Re: [Inkscape-devel] Vectors Meeting - Tomorrow - Possible Postponement
Ryan Gorley via Inkscape-user <[email protected]> Thu, 9 May 2019 20:10:48 -0600
| Newsgroups | gmane.comp.graphics.inkscape.user,gmane.comp.graphics.inkscape.devel |
|---|---|
| Organization | Freehive |
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format. --===============8817854945952484313== Content-Type: multipart/alternative; boundary="------------DA73375C7DFA93CCDBEAB3C9" Content-Language: en-US This is a multi-part message in MIME format. --------------DA73375C7DFA93CCDBEAB3C9 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Offering a website connection over an encrypted HTTPS path isn't just about protecting credit card numbers or passwords anymore. Encryption protects a visitor from unwanted snooping and tampering by anyone along the worldwide network between that user's computer and the website's host. To illustrate, my ISP began injecting popup notices on my screen without my consent during casual web browsing (only on HTTP sites) when I was approaching their monthly usage limit. I'm sure they are scraping and selling every bit of information about me that they can whenever I visit and interact with an unencrypted site. No doubt the dozens of others(ISPs, employers, governments) who handle my information are doing the same. I don't think there is a great argument to be made for /not/ offering this protection to our visitors if we can--which we do. To the issue at hand, our TLS certificate for chat.inkscape.org is issued by Let's Encrypt. The certificate is offered free-of-charge, but it expires more frequently than alternatives. Fortunately it's pretty easy to set such certificates up to renew automatically. When they are about to expire the Let's Encrypt organization will automatically email a notice to the admin so they can renew manually if necessary. In this case the automatic renewal must have failed (or wasn't setup yet) and the email notification went unnoticed. It was a perfect storm. I don't expect this is something that will happen frequently. If it hadn't happened the day prior to a planned meeting, it wouldn't have been noteworthy. Browsers make a big deal about certificates being invalid in one way or another. Many people don't know how to even circumvent these notices, because in most cases they probably shouldn't. The Rocket.Chat app simply became inoperable when the certificate expired. Recena, Bryce, and others have been doing fantastic work on our new infrastructure. The chat service has been up for months, and renewed many times, without issue. I don't think we need to worry too much about it. On the bright side, it gave me a chance to complain about Comcast in this email. I think that alone offset the inconvenience of moving a meeting. Though, now that I think about it, this email is also traveling unencrypted. Who knows what may happen before it reaches you. ;) Ryan On 5/9/19 6:33 PM, brynn wrote: > I'm just saying it's a relatively new thing to think of SSL as > something that users expect of any website.=C2=A0 A few years ago, most= > people never saw an untrusted certificate warning.=C2=A0 Now they see t= hem > (and they're worded way too strongly, in my opinion) and it's like the > end of the world, when just a few years ago, we never had this kind of > security.=C2=A0 We depended on our local security, rather than the webs= ite > we visit. > > When all websites across the internet provide SSL security, then I > think we better make sure we do too.=C2=A0 Until then, we do our best.=C2= =A0 But > I don't think we need to panic, or take any kind of excessive > measures.=C2=A0 I mean, that was your original question, wasn't it, whe= ther > we need to do more?=C2=A0 Or whether we need to worry? > > I don't think we need to do either.=C2=A0 The certificate had a problem= , > not the website.=C2=A0 (Thus my concern about how the warning is worded= =2E=C2=A0 > It leads you to think the website has a problem, when it didn't.) > > At least with my own website, I haven't seen any way to be notified in > advance when a problem is about to happen with a certificate.=C2=A0 I > suppose our sysadmin could look into that?=C2=A0 But as far as I know, = the > sysadmin learns about it when everyone else does.=C2=A0 Other than be > notified before the certificate has a problem I don't know any > non-excessive way to protect against this problem. > > All best, > brynn > > > -----Original Message----- From: C R > Sent: Thursday, May 09, 2019 2:17 PM > To: brynn > Cc: Inkscape User Community ; Ryan Gorley ; inkscape-devel > Subject: Re: [Inkscape-user] [Inkscape-devel] Vectors Meeting - > Tomorrow - Possible Postponement > > > If there's no login, there's no problem. > Anywhere I'm entering in username and passwords, and storing stuff on > a server, you better believe it should have encryption. > But whether or not you think we need it, we are an official project > who cares about the security of our users. We depend on mutual trust, > and it looks very bad when browsers reject our invalid credentials > (and rightly so). > > Obviously, we want our users to trust us, and having official websites > and chat services fail basic security checks destroys that confidence > and trust. > > So yea, big deal from my perspective. :) > > -C > > > > On Thu, May 9, 2019 at 4:43 PM brynn <[email protected]> wrote: > What about websites which have no certificate at all?=C2=A0 You just do= n't > use them? > Those websites will never have warnings about the certificate, because > they > don't have one.=C2=A0 It doesn't necessarily mean that they aren't safe= sites. > InkscapeForum.com is one of those, fyi. > > Of course we can agree to disagree :-) > > All best > brynn > > -----Original Message----- From: C R > Sent: Thursday, May 09, 2019 7:42 AM > To: Brynn > Cc: Inkscape User Community ; Ryan Gorley ; inkscape-devel > Subject: Re: [Inkscape-user] [Inkscape-devel] Vectors Meeting - > Tomorrow - > Possible Postponement > > > No, I didn't. But I think it's important for visitors to our site to > be able to > trust the chat (especially one you have to sign up for and log into). > I disagree > that it's not a big deal. > > -C > > > > On Thu, 9 May 2019, 13:25 brynn, <[email protected]> wrote: > Wow!=C2=A0 I wonder if that could be some security setting in Chrome?=C2= =A0 I'd > have to > look it up to be sure, but I think it's an option in Firefox, to not > load a page > with an untrusted certificate.=C2=A0 There are just so many untrusted > certificates, > on entirely trustworthy sites, I disabled it.=C2=A0 I still get the > warning, but the > page isn't completely blocked. > > Did you set a temporary exception?=C2=A0 At least in Firefox, I got the= > option to set > either a temporary or permanent exception, and that fixed the chat. > > Or otherwise, perhaps Chrome should be notified.=C2=A0 To my limited > understanding, > that doesn't seem reasonable to block the page and not give a choice. > > brynn > > -----Original Message----- From: C R > Sent: Wednesday, May 08, 2019 1:57 PM > To: Inkscape User Community > Cc: Brynn ; Ryan Gorley ; inkscape-devel > Subject: Re: [Inkscape-user] [Inkscape-devel] Vectors Meeting - > Tomorrow - > Possible Postponement > > > It actually broke the chat entirely in Chrome, even clicking past the > warning, > it still would not connect. Fyi > > -C > > > On Tue, 7 May 2019, 23:32 Ryan Gorley via Inkscape-user, > <[email protected]> wrote: > > > Understood. Had to make a call with imperfect information. Sorry for th= e > inconvenience. I hope we can pick up the forum stuff at the meeting in > a couple > days. > > > Ryan > > On 5/7/19 4:29 PM, brynn wrote: > I'll have to be honest.=C2=A0 This is just my opinion. > > I don't consider an expired certificate, or whatever problem it was > with the > certificate, to be any kind of serious problem.=C2=A0 I trust that the > website is > safe, and no serious threat will show up via untrusted certificate > warning. > > In my opinion, the untrusted certificate warnings are built on maximum > paranoia. > They truly do sound dire.=C2=A0 But unless=C2=A0 you are making some mo= netary > transaction, > or sharing files or info that should remain secure, they really can be > ignored. > Again, my opinion. > > All best, > brynn > > -----Original Message----- From: C R > Sent: Monday, May 06, 2019 8:32 AM > To: Manuel Jes=C3=BAs Recena Soto > Cc: inkscape-devel ; Inkscape User Community > Subject: Re: [Inkscape-user] [Inkscape-devel] Vectors Meeting - > Tomorrow - > Possible Postponement > > > We are heavily using this chat across all parts of the project at the > moment. Do > we need to worry about stability? Thanks for any advice. > > -C > > > On Sun, 5 May 2019, 20:04 Manuel Jes=C3=BAs Recena Soto, > mailto:[email protected] > wrote: > > Hello Ryan, > > If you believe this chat service is critical, I suggest you to schedule= a > meeting with infrastructure team in order to find a better solution. > > Regards, > > > On Sat, May 4, 2019 at 2:02 AM Ryan Gorley via Inkscape-devel > mailto:[email protected] wrote: > > > Hello All, > Due to the certificate error on chat.inkscape.org, some individuals > may be > scared away from participating in our meeting tomorrow. I'm going to > keep an eye > on it, but if the error isn't resolved in the next couple hours I'm > going to > suggest we postpone our meeting one week. I'll update everyone on the > status a > little later. > > - Ryan > > > > _______________________________________________ > Inkscape-devel mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/inkscape-devel > > > > > _______________________________________________ > Inkscape-user mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/inkscape-user > > > --------------DA73375C7DFA93CCDBEAB3C9 Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: 8bit <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> </head> <body text="#000000" bgcolor="#FFFFFF"> <p><font face="Helvetica, Arial, sans-serif">Offering a website connection over an encrypted HTTPS path isn't just about protecting credit card numbers or passwords anymore. Encryption protects a visitor from unwanted snooping and tampering by anyone along the worldwide network between that user's computer and the website's host. To illustrate, my ISP began injecting popup notices on my screen without my consent during casual web browsing (only on HTTP sites) when I was approaching their monthly usage limit. I'm sure they are scraping and selling every bit of information about me that they can whenever I visit and interact with an unencrypted site. No doubt the dozens of others</font><font face="Helvetica, Arial, sans-serif"><font face="Helvetica, Arial, sans-serif"> (ISPs, employers, governments)</font> who handle my information are doing the same. I don't think there is a great argument to be made for <i>not</i> offering this protection to our visitors if we can--which we do.<br> </font></p> <p><font face="Helvetica, Arial, sans-serif">To the issue at hand, our TLS certificate for chat.inkscape.org is issued by Let's Encrypt. The certificate is offered free-of-charge, but it expires more frequently than alternatives. Fortunately it's pretty easy to set such certificates up to renew automatically. When they are about to expire the Let's Encrypt organization will automatically email a notice to the admin so they can renew manually if necessary. In this case the automatic renewal must have failed (or wasn't setup yet) and the email notification went unnoticed. It was a perfect storm. I don't expect this is something that will happen frequently. If it hadn't happened the day prior to a planned meeting, it wouldn't have been noteworthy. Browsers make a big deal about certificates being invalid in one way or another. Many people don't know how to even circumvent these notices, because in most cases they probably shouldn't. The Rocket.Chat app simply became inoperable when the certificate expired. <br> </font></p> <p>Recena, Bryce, and others have been doing fantastic work on our new infrastructure. The chat service has been up for months, and renewed many times, without issue. I don't think we need to worry too much about it. On the bright side, it gave me a chance to complain about Comcast in this email. I think that alone offset the inconvenience of moving a meeting. Though, now that I think about it, this email is also traveling unencrypted. Who knows what may happen before it reaches you. ;)<br> </p> <div class="moz-signature">Ryan<br> <br> </div> <div class="moz-cite-prefix">On 5/9/19 6:33 PM, brynn wrote:<br> </div> <blockquote type="cite" cite="mid:64ECD76E762245FEAB1253CF2E00C362@brynnPC">I'm just saying it's a relatively new thing to think of SSL as something that users expect of any website. A few years ago, most people never saw an untrusted certificate warning. Now they see them (and they're worded way too strongly, in my opinion) and it's like the end of the world, when just a few years ago, we never had this kind of security. We depended on our local security, rather than the website we visit. <br> <br> When all websites across the internet provide SSL security, then I think we better make sure we do too. Until then, we do our best. But I don't think we need to panic, or take any kind of excessive measures. I mean, that was your original question, wasn't it, whether we need to do more? Or whether we need to worry? <br> <br> I don't think we need to do either. The certificate had a problem, not the website. (Thus my concern about how the warning is worded. It leads you to think the website has a problem, when it didn't.) <br> <br> At least with my own website, I haven't seen any way to be notified in advance when a problem is about to happen with a certificate. I suppose our sysadmin could look into that? But as far as I know, the sysadmin learns about it when everyone else does. Other than be notified before the certificate has a problem I don't know any non-excessive way to protect against this problem. <br> <br> All best, <br> brynn <br> <br> <br> -----Original Message----- From: C R <br> Sent: Thursday, May 09, 2019 2:17 PM <br> To: brynn <br> Cc: Inkscape User Community ; Ryan Gorley ; inkscape-devel <br> Subject: Re: [Inkscape-user] [Inkscape-devel] Vectors Meeting - Tomorrow - Possible Postponement <br> <br> <br> If there's no login, there's no problem. <br> Anywhere I'm entering in username and passwords, and storing stuff on a server, you better believe it should have encryption. <br> But whether or not you think we need it, we are an official project who cares about the security of our users. We depend on mutual trust, and it looks very bad when browsers reject our invalid credentials (and rightly so). <br> <br> Obviously, we want our users to trust us, and having official websites and chat services fail basic security checks destroys that confidence and trust. <br> <br> So yea, big deal from my perspective. :) <br> <br> -C <br> <br> <br> <br> On Thu, May 9, 2019 at 4:43 PM brynn <a class="moz-txt-link-rfc2396E" href="mailto:[email protected]"><[email protected]></a> wrote: <br> What about websites which have no certificate at all? You just don't use them? <br> Those websites will never have warnings about the certificate, because they <br> don't have one. It doesn't necessarily mean that they aren't safe sites. <br> InkscapeForum.com is one of those, fyi. <br> <br> Of course we can agree to disagree :-) <br> <br> All best <br> brynn <br> <br> -----Original Message----- From: C R <br> Sent: Thursday, May 09, 2019 7:42 AM <br> To: Brynn <br> Cc: Inkscape User Community ; Ryan Gorley ; inkscape-devel <br> Subject: Re: [Inkscape-user] [Inkscape-devel] Vectors Meeting - Tomorrow - <br> Possible Postponement <br> <br> <br> No, I didn't. But I think it's important for visitors to our site to be able to <br> trust the chat (especially one you have to sign up for and log into). I disagree <br> that it's not a big deal. <br> <br> -C <br> <br> <br> <br> On Thu, 9 May 2019, 13:25 brynn, <a class="moz-txt-link-rfc2396E" href="mailto:[email protected]"><[email protected]></a> wrote: <br> Wow! I wonder if that could be some security setting in Chrome? I'd have to <br> look it up to be sure, but I think it's an option in Firefox, to not load a page <br> with an untrusted certificate. There are just so many untrusted certificates, <br> on entirely trustworthy sites, I disabled it. I still get the warning, but the <br> page isn't completely blocked. <br> <br> Did you set a temporary exception? At least in Firefox, I got the option to set <br> either a temporary or permanent exception, and that fixed the chat. <br> <br> Or otherwise, perhaps Chrome should be notified. To my limited understanding, <br> that doesn't seem reasonable to block the page and not give a choice. <br> <br> brynn <br> <br> -----Original Message----- From: C R <br> Sent: Wednesday, May 08, 2019 1:57 PM <br> To: Inkscape User Community <br> Cc: Brynn ; Ryan Gorley ; inkscape-devel <br> Subject: Re: [Inkscape-user] [Inkscape-devel] Vectors Meeting - Tomorrow - <br> Possible Postponement <br> <br> <br> It actually broke the chat entirely in Chrome, even clicking past the warning, <br> it still would not connect. Fyi <br> <br> -C <br> <br> <br> On Tue, 7 May 2019, 23:32 Ryan Gorley via Inkscape-user, <br> <a class="moz-txt-link-rfc2396E" href="mailto:[email protected]"><[email protected]></a> wrote: <br> <br> <br> Understood. Had to make a call with imperfect information. Sorry for the <br> inconvenience. I hope we can pick up the forum stuff at the meeting in a couple <br> days. <br> <br> <br> Ryan <br> <br> On 5/7/19 4:29 PM, brynn wrote: <br> I'll have to be honest. This is just my opinion. <br> <br> I don't consider an expired certificate, or whatever problem it was with the <br> certificate, to be any kind of serious problem. I trust that the website is <br> safe, and no serious threat will show up via untrusted certificate warning. <br> <br> In my opinion, the untrusted certificate warnings are built on maximum paranoia. <br> They truly do sound dire. But unless you are making some monetary transaction, <br> or sharing files or info that should remain secure, they really can be ignored. <br> Again, my opinion. <br> <br> All best, <br> brynn <br> <br> -----Original Message----- From: C R <br> Sent: Monday, May 06, 2019 8:32 AM <br> To: Manuel Jesús Recena Soto <br> Cc: inkscape-devel ; Inkscape User Community <br> Subject: Re: [Inkscape-user] [Inkscape-devel] Vectors Meeting - Tomorrow - <br> Possible Postponement <br> <br> <br> We are heavily using this chat across all parts of the project at the moment. Do <br> we need to worry about stability? Thanks for any advice. <br> <br> -C <br> <br> <br> On Sun, 5 May 2019, 20:04 Manuel Jesús Recena Soto, <a class="moz-txt-link-freetext" href="mailto:[email protected]">mailto:[email protected]</a> <br> wrote: <br> <br> Hello Ryan, <br> <br> If you believe this chat service is critical, I suggest you to schedule a <br> meeting with infrastructure team in order to find a better solution. <br> <br> Regards, <br> <br> <br> On Sat, May 4, 2019 at 2:02 AM Ryan Gorley via Inkscape-devel <br> <a class="moz-txt-link-freetext" href="mailto:[email protected]">mailto:[email protected]</a> wrote: <br> <br> <br> Hello All, <br> Due to the certificate error on chat.inkscape.org, some individuals may be <br> scared away from participating in our meeting tomorrow. I'm going to keep an eye <br> on it, but if the error isn't resolved in the next couple hours I'm going to <br> suggest we postpone our meeting one week. I'll update everyone on the status a <br> little later. <br> <br> - Ryan <br> <br> <br> <br> _______________________________________________ <br> Inkscape-devel mailing list <br> <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a> <br> <a class="moz-txt-link-freetext" href="https://lists.sourceforge.net/lists/listinfo/inkscape-devel">https://lists.sourceforge.net/lists/listinfo/inkscape-devel</a> <br> <br> <br> <br> <br> _______________________________________________ <br> Inkscape-user mailing list <br> <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a> <br> <a class="moz-txt-link-freetext" href="https://lists.sourceforge.net/lists/listinfo/inkscape-user">https://lists.sourceforge.net/lists/listinfo/inkscape-user</a> <br> <br> <br> <br> </blockquote> </body> </html> --------------DA73375C7DFA93CCDBEAB3C9-- --===============8817854945952484313== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============8817854945952484313== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Inkscape-user mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/inkscape-user --===============8817854945952484313==--