Live data from Hacker News

Let's Encrypt is Trusted

letsencrypt.org

101–110 of 318 posts

Re: Let's Encrypt is Trusted

#101
post #53

Yay! Honestly, it is amazing to me that someone like Google or Amazon did not do this as free service a long time ago. But having an independent entity like this do it is far better.

Serious question, to what degree is one defined as being independent? When you have "platinum" sponsors like akamai and cisco, and can take donations through paypal?

They are a separate legal entity, with multiple independent sources of funding and a diverse range of board members[1]. I'm not sure about degrees of independence, but I would say this satisfies my criteria. Are you arguing they aren't really independent of their sponsors?

[1] https://letsencrypt.org/isrg/

Re: Let's Encrypt is Trusted

#102

Earlier quoted context omitted.

No, they have announced their launch schedule in the past. Here is the latest update: https://letsencrypt.org/2015/08/07/updated-lets-encrypt-laun...

But we are waiting for the client, no? If I understand correctly, the client will enable us to install Let’s Encrypt’s certificate on our web server. I assume, “general availability” is when the client will become available for everyone.

The source for the client is here: https://github.com/letsencrypt/letsencrypt

However, their release schedule dictates when the service (yes, the client is part of this) is ready for use.

Until then you are waiting for the service to be available.

Re: Let's Encrypt is Trusted

#104
post #93

Being told that you now trust someone with your secrets via a news website is a pleasingly succinct display of everything that's wrong with the CA model.

I'm not sure what you're getting at. Care to elaborate?

New wannabe CA Entity B can approach an established CA entity A, convince A to sign B's root or intermediate cert, and then B can forge browser-trusted certs for every SSL website on the net that's not pinned.

In this case, B is LetsEncrypt and is (hopefully) pretty solid, but that isn't always the case. Earlier this year, it became known that CNNIC had issued a CA cert to MCS Holdings (of Egypt), which then did bad things.[1]

The news that everyone is suddenly trusting a new entity B, whether it's some Egyptian IT firm, or LetsEncrypt, comes out of nowhere. Neither cooperation nor even awareness is needed of the major browsers' dev teams.

[1] https://googleonlinesecurity.blogspot.com/2015/03/maintainin...

Re: Let's Encrypt is Trusted

#105

I truly appreciate the hard work Let's Encrypt is doing. However, this is not free. In return for getting an SSL certificate, your users will need to trust an organization to protect the secrets they share with you and vice versa. This organization has no economic incentive to do good for you or to do harm to you. What happens when this organization is compelled by the TLA to give up the lucky charms, and there is no…

You protect your secrets with your private key. That organization is only assures that this particular key belongs to your site. They don't have access to your key. Users don't need to trust anything they don't trust yet.

Re: Let's Encrypt is Trusted

#106

I truly appreciate the hard work Let's Encrypt is doing. However, this is not free. In return for getting an SSL certificate, your users will need to trust an organization to protect the secrets they share with you and vice versa. This organization has no economic incentive to do good for you or to do harm to you. What happens when this organization is compelled by the TLA to give up the lucky charms, and there is no…

You protect your secrets with your private key. That organization is only assures that this particular key belongs to your site. They don't have access to your key. Users don't need to trust anything they don't trust yet.

Which is the whole value proposition of a CA. Without this, a website and its clients are vulnerable to MitM attacks.

Re: Let's Encrypt is Trusted

#107

I truly appreciate the hard work Let's Encrypt is doing. However, this is not free. In return for getting an SSL certificate, your users will need to trust an organization to protect the secrets they share with you and vice versa. This organization has no economic incentive to do good for you or to do harm to you. What happens when this organization is compelled by the TLA to give up the lucky charms, and there is no…

I personally argued with the W3C TAG against an HTTPS-only web for this reason. Tim Berners Lee, who heads the TAG, ceremonially speaking, argued against it, too, but on different ground. The browser vendor 'experts' on the TAG totally dismissed any and all argument against forcing everyone to use HTTPS. They were basically told by their employers (the big browser vendors and CDNs like Akamai) to make it happen. HTTPS is a rather costly false sense of security. Now anyone who wants to setup a website, for whatever reason, has to go thru some central authority in the name of "securing the web" (LOL) but it's just another way to control free speech and what people do with the web.

Re: Let's Encrypt is Trusted

#108

I truly appreciate the hard work Let's Encrypt is doing. However, this is not free. In return for getting an SSL certificate, your users will need to trust an organization to protect the secrets they share with you and vice versa. This organization has no economic incentive to do good for you or to do harm to you. What happens when this organization is compelled by the TLA to give up the lucky charms, and there is no…

I personally argued with the W3C TAG against an HTTPS-only web for this reason. Tim Berners Lee, who heads the TAG, ceremonially speaking, argued against it, too, but on different ground. The browser vendor 'experts' on the TAG totally dismissed any and all argument against forcing everyone to use HTTPS. They were basically told by their employers (the big browser vendors and CDNs like Akamai) to make it happen. HTTP…

It's worth noting that Akamai is on the board of the parent organization of Let's Encrypt.

Re: Let's Encrypt is Trusted

#109

I truly appreciate the hard work Let's Encrypt is doing. However, this is not free. In return for getting an SSL certificate, your users will need to trust an organization to protect the secrets they share with you and vice versa. This organization has no economic incentive to do good for you or to do harm to you. What happens when this organization is compelled by the TLA to give up the lucky charms, and there is no…

What secrets are shared? Your private key stays on your server, the CA's private key on theirs...

The main thing that you trust (every) CA to do is to not issue a certificate for your domain to somebody else.

Re: Let's Encrypt is Trusted

#110

I truly appreciate the hard work Let's Encrypt is doing. However, this is not free. In return for getting an SSL certificate, your users will need to trust an organization to protect the secrets they share with you and vice versa. This organization has no economic incentive to do good for you or to do harm to you. What happens when this organization is compelled by the TLA to give up the lucky charms, and there is no…

This is absolutely FUD, even if you don't intend it to be. By what mechanism do you suppose the TLA boogeymen could compel ISRG to give up their private keys, and how would a team of lawyers make one exempt from such mechanisms?

Let's Encrypt is the effort of a benefit corp (ISRG) run by people who care about security and privacy enough to bake it into the foundations of the organization [1]. I think this makes them more trustworthy than for-profit CA's, which have a history of misunderstanding the fundamental roles they play in the security chain, e.g. [2].

1. https://en.wikipedia.org/wiki/Internet_Security_Research_Gro...

2. http://www.computerworld.com/article/2501291/internet/trustw...

Post reply on HN