Yay! Honestly, it is amazing to me that someone like Google or Amazon did not do this as free service a long time ago. But having an independent entity like this do it is far better.
Serious question, to what degree is one defined as being independent? When you have "platinum" sponsors like akamai and cisco, and can take donations through paypal?
Let's Encrypt is Trusted
101–110 of 318 posts
Re: Let's Encrypt is Trusted
#102Earlier quoted context omitted.
No, they have announced their launch schedule in the past. Here is the latest update: https://letsencrypt.org/2015/08/07/updated-lets-encrypt-laun...
But we are waiting for the client, no? If I understand correctly, the client will enable us to install Let’s Encrypt’s certificate on our web server. I assume, “general availability” is when the client will become available for everyone.
However, their release schedule dictates when the service (yes, the client is part of this) is ready for use.
Until then you are waiting for the service to be available.
Re: Let's Encrypt is Trusted
#103It just had to be right after I renewed my SSL cert, didn't it? :P
Re: Let's Encrypt is Trusted
#104Being told that you now trust someone with your secrets via a news website is a pleasingly succinct display of everything that's wrong with the CA model.
I'm not sure what you're getting at. Care to elaborate?
In this case, B is LetsEncrypt and is (hopefully) pretty solid, but that isn't always the case. Earlier this year, it became known that CNNIC had issued a CA cert to MCS Holdings (of Egypt), which then did bad things.[1]
The news that everyone is suddenly trusting a new entity B, whether it's some Egyptian IT firm, or LetsEncrypt, comes out of nowhere. Neither cooperation nor even awareness is needed of the major browsers' dev teams.
[1] https://googleonlinesecurity.blogspot.com/2015/03/maintainin...
Re: Let's Encrypt is Trusted
#105I truly appreciate the hard work Let's Encrypt is doing. However, this is not free. In return for getting an SSL certificate, your users will need to trust an organization to protect the secrets they share with you and vice versa. This organization has no economic incentive to do good for you or to do harm to you. What happens when this organization is compelled by the TLA to give up the lucky charms, and there is no…
Re: Let's Encrypt is Trusted
#106I truly appreciate the hard work Let's Encrypt is doing. However, this is not free. In return for getting an SSL certificate, your users will need to trust an organization to protect the secrets they share with you and vice versa. This organization has no economic incentive to do good for you or to do harm to you. What happens when this organization is compelled by the TLA to give up the lucky charms, and there is no…
You protect your secrets with your private key. That organization is only assures that this particular key belongs to your site. They don't have access to your key. Users don't need to trust anything they don't trust yet.
Re: Let's Encrypt is Trusted
#107I truly appreciate the hard work Let's Encrypt is doing. However, this is not free. In return for getting an SSL certificate, your users will need to trust an organization to protect the secrets they share with you and vice versa. This organization has no economic incentive to do good for you or to do harm to you. What happens when this organization is compelled by the TLA to give up the lucky charms, and there is no…
Re: Let's Encrypt is Trusted
#108I truly appreciate the hard work Let's Encrypt is doing. However, this is not free. In return for getting an SSL certificate, your users will need to trust an organization to protect the secrets they share with you and vice versa. This organization has no economic incentive to do good for you or to do harm to you. What happens when this organization is compelled by the TLA to give up the lucky charms, and there is no…
I personally argued with the W3C TAG against an HTTPS-only web for this reason. Tim Berners Lee, who heads the TAG, ceremonially speaking, argued against it, too, but on different ground. The browser vendor 'experts' on the TAG totally dismissed any and all argument against forcing everyone to use HTTPS. They were basically told by their employers (the big browser vendors and CDNs like Akamai) to make it happen. HTTP…
Re: Let's Encrypt is Trusted
#109I truly appreciate the hard work Let's Encrypt is doing. However, this is not free. In return for getting an SSL certificate, your users will need to trust an organization to protect the secrets they share with you and vice versa. This organization has no economic incentive to do good for you or to do harm to you. What happens when this organization is compelled by the TLA to give up the lucky charms, and there is no…
The main thing that you trust (every) CA to do is to not issue a certificate for your domain to somebody else.
Re: Let's Encrypt is Trusted
#110I truly appreciate the hard work Let's Encrypt is doing. However, this is not free. In return for getting an SSL certificate, your users will need to trust an organization to protect the secrets they share with you and vice versa. This organization has no economic incentive to do good for you or to do harm to you. What happens when this organization is compelled by the TLA to give up the lucky charms, and there is no…
Let's Encrypt is the effort of a benefit corp (ISRG) run by people who care about security and privacy enough to bake it into the foundations of the organization [1]. I think this makes them more trustworthy than for-profit CA's, which have a history of misunderstanding the fundamental roles they play in the security chain, e.g. [2].
1. https://en.wikipedia.org/wiki/Internet_Security_Research_Gro...
2. http://www.computerworld.com/article/2501291/internet/trustw...