seen any way to be notified in
> advance when a problem is about to happen with a certificate.=C2=A0 I
> suppose our sysadmin could look into that?=C2=A0 But as far as I know, =
the
> sysadmin learns about it when everyone else does.=C2=A0 Other than be
> notified before the certificate has a problem I don't know any
> non-excessive way to protect against this problem.
>
> All best,
> brynn
>
>
> -----Original Message----- From: C R
> Sent: Thursday, May 09, 2019 2:17 PM
> To: brynn
> Cc: Inkscape User Community ; Ryan Gorley ; inkscape-devel
> Subject: Re: [Inkscape-user] [Inkscape-devel] Vectors Meeting -
> Tomorrow - Possible Postponement
>
>
> If there's no login, there's no problem.
> Anywhere I'm entering in username and passwords, and storing stuff on
> a server, you better believe it should have encryption.
> But whether or not you think we need it, we are an official project
> who cares about the security of our users. We depend on mutual trust,
> and it looks very bad when browsers reject our invalid credentials
> (and rightly so).
>
> Obviously, we want our users to trust us, and having official websites
> and chat services fail basic security checks destroys that confidence
> and trust.
>
> So yea, big deal from my perspective. :)
>
> -C
>
>
>
> On Thu, May 9, 2019 at 4:43 PM brynn <[email protected]> wrote:
> What about websites which have no certificate at all?=C2=A0 You just do=
n't
> use them?
> Those websites will never have warnings about the certificate, because
> they
> don't have one.=C2=A0 It doesn't necessarily mean that they aren't safe=
 sites.
> InkscapeForum.com is one of those, fyi.
>
> Of course we can agree to disagree :-)
>
> All best
> brynn
>
> -----Original Message----- From: C R
> Sent: Thursday, May 09, 2019 7:42 AM
> To: Brynn
> Cc: Inkscape User Community ; Ryan Gorley ; inkscape-devel
> Subject: Re: [Inkscape-user] [Inkscape-devel] Vectors Meeting -
> Tomorrow -
> Possible Postponement
>
>
> No, I didn't. But I think it's important for visitors to our site to
> be able to
> trust the chat (especially one you have to sign up for and log into).
> I disagree
> that it's not a big deal.
>
> -C
>
>
>
> On Thu, 9 May 2019, 13:25 brynn, <[email protected]> wrote:
> Wow!=C2=A0 I wonder if that could be some security setting in Chrome?=C2=
=A0 I'd
> have to
> look it up to be sure, but I think it's an option in Firefox, to not
> load a page
> with an untrusted certificate.=C2=A0 There are just so many untrusted
> certificates,
> on entirely trustworthy sites, I disabled it.=C2=A0 I still get the
> warning, but the
> page isn't completely blocked.
>
> Did you set a temporary exception?=C2=A0 At least in Firefox, I got the=

> option to set
> either a temporary or permanent exception, and that fixed the chat.
>
> Or otherwise, perhaps Chrome should be notified.=C2=A0 To my limited
> understanding,
> that doesn't seem reasonable to block the page and not give a choice.
>
> brynn
>
> -----Original Message----- From: C R
> Sent: Wednesday, May 08, 2019 1:57 PM
> To: Inkscape User Community
> Cc: Brynn ; Ryan Gorley ; inkscape-devel
> Subject: Re: [Inkscape-user] [Inkscape-devel] Vectors Meeting -
> Tomorrow -
> Possible Postponement
>
>
> It actually broke the chat entirely in Chrome, even clicking past the
> warning,
> it still would not connect. Fyi
>
> -C
>
>
> On Tue, 7 May 2019, 23:32 Ryan Gorley via Inkscape-user,
> <[email protected]> wrote:
>
>
> Understood. Had to make a call with imperfect information. Sorry for th=
e
> inconvenience. I hope we can pick up the forum stuff at the meeting in
> a couple
> days.
>
>
> Ryan
>
> On 5/7/19 4:29 PM, brynn wrote:
> I'll have to be honest.=C2=A0 This is just my opinion.
>
> I don't consider an expired certificate, or whatever problem it was
> with the
> certificate, to be any kind of serious problem.=C2=A0 I trust that the
> website is
> safe, and no serious threat will show up via untrusted certificate
> warning.
>
> In my opinion, the untrusted certificate warnings are built on maximum
> paranoia.
> They truly do sound dire.=C2=A0 But unless=C2=A0 you are making some mo=
netary
> transaction,
> or sharing files or info that should remain secure, they really can be
> ignored.
> Again, my opinion.
>
> All best,
> brynn
>
> -----Original Message----- From: C R
> Sent: Monday, May 06, 2019 8:32 AM
> To: Manuel Jes=C3=BAs Recena Soto
> Cc: inkscape-devel ; Inkscape User Community
> Subject: Re: [Inkscape-user] [Inkscape-devel] Vectors Meeting -
> Tomorrow -
> Possible Postponement
>
>
> We are heavily using this chat across all parts of the project at the
> moment. Do
> we need to worry about stability? Thanks for any advice.
>
> -C
>
>
> On Sun, 5 May 2019, 20:04 Manuel Jes=C3=BAs Recena Soto,
> mailto:[email protected]
> wrote:
>
> Hello Ryan,
>
> If you believe this chat service is critical, I suggest you to schedule=
 a
> meeting with infrastructure team in order to find a better solution.
>
> Regards,
>
>
> On Sat, May 4, 2019 at 2:02 AM Ryan Gorley via Inkscape-devel
> mailto:[email protected] wrote:
>
>
> Hello All,
> Due to the certificate error on chat.inkscape.org, some individuals
> may be
> scared away from participating in our meeting tomorrow. I'm going to
> keep an eye
> on it, but if the error isn't resolved in the next couple hours I'm
> going to
> suggest we postpone our meeting one week. I'll update everyone on the
> status a
> little later.
>
> - Ryan
>
>
>
> _______________________________________________
> Inkscape-devel mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/inkscape-devel
>
>
>
>
> _______________________________________________
> Inkscape-user mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/inkscape-user
>
>
>

--------------DA73375C7DFA93CCDBEAB3C9
Content-Type: text/html; charset=utf-8
Content-Transfer-Encoding: 8bit

<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    <p><font face="Helvetica, Arial, sans-serif">Offering a website
        connection over an encrypted HTTPS path isn't just about
        protecting credit card numbers or passwords anymore. Encryption
        protects a visitor from unwanted snooping and tampering by
        anyone along the worldwide network between that user's computer
        and the website's host. To illustrate, my ISP began injecting
        popup notices on my screen without my consent during casual web
        browsing (only on HTTP sites) when I was approaching their
        monthly usage limit. I'm sure they are scraping and selling
        every bit of information about me that they can whenever I visit
        and interact with an unencrypted site. No doubt the dozens of
        others</font><font face="Helvetica, Arial, sans-serif"><font
          face="Helvetica, Arial, sans-serif"> (ISPs, employers,
          governments)</font> who handle my information are doing the
        same. I don't think there is a great argument to be made for <i>not</i>
        offering this protection to our visitors if we can--which we do.<br>
      </font></p>
    <p><font face="Helvetica, Arial, sans-serif">To the issue at hand,
        our TLS certificate for chat.inkscape.org is issued by Let's
        Encrypt. The certificate is offered free-of-charge, but it
        expires more frequently than alternatives. Fortunately it's
        pretty easy to set such certificates up to renew automatically.
        When they are about to expire the Let's Encrypt organization
        will automatically email a notice to the admin so they can renew
        manually if necessary. In this case the automatic renewal must
        have failed (or wasn't setup yet) and the email notification
        went unnoticed. It was a perfect storm. I don't expect this is
        something that will happen frequently. If it hadn't happened the
        day prior to a planned meeting, it wouldn't have been
        noteworthy. Browsers make a big deal about certificates being
        invalid in one way or another. Many people don't know how to
        even circumvent these notices, because in most cases they
        probably shouldn't. The Rocket.Chat app simply became inoperable
        when the certificate expired. <br>
      </font></p>
    <p>Recena, Bryce, and others have been doing fantastic work on our
      new infrastructure. The chat service has been up for months, and
      renewed many times, without issue. I don't think we need to worry
      too much about it. On the bright side, it gave me a chance to
      complain about Comcast in this email. I think that alone offset
      the inconvenience of moving a meeting. Though, now that I think
      about it, this email is also traveling unencrypted. Who knows what
      may happen before it reaches you. ;)<br>
    </p>
    <div class="moz-signature">Ryan<br>
      <br>
    </div>
    <div class="moz-cite-prefix">On 5/9/19 6:33 PM, brynn wrote:<br>
    </div>
    <blockquote type="cite"
      cite="mid:64ECD76E762245FEAB1253CF2E00C362@brynnPC">I'm just
      saying it's a relatively new thing to think of SSL as something
      that users expect of any website.  A few years ago, most people
      never saw an untrusted certificate warning.  Now they see them
      (and they're worded way too strongly, in my opinion) and it's like
      the end of the world, when just a few years ago, we never had this
      kind of security.  We depended on our local security, rather than
      the website we visit.
      <br>
      <br>
      When all websites across the internet provide SSL security, then I
      think we better make sure we do too.  Until then, we do our best. 
      But I don't think we need to panic, or take any kind of excessive
      measures.  I mean, that was your original question, wasn't it,
      whether we need to do more?  Or whether we need to worry?
      <br>
      <br>
      I don't think we need to do either.  The certificate had a
      problem, not the website.  (Thus my concern about how the warning
      is worded.  It leads you to think the website has a problem, when
      it didn't.)
      <br>
      <br>
      At least with my own website, I haven't seen any way to be
      notified in advance when a problem is about to happen with a
      certificate.  I suppose our sysadmin could look into that?  But as
      far as I know, the sysadmin learns about it when everyone else
      does.  Other than be notified before the certificate has a problem
      I don't know any non-excessive way to protect against this
      problem.
      <br>
      <br>
      All best,
      <br>
      brynn
      <br>
      <br>
      <br>
      -----Original Message----- From: C R
      <br>
      Sent: Thursday, May 09, 2019 2:17 PM
      <br>
      To: brynn
      <br>
      Cc: Inkscape User Community ; Ryan Gorley ; inkscape-devel
      <br>
      Subject: Re: [Inkscape-user] [Inkscape-devel] Vectors Meeting -
      Tomorrow - Possible Postponement
      <br>
      <br>
      <br>
      If there's no login, there's no problem.
      <br>
      Anywhere I'm entering in username and passwords, and storing stuff
      on a server, you better believe it should have encryption.
      <br>
      But whether or not you think we need it, we are an official
      project who cares about the security of our users. We depend on
      mutual trust, and it looks very bad when browsers reject our
      invalid credentials (and rightly so).
      <br>
      <br>
      Obviously, we want our users to trust us, and having official
      websites and chat services fail basic security checks destroys
      that confidence and trust.
      <br>
      <br>
      So yea, big deal from my perspective. :)
      <br>
      <br>
      -C
      <br>
      <br>
      <br>
      <br>
      On Thu, May 9, 2019 at 4:43 PM brynn <a class="moz-txt-link-rfc2396E" href="mailto:[email protected]">&lt;[email protected]&gt;</a> wrote:
      <br>
      What about websites which have no certificate at all?  You just
      don't use them?
      <br>
      Those websites will never have warnings about the certificate,
      because they
      <br>
      don't have one.  It doesn't necessarily mean that they aren't safe
      sites.
      <br>
      InkscapeForum.com is one of those, fyi.
      <br>
      <br>
      Of course we can agree to disagree :-)
      <br>
      <br>
      All best
      <br>
      brynn
      <br>
      <br>
      -----Original Message----- From: C R
      <br>
      Sent: Thursday, May 09, 2019 7:42 AM
      <br>
      To: Brynn
      <br>
      Cc: Inkscape User Community ; Ryan Gorley ; inkscape-devel
      <br>
      Subject: Re: [Inkscape-user] [Inkscape-devel] Vectors Meeting -
      Tomorrow -
      <br>
      Possible Postponement
      <br>
      <br>
      <br>
      No, I didn't. But I think it's important for visitors to our site
      to be able to
      <br>
      trust the chat (especially one you have to sign up for and log
      into). I disagree
      <br>
      that it's not a big deal.
      <br>
      <br>
      -C
      <br>
      <br>
      <br>
      <br>
      On Thu, 9 May 2019, 13:25 brynn, <a class="moz-txt-link-rfc2396E" href="mailto:[email protected]">&lt;[email protected]&gt;</a> wrote:
      <br>
      Wow!  I wonder if that could be some security setting in Chrome? 
      I'd have to
      <br>
      look it up to be sure, but I think it's an option in Firefox, to
      not load a page
      <br>
      with an untrusted certificate.  There are just so many untrusted
      certificates,
      <br>
      on entirely trustworthy sites, I disabled it.  I still get the
      warning, but the
      <br>
      page isn't completely blocked.
      <br>
      <br>
      Did you set a temporary exception?  At least in Firefox, I got the
      option to set
      <br>
      either a temporary or permanent exception, and that fixed the
      chat.
      <br>
      <br>
      Or otherwise, perhaps Chrome should be notified.  To my limited
      understanding,
      <br>
      that doesn't seem reasonable to block the page and not give a
      choice.
      <br>
      <br>
      brynn
      <br>
      <br>
      -----Original Message----- From: C R
      <br>
      Sent: Wednesday, May 08, 2019 1:57 PM
      <br>
      To: Inkscape User Community
      <br>
      Cc: Brynn ; Ryan Gorley ; inkscape-devel
      <br>
      Subject: Re: [Inkscape-user] [Inkscape-devel] Vectors Meeting -
      Tomorrow -
      <br>
      Possible Postponement
      <br>
      <br>
      <br>
      It actually broke the chat entirely in Chrome, even clicking past
      the warning,
      <br>
      it still would not connect. Fyi
      <br>
      <br>
      -C
      <br>
      <br>
      <br>
      On Tue, 7 May 2019, 23:32 Ryan Gorley via Inkscape-user,
      <br>
      <a class="moz-txt-link-rfc2396E" href="mailto:[email protected]">&lt;[email protected]&gt;</a> wrote:
      <br>
      <br>
      <br>
      Understood. Had to make a call with imperfect information. Sorry
      for the
      <br>
      inconvenience. I hope we can pick up the forum stuff at the
      meeting in a couple
      <br>
      days.
      <br>
      <br>
      <br>
      Ryan
      <br>
      <br>
      On 5/7/19 4:29 PM, brynn wrote:
      <br>
      I'll have to be honest.  This is just my opinion.
      <br>
      <br>
      I don't consider an expired certificate, or whatever problem it
      was with the
      <br>
      certificate, to be any kind of serious problem.  I trust that the
      website is
      <br>
      safe, and no serious threat will show up via untrusted certificate
      warning.
      <br>
      <br>
      In my opinion, the untrusted certificate warnings are built on
      maximum paranoia.
      <br>
      They truly do sound dire.  But unless  you are making some
      monetary transaction,
      <br>
      or sharing files or info that should remain secure, they really
      can be ignored.
      <br>
      Again, my opinion.
      <br>
      <br>
      All best,
      <br>
      brynn
      <br>
      <br>
      -----Original Message----- From: C R
      <br>
      Sent: Monday, May 06, 2019 8:32 AM
      <br>
      To: Manuel Jesús Recena Soto
      <br>
      Cc: inkscape-devel ; Inkscape User Community
      <br>
      Subject: Re: [Inkscape-user] [Inkscape-devel] Vectors Meeting -
      Tomorrow -
      <br>
      Possible Postponement
      <br>
      <br>
      <br>
      We are heavily using this chat across all parts of the project at
      the moment. Do
      <br>
      we need to worry about stability? Thanks for any advice.
      <br>
      <br>
      -C
      <br>
      <br>
      <br>
      On Sun, 5 May 2019, 20:04 Manuel Jesús Recena Soto,
      <a class="moz-txt-link-freetext" href="mailto:[email protected]">mailto:[email protected]</a>
      <br>
      wrote:
      <br>
      <br>
      Hello Ryan,
      <br>
      <br>
      If you believe this chat service is critical, I suggest you to
      schedule a
      <br>
      meeting with infrastructure team in order to find a better
      solution.
      <br>
      <br>
      Regards,
      <br>
      <br>
      <br>
      On Sat, May 4, 2019 at 2:02 AM Ryan Gorley via Inkscape-devel
      <br>
      <a class="moz-txt-link-freetext" href="mailto:[email protected]">mailto:[email protected]</a> wrote:
      <br>
      <br>
      <br>
      Hello All,
      <br>
      Due to the certificate error on chat.inkscape.org, some
      individuals may be
      <br>
      scared away from participating in our meeting tomorrow. I'm going
      to keep an eye
      <br>
      on it, but if the error isn't resolved in the next couple hours
      I'm going to
      <br>
      suggest we postpone our meeting one week. I'll update everyone on
      the status a
      <br>
      little later.
      <br>
      <br>
      - Ryan
      <br>
      <br>
      <br>
      <br>
      _______________________________________________
      <br>
      Inkscape-devel mailing list
      <br>
      <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a>
      <br>
      <a class="moz-txt-link-freetext" href="https://lists.sourceforge.net/lists/listinfo/inkscape-devel">https://lists.sourceforge.net/lists/listinfo/inkscape-devel</a>
      <br>
      <br>
      <br>
      <br>
      <br>
      _______________________________________________
      <br>
      Inkscape-user mailing list
      <br>
      <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a>
      <br>
      <a class="moz-txt-link-freetext" href="https://lists.sourceforge.net/lists/listinfo/inkscape-user">https://lists.sourceforge.net/lists/listinfo/inkscape-user</a>
      <br>
      <br>
      <br>
      <br>
    </blockquote>
  </body>
</html>

--------------DA73375C7DFA93CCDBEAB3C9--


--===============8817854945952484313==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============8817854945952484313==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Inkscape-user mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/inkscape-user

--===============8817854945952484313==--