curl with http vs --insecure https

Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking
Author Message
yoyoma2
DD-WRT User


Joined: 24 Sep 2016
Posts: 358

PostPosted: Fri Aug 25, 2023 12:39    Post subject: curl with http vs --insecure https Reply with quote
Disclaimer: I'm not a networking person so please ELI5

There is currently a certificate problem as discussed here. As a temporary workaround I added a way for easyddup to use curl with http instead of https and it works.

Question1:
Would it be better to add a workaround using curl with --insecure https ? My limited understanding is that it's insecure because I'm not sure who I'm talking to but still encrypted so a man in the middle couldn't see/modify the contents of the dd-wrt build on the way to me? If the source is already unknown, isn't the man in the middle attack irrelevant?

Question2:
How long until this certificate problem is back to normal? I'm not even clear on the exact problem as easyddup can work on two url's (primary and a fallback) and the certificate on the fallback url works to navigate the builds but the final build download is on the primary url with the bad certificate.
Sponsor
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12468
Location: Netherlands

PostPosted: Fri Aug 25, 2023 12:53    Post subject: Reply with quote
Usually the certificate is renewed in 1-3 days.

But now during the holidays it apparently takes longer.

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
yoyoma2
DD-WRT User


Joined: 24 Sep 2016
Posts: 358

PostPosted: Sat Aug 26, 2023 13:20    Post subject: Reply with quote
Thanks @egc for question #2. Nobody has an opinion on question #1 whether https with an unverified certificate is better than http? I read this answer before creating this thread but it doesn't really answer the question of which is better. There are degrees of insecurity...
dale_gribble39
DD-WRT Guru


Joined: 11 Jun 2022
Posts: 1636

PostPosted: Sat Aug 26, 2023 17:43    Post subject: Reply with quote
It wouldn't surprise me if they are waiting for "the rest of the certificates" to expire to do an all-inclusive certificate for the entire domain, i.e. *.dd-wrt.com.

DD-WRT Forum Index -> Broadcom SoC based Hardware -> New Build - 08/21/2023 - r53396

_________________
"The woods are lovely, dark and deep,
But I have promises to keep,
And miles to go before I sleep,
And miles to go before I sleep." - Robert Frost

"I am one of the noticeable ones - notice me" - Dale Frances McKenzie Bozzio

<fact>code knows no gender</fact>

This is me, knowing I've ruffled your feathers, and not giving a ****
Some people are still hard-headed.

--------------------------------------
Mac Pro (Mid 2012) - Two 2.4GHz 6-Core Intel Xeon E5645 processors 64GB 1333MHz DDR3 ECC SDRAM OpenSUSE Leap 15.5
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12468
Location: Netherlands

PostPosted: Sat Aug 26, 2023 18:35    Post subject: Reply with quote
yoyoma2 wrote:
Thanks @egc for question #2. Nobody has an opinion on question #1 whether https with an unverified certificate is better than http? I read this answer before creating this thread but it doesn't really answer the question of which is better. There are degrees of insecurity...


I do think that is better but we just need a valid certificate.
Using https with unverified certificate is just not good enough in my book

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
yoyoma2
DD-WRT User


Joined: 24 Sep 2016
Posts: 358

PostPosted: Sun Aug 27, 2023 2:23    Post subject: Reply with quote
Thanks for the replies guys. I'm not complaining about the wait for the valid certificate. Just trying to learn something. Smile
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum