Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

As usual: it depends.

Why does it need to validate a cert? How acceptable is it if you get it wrong? Depending on the answer, perhaps "have a more reliable clock" is the right answer (plenty of embedded devices certainly have a decent idea of what time it is, and if it's already big enough to validate TLS). It seems reasonably probable that the NTP server stops being available for a reasonable amount of time before you have no idea what time it is anymore and can no longer validate certificates; so depending on the device, telemetry might be a good idea too.

It doesn't sound like a reason to give up, though :)



What I meant is:

- Device is rebooted

- Can't reach NTP, no RTC or dead RTC battery, happy that time is January 1st, 1970

- HTTPS breaks


You can reach a web host but not NTP? That seems like an edge case.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: