Live data from Hacker News

Let's Encrypt is Trusted

letsencrypt.org

141–150 of 318 posts

Re: Let's Encrypt is Trusted

#141

Earlier quoted context omitted.

Ah, but to use the Full SSL options you need an SSL on your origin server (which CloudFlare doesn't provide for free)!

That certificate can be self signed.

In which case, it can be easily MITM'd by an attacker sitting between CloudFlare and your server, which makes it only slightly better than plain HTTP. It would have been great if CloudFlare let the user to upload and pin a specific self-signed certificate that it could then validate to prevent such attacks.

Re: Let's Encrypt is Trusted

#142

Earlier quoted context omitted.

Ah, but to use the Full SSL options you need an SSL on your origin server (which CloudFlare doesn't provide for free)!

That certificate can be self signed.

I think there was some rumors that they are - or are planing - to offer certificates signed by a private Cloudflare CA exactly for the purpose of encrypting the traffic to the backend.

Re: Let's Encrypt is Trusted

#143

Earlier quoted context omitted.

StartSSL is the opposite of user friendly.

Here's a cert! Hopefully you still have it around somewhere when you try to renew in a year!

The best part is, the cert you use to log in to your account itself expires after a year. So if you don't renew it in time you lose the ability to log in and issue a new certificate for your site, right at around the time your site's certificate expires.

Re: Let's Encrypt is Trusted

#144
post #93

Earlier quoted context omitted.

I'm not sure what you're getting at. Care to elaborate?

New wannabe CA Entity B can approach an established CA entity A, convince A to sign B's root or intermediate cert, and then B can forge browser-trusted certs for every SSL website on the net that's not pinned. In this case, B is LetsEncrypt and is (hopefully) pretty solid, but that isn't always the case. Earlier this year, it became known that CNNIC had issued a CA cert to MCS Holdings (of Egypt), which then did bad…

How is this any worse than trusting the original CA? There's almost assuredly some high standard they use to cross sign, and they'd get revoked if they do that incorrectly. You're failing to note that MCS was revoked as was CNNIC. So, boom, 2 bad/laughably incompetent players are out.

Trusting a CA means trusting them to write certs, even via an intermediary. If you don't actually trust them, remove those CAs.

The CA model has lots of problems, but I don't see what additional harm this actually causes.

Re: Let's Encrypt is Trusted

#145
post #93

Being told that you now trust someone with your secrets via a news website is a pleasingly succinct display of everything that's wrong with the CA model.

I'm not sure what you're getting at. Care to elaborate?

Probably just that we're being told who to trust, instead of deciding who to trust.

Re: Let's Encrypt is Trusted

#146

Earlier quoted context omitted.

They are not quite the same thing: * CloudFlare doesn't give you a certificate. It terminates your TLS connection at their endpoint with a certificate they own the private key to. * StartSSL free tier is for non-commerical use only. * Haven't used WoSign so no idea what it is, but clicking on the link took was so laggy it didn't give me much confidence. (I personally wouldn't work with a company in China jurisdiction…

> user-friendly This is the key. StartSSL is NOT user-friendly at all, even if you want to use it for the non-commercial personal use that it was designed for.

I'm quite pleased with StartSSL.

Although i agree that their user interface isn't that much user friendly, it took me just a couple of hours to learn how the process is handled at StartSSL.

You let them create a certificate you then use for your login process. Then you validate your domain by email and then you're pretty much valid to pump out as much certificates as you want.

Only drawback is that the certificates are only valid for one year.

Re: Let's Encrypt is Trusted

#147
post #93

Earlier quoted context omitted.

I'm not sure what you're getting at. Care to elaborate?

Probably just that we're being told who to trust, instead of deciding who to trust.

I guess we could have some kind of web of trust system instead. But are there any web of trust systems that actually work in practice?

Re: Let's Encrypt is Trusted

#148

From a comment on a similar reddit-thread[1]: > So thus beings the transition. EV certs are going to be the only ones that get the "green" chrome in browsers anymore. Sites using standard SSL are going to get the normal no-lock/white treatment. And sites without SSL will get the caution symbol/yellow treatment. I don't like it, but I suspect this is where we're heading. [1] https://www.reddit.com/r/linux/comments/3pg…

"EV certs are going to be the only ones that get the 'green' chrome in browsers anymore."

Are there any facts to back up this claim?

Edit: This is what HN looks like in Firefox 38.0.5: http://img4.imagetitan.com/img4/RsbN6Rsn61k2IMN/12/12_l.png

Sure, the background color is white, but there's still a padlock icon.

Re: Let's Encrypt is Trusted

#149

Earlier quoted context omitted.

> user-friendly This is the key. StartSSL is NOT user-friendly at all, even if you want to use it for the non-commercial personal use that it was designed for.

I'm quite pleased with StartSSL. Although i agree that their user interface isn't that much user friendly, it took me just a couple of hours to learn how the process is handled at StartSSL. You let them create a certificate you then use for your login process. Then you validate your domain by email and then you're pretty much valid to pump out as much certificates as you want. Only drawback is that the certificates a…

> it took me just a couple of hours > to learn how the process is handled at StartSSL. Well, if something takes 'just a couple of hours' to learn i'll happily fork over some money to ease the pain. You can get certificates for $10/year nowadays.
Post reply on HN