I truly appreciate the hard work Let's Encrypt is doing. However, this is not free. In return for getting an SSL certificate, your users will need to trust an organization to protect the secrets they share with you and vice versa. This organization has no economic incentive to do good for you or to do harm to you. What happens when this organization is compelled by the TLA to give up the lucky charms, and there is no…
Let's Encrypt is Trusted
111–120 of 318 posts
Re: Let's Encrypt is Trusted
#112I truly appreciate the hard work Let's Encrypt is doing. However, this is not free. In return for getting an SSL certificate, your users will need to trust an organization to protect the secrets they share with you and vice versa. This organization has no economic incentive to do good for you or to do harm to you. What happens when this organization is compelled by the TLA to give up the lucky charms, and there is no…
What secrets are shared? Your private key stays on your server, the CA's private key on theirs... The main thing that you trust (every) CA to do is to not issue a certificate for your domain to somebody else.
Re: Let's Encrypt is Trusted
#113Earlier quoted context omitted.
You protect your secrets with your private key. That organization is only assures that this particular key belongs to your site. They don't have access to your key. Users don't need to trust anything they don't trust yet.
Which is the whole value proposition of a CA. Without this, a website and its clients are vulnerable to MitM attacks.
Re: Let's Encrypt is Trusted
#114I truly appreciate the hard work Let's Encrypt is doing. However, this is not free. In return for getting an SSL certificate, your users will need to trust an organization to protect the secrets they share with you and vice versa. This organization has no economic incentive to do good for you or to do harm to you. What happens when this organization is compelled by the TLA to give up the lucky charms, and there is no…
I personally argued with the W3C TAG against an HTTPS-only web for this reason. Tim Berners Lee, who heads the TAG, ceremonially speaking, argued against it, too, but on different ground. The browser vendor 'experts' on the TAG totally dismissed any and all argument against forcing everyone to use HTTPS. They were basically told by their employers (the big browser vendors and CDNs like Akamai) to make it happen. HTTP…
How so? Do you expect browsers to stop serving content from sites using boring old HTTP? And the fact is that we've had to go through a central authority to put a website up for a long time, with DNS.
Re: Let's Encrypt is Trusted
#115I truly appreciate the hard work Let's Encrypt is doing. However, this is not free. In return for getting an SSL certificate, your users will need to trust an organization to protect the secrets they share with you and vice versa. This organization has no economic incentive to do good for you or to do harm to you. What happens when this organization is compelled by the TLA to give up the lucky charms, and there is no…
This is absolutely FUD, even if you don't intend it to be. By what mechanism do you suppose the TLA boogeymen could compel ISRG to give up their private keys, and how would a team of lawyers make one exempt from such mechanisms? Let's Encrypt is the effort of a benefit corp (ISRG) run by people who care about security and privacy enough to bake it into the foundations of the organization [1]. I think this makes them…
Lavabit waa ordered to give up their private key, despite the fact that Lavabit wasn't, itself, under investigation. In other words, they were forced to give up their clients privacy and were given a gag orders.
Attorneys don't exempt anyone from anything, but your comment seems to suggest their existence is for entertainment. A team of attorneys might have found a way out of the mess for Lavabit.
Re: Let's Encrypt is Trusted
#116Earlier quoted context omitted.
What secrets are shared? Your private key stays on your server, the CA's private key on theirs... The main thing that you trust (every) CA to do is to not issue a certificate for your domain to somebody else.
If I know Let's Encrypt's secrets, and I control your network, I can set up a valid certificate on my server and MitM you.
Re: Let's Encrypt is Trusted
#117I truly appreciate the hard work Let's Encrypt is doing. However, this is not free. In return for getting an SSL certificate, your users will need to trust an organization to protect the secrets they share with you and vice versa. This organization has no economic incentive to do good for you or to do harm to you. What happens when this organization is compelled by the TLA to give up the lucky charms, and there is no…
You state "This is not FUD" yet that's exactly what it strikes me as since making a certificate $0 instead of $19 doesn't change anything at all about "the issues that arise from centralized authority in a decentralized economy".
Re: Let's Encrypt is Trusted
#118Earlier quoted context omitted.
No, they have announced their launch schedule in the past. Here is the latest update: https://letsencrypt.org/2015/08/07/updated-lets-encrypt-laun...
But we are waiting for the client, no? If I understand correctly, the client will enable us to install Let’s Encrypt’s certificate on our web server. I assume, “general availability” is when the client will become available for everyone.
Re: Let's Encrypt is Trusted
#119Re: Let's Encrypt is Trusted
#120Earlier quoted context omitted.
Let's Encrypt isn't the first to offer free TLS certificates. I've attempted to maintain a list of all the providers that do (in one way or another), and it's currently 4: * CloudFlare https://www.cloudflare.com/ssl * StartSSL https://startssl.com * WoSign https://buy.wosign.com/free * Let's Encrypt https://letsencrypt.org For people reading this comment dozens of months in the future, a maintained list will be kept…
One of them is not like the other, and that's CloudFlare's free SSL, which is more like "half-SSL". You only get free encryption between Cloudflare and the user, but not between your site and Cloudflare.