{"id":5683,"date":"2018-01-09T10:14:15","date_gmt":"2018-01-09T15:14:15","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=5683"},"modified":"2018-01-09T23:50:12","modified_gmt":"2018-01-10T04:50:12","slug":"conservative-party-website-security-certificate-expire","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/conservative-party-website-security-certificate-expire\/","title":{"rendered":"Whoops, the Conservative Party Lets its Website Security Certificate Expire"},"content":{"rendered":"<h2>UK\u2019s Conservative Party Feels the Heat After Failing to Renew its Website Security Certificate<\/h2>\n<p>While the world had its eyes on Theresa May\u2019s cabinet reshuffle, the UK Conservative Party\u2019s website grabbed the attention of the techie community. The reason behind this was the conservatives\u2019 failure to renew their site\u2019s SSL\/TLS certificate \u2013 the certificate responsible for the connection security of a website.<\/p>\n<p>As a result, the website went down for hours.<\/p>\n<p>This issue came to attention yesterday when any attempts to visit the website (<a href=\"https:\/\/www.conservatives.com\/\" rel=\"nofollow\">https:\/\/www.conservatives.com\/<\/a>) resulted in a warning that said \u201cYour connection is not private. Attackers might be trying to steal your information from www.conservatives.com (for example, passwords, messages or credit cards).&#8221;<\/p>\n<p>This warning led to inevitable social media reactions (there really is no escaping them!). Here\u2019s one tweet that went viral:<\/p>\n<blockquote class=\"twitter-tweet\" data-lang=\"en\">\n<p dir=\"ltr\" lang=\"en\">In the most appropriate possible metaphor for the party&#8217;s failure to grasp 21st-century campaigning, the Conservative website is down, apparently because they&#8217;ve failed to upgrade to HTTPS <a href=\"https:\/\/t.co\/iSHNST91lS\" rel=\"nofollow\">pic.twitter.com\/iSHNST91lS<\/a><\/p>\n<p>\u2014 Robert Colvile (@rcolvile) <a href=\"https:\/\/twitter.com\/rcolvile\/status\/950321098704506880?ref_src=twsrc%5Etfw\" rel=\"nofollow\">January 8, 2018<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>Ultimately, the Conservative Party noticed this and took its website down for a few hours to avoid any potential disasters. After some time, the website came back online with a new certificate, but the damage was already done.<\/p>\n<p>Perhaps the most ironic part of this is that the Conservative party\u2019s own Amber Rudd, Home Secretary, recently made waves when she said she would \u201ccombat\u201d encryption on the premise that it provides a helpful environment for criminals. Upon being pressed, Rudd then admitted she doesn\u2019t understand how encryption works.<\/p>\n<p>Maybe this would be a good opportunity for her to learn.<\/p>\n<h2>If you let your SSL certificate expire, you have only yourself to blame<\/h2>\n<p>Often an ignored part of the SSL certificate process is its renewal. Many people either aren\u2019t aware or just take it for granted believing that an SSL certificate will serve them for the rest of their life. Well, they don\u2019t. For safety purposes, SSL certificates MUST be renewed after a specific time frame (<a href=\"https:\/\/www.thesslstore.com\/blog\/ssl-certificates-expire\/\">if you want to know why SSL certificates expire, here\u2019s an excellent post for you<\/a>). Unfortunately, the technical team for the UK conservative party ignored that fact.<\/p>\n<p>I\u2019m deliberately using the word \u2018ignored\u2019 because there should have been many instances where the certificate authority, as well as the certificate provider, would have reminded them that their certificate was about to expire. In fact, standard practice is to notify at 90, 30, 15, 7, 3 and 1 day before expiration. We know this because our parent company, as an SSL certificate provider, sends out notifications along these exact timelines.<\/p>\n<p>By allowing the certificate to expire, the UK Conservative party also loses any benefits that come from renewing, namely the ability to skip certain steps to expedite validation. You never want to wait until the last minute to purchase or renew an SSL certificate, give yourself a day or two just in case anything goes sideways. Again, you&#8217;ll know when your certificate is about to expire. Even if you&#8217;re not tracking the date on your own, you&#8217;ll be notified.<\/p>\n<p>So, use this as a cautionary tale. If you somehow manage to ignore all of these e-mails, you have only yourself to blame!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>UK\u2019s Conservative Party Feels the Heat After Failing to Renew its Website Security Certificate While the world had its eyes on Theresa May\u2019s cabinet reshuffle, the UK Conservative Party\u2019s website&#8230;<\/p>\n","protected":false},"author":10,"featured_media":5684,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[130],"tags":[182,5793],"class_list":["post-5683","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-everything-encryption","tag-encryption","tag-renewals","post-with-tags"],"views":10684,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/01\/iStock-539041797.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/5683","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=5683"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/5683\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/5684"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=5683"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=5683"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=5683"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}