Sunday, April 20

Geek

Daily News Stuff 20 April 2025

Demon Barbecue Edition

Top Story

  • Vendors have voted to reduce the duration of SSL certificates from one year to 47 days.  (Computerworld)

    Fuck vendors.

    This is mostly driven by Apple, because...  Because nothing, really.  It's a bad solution to a non-problem.

    Apple has been pushing for this for some time.  Previously certificates were valid for up to five years, and then Apple got involved.

    And the certificate vendors have just committed suicide, because nobody is going to pay them for a certificate that has to be manually refreshed every few weeks, and if you are deploying an automated solution you might as well go all the way and implement a free automated solution using Let's Encrypt.

    So good work, assholes.


  • It's true that SSL providers are stupid but you still can't use the certificate without hacking DNS.  (Bugzilla)

    And it's true that SSL is intended to be resilient to this sort of attack, but if you care about security you need to care about who is providing your DNS, and if you do then this attack doesn't work anyway.

Tech News

  • Intel says yes, our graphics cards kind of suck when used with older (and slower) CPUs.  (WCCFTech)

    Intel's graphics drives are somewhat inefficient.  This doesn't show up on recent CPUs, because they are fast enough to keep up anyway.  But if you pair an Intel graphics card with a CPU from five years ago, the performance bottleneck is now the CPU.

    This is a problem because Intel's graphics cards are cheaper than anything current from AMD or Nvidia, making them look like a good option for people with tight budgets...  Who would still be using older CPUs.


  • Russia is seeding chatbots with lies.  Any bad actor could do the same, though of course the exercise would be redundant because feeding bullshit into a bullshit factory doesn't really change the output.  (Detroit News)

    What it we made it even more stochastic?


  • Ordered the Lenovo Legion Tab Gen 3 to replace my dead Tab M8 FHD.  It's more than I wanted to pay, but I need a small tablet with a high-resolution display, and it is the only small Android model available with a resolution better than 1340x800.  Unless I buy from Aliexpress and risk having my Google and Amazon accounts hoovered up in the next OTA update exploit, as happened with Alldocube not long ago.

    Compared to the M8 FHD it's three times the price (with the current discount), but has four times the RAM, eight times the storage (no microSD slot, which messes that up, but 256GB is still decent), bumps the resolution up from 1920x1200 to 2560x1600, and is just astronomically faster.  The Cortex X4 is at least nine generations newer than the A53 in the M8 FHD depending on how you count, and on Antutu is ten times faster on multi-threaded tests comparing the two eight-core chips.  (It doesn't have an entry for the P22T, but that had the same cores and clock speed as the P35 which is on the list.)

    Which I'd like to say I don't care about but the M8 FHD was kind of a slug.

    Hope it's worth it.  Shame I really don't care about graphics performance on this thing, because there it scores 127 times faster than the old model.


Musical Interlude




Disclaimer: It digs the hole or it gets the hose again.

Posted by: Pixy Misa at 04:24 PM | Comments (4) | Add Comment | Trackbacks (Suck)
Post contains 568 words, total size 5 kb.

1 "Callan said that he personally applauds the changes. "I am thrilled for a couple of reasons. Shortening certificate lifespans are a good trend. It is the right direction for things to go.'"

There's a story, possibly apocryphal, about Milton Friedman:

"While traveling by car during one of his many overseas travels, Professor Milton Friedman spotted scores of road builders moving earth with shovels instead of modern machinery. When he asked why powerful equipment wasn't used instead of so many laborers, his host told him it was to keep employment high in the construction industry. If they used tractors or modern road building equipment, fewer people would have jobs was his host's logic.

'Then instead of shovels, why don't you give them spoons and create even more jobs?' Friedman inquired."


If this moron Callan thinks shortening the timespan is so great, why not carry it to the logical conclusion and make certs last 1 day?



Posted by: Rick C at Monday, April 21 2025 07:22 AM (1zWbY)

2 This web certificate stuff is a systems engineering analysis involving security. My take is that Apple's position is stupid. Apple employs a fair number of very smart people. I'm still often confident enough that I would presume that I am more correct than Apple's people. I could be super wrong, of course.

Posted by: PatBuckman at Monday, April 21 2025 08:12 AM (rcPLc)

3 It's not clear to me whether they just mean top level domain certs, or all SSL certificates used for any purpose. The applications I manage at work involve around a dozen certificates for use connecting to different third party vendors. At least one of those vendors, a major regional utility, has a process they go through when you ask for a new or renewed certificate that, currently, can take longer than 47 days.

Posted by: David Eastman at Monday, April 21 2025 12:55 PM (aAyxl)

4 wasn't the issue with your Tab M8 just a bad usb charging port? if you ever want to sell it for parts, I had bought one based on your review a couple years back and love it and wouldn't mind having a donor for parts if you feel like getting rid of it,  in the event i break the screen on mine  or my battery gets wonky.

Posted by: bob in houston at Wednesday, April 23 2025 01:49 AM (YBLgY)

Hide Comments | Add Comment




Apple pies are delicious. But never mind apple pies. What colour is a green orange?




Save
Bold
Italic
Underline
Strikethrough
Superscript
Subscript
Foreground Color
Background Color
Hyperlink
Special Characters
Undo
Redo
View/Edit Source
 

54kb generated in CPU 0.0291, elapsed 0.1468 seconds.
58 queries taking 0.1358 seconds, 356 records returned.
Powered by Minx 1.1.6c-pink.