back to article SNAFU: Blighty's judges not trustworthy, says their own website

UK.gov's judiciary website has had its security compromised after bungling administrators failed to renew a security certificate. The judiciary.gov.uk site is designed to provide information on Blighty's top legal bods and information on judgments. It represents the Judicial Office, which reports to the Lord Chief Justice and …

  1. Anonymous Coward
    Unhappy

    Doesn't surprise me.

    I'm amazed it doesn't simply ask you to download a form and fax it to them.

    1. RosslynDad

      Re: Doesn't surprise me.

      After you've paid your 200 Guineas

  2. Thrud61
    Facepalm

    Expired cert does not mean in the clear

    This article is a bit misleading, just because a certificate has expired does NOT mean that the communications are no longer encrypted. You just can't verify that the cert used for the encryption belongs to the site you go to.

    1. DanDanDan

      Re: Expired cert does not mean in the clear

      "A spokesman from the Judicial Office told El Reg that people wanting to access their site should do so by clicking past the security warning."

      Good grief!

      "... just because a certificate has expired does NOT mean that the communications are no longer encrypted"

      No, but it may as well. If I can't be sure who gave me the info, or who I'm giving it to, it hardly matters that it's encrypted at all!

      1. trickie

        Re: Expired cert does not mean in the clear

        Hardly. The certificate has expired, not been invalidated. If you care then you can still see the signature chain. If you could trust the certificate yesterday based on that information, why can't you trust it today?

        1. Dan 55 Silver badge

          Re: Expired cert does not mean in the clear

          Because you now can't tell the difference between a certificate which expired this morning and a false certificate which has been set up to expire early this morning set up by a MITM, both pop up the same warning.

          It really should make clear that the identity is correct but the certificate expired a little while ago instead of saying 'ARGH, I don't like this certificate at all'. But then again, this shouldn't really have happened in the first place, the site owner should take certificates seriously. In that way a huge great honking warning when something's wrong is the correct way to get site owners into compliance.

  3. CAPS LOCK

    M'learned friends not good with computer?

    I'm shocked.

  4. scoobie

    SSL Check

    Same sort of thing when you try to logon to the aged if.com with Firefox.

    https://my.if.com/Security/Auth/Logon

    Surprising that a bank seems to fail every SSL vulnerability known to man.......

    1. FrankAlphaXII

      Re: SSL Check

      One of them must be that they're using actual SSL instead of TLS. I'd not use them for anything I could avoid it.

      I can't get any https pages from them to load at all, and the only reason I can think of is that I have old-school SSL completely disabled in both Firefox and Windows.

  5. Anonymous Coward
    Anonymous Coward

    Spokesman's name?

    "A spokesman from the Judicial Office told El Reg that people wanting to access their site should do so by clicking past the security warning."

    Justice Wunce, shirley?

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like