Let's Encrypt is Trusted
241–250 of 318 posts
Re: Let's Encrypt is Trusted
#242Er... you're trusted by a CA that's owned by a company that resides in Austin Texas... Texas hasn't exactly got a glowing reputation in the software industry due to its mountain of intellectual property lawsuits filed by patent trolls... er, sorry, I mean non-practicing entities Excuse me while I reserve some skepticism about just how trusted your security certificates should be.
Absolutely pointless and irrelevant. This is the same logic that Donald Trump uses to dismiss all Mexican people as rapists.
Re: Let's Encrypt is Trusted
#243Er... you're trusted by a CA that's owned by a company that resides in Austin Texas... Texas hasn't exactly got a glowing reputation in the software industry due to its mountain of intellectual property lawsuits filed by patent trolls... er, sorry, I mean non-practicing entities Excuse me while I reserve some skepticism about just how trusted your security certificates should be.
I'm not sure what you think CAs have to do with patent trolling. If there was a patent on the PKI, many large companies would have been sued already.
Re: Let's Encrypt is Trusted
#244Earlier quoted context omitted.
I personally argued with the W3C TAG against an HTTPS-only web for this reason. Tim Berners Lee, who heads the TAG, ceremonially speaking, argued against it, too, but on different ground. The browser vendor 'experts' on the TAG totally dismissed any and all argument against forcing everyone to use HTTPS. They were basically told by their employers (the big browser vendors and CDNs like Akamai) to make it happen. HTTP…
Thank you. Demanding TLS while insisting on keeping our broken PKI alive is saying that anonymous publishing is impossible. Just look at the stupid way browsers treat self-signed certificates: these are strictly better than plaintext, but plaintext gets no warning and self-signed certificates are warned about and in some cases actually blocked. Similarly, one mailer (exim, I think?) on seeing an untrusted certificate…
Technically, yes. UI-wise, no. People have different expectations for https:// URLs, which would be broken if browsers simply accepted any self-signed cert.
No excuse for the mailer behaviour, though.
Re: Let's Encrypt is Trusted
#245I really dislike the fact that a CA is able to bless a new CA completely independently. Does this cause anyone else the slightest amount of anxiety, or am I just being paranoid?
You're right that this sort of broad power is scary, but I think it's being used reasonably in this context. Do you have specific concerns you are afraid of? The only problem I thought of was a compromised CA cross-signing a malicious CA, but if they are compromised, you could just issue the main CAs certs anyway.
Re: Let's Encrypt is Trusted
#246Being told that you now trust someone with your secrets via a news website is a pleasingly succinct display of everything that's wrong with the CA model.
An encrypted communication channel specifically doesn’t say that you trust the person at the other end with your secrets. It means that you both agree that the secrets being transferred are safe from 3rd parties.
Re: Let's Encrypt is Trusted
#247I really dislike the fact that a CA is able to bless a new CA completely independently. Does this cause anyone else the slightest amount of anxiety, or am I just being paranoid?
Re: Let's Encrypt is Trusted
#248Earlier quoted context omitted.
Probably just that we're being told who to trust, instead of deciding who to trust.
So you trust yourself more than everyone behind Let's Encrypt, et al? Of course, you don't have to use Let's Encrypt so you do have a choice.
Re: Let's Encrypt is Trusted
#249Earlier quoted context omitted.
Let's Encrypt is also limited in that it issues Domain Validated certificates only. They aren't planning on issuing EV certificates (the "green address bar").
Probably because EV certs are a stupid idea. Do you really know the difference between Citi Bank and Citibank? No? Then EV hasn't saved you from being phished.
Re: Let's Encrypt is Trusted
#250Earlier quoted context omitted.
I don't think that's true anymore, see https://www.cloudflare.com/ssl ("Full SSL" and "Full SSL (strict)" options)
Unfortunately, this means you either have to use a self-signed cert which CloudFlare will not verify at all (meaning it can be MITMed) or use one signed by a trusted CA... which brings you back to square one.
Use this to serve e.g. an S3 site on your own domain using SSL: S3 -> CloudFlare (with CloudFront) uses Amazon's certificates for their hostnames. Cloudflare -> internet uses your website's hostname and certificates.
Total money spent on SSL: $0.