• 1 Post
  • 7 Comments
Joined 1 year ago
cake
Cake day: July 7th, 2023

help-circle

  • Also delete your expired certificate if you have one (for example after a year)

    This is likely a bad mistake. Keep the old cert around.

    There’s two possibilities:

    The first possibility is that Actalis uses the same key pair for the new cert. This is not a great approach because it doesn’t defend against a leaked key or key overuse. After all, if the key can be trusted longer than a year, the first cert they issued should be valid for longer.

    The second, and much worse possibility, is that renewing the cert gets a different private key. This can case data loss. Deleting the old identity means you lose the ability to decrypt any messages that were encrypted using that key! Even if your mail client stores the previously encrypted emails in decrypted form, you may receive a new email from a sender who does not yet have your new cert.




  • In America there’s a concerted effort to destroy public education. That means there are insane policies like this one: Some public schools lose a bit of funding each time a student doesn’t show up. Doesn’t matter that the school’s expenses stayed the same. It’s not like they could tell a teacher to go home 15 minutes early and reduce their pay accordingly, which would be awful for the teachers anyway. So schools are extremely motivated to keep kids in the school.