Live data from Hacker News

Let's Encrypt is Trusted

letsencrypt.org

281–290 of 318 posts

Re: Let's Encrypt is Trusted

#281
post #193

I truly appreciate the hard work Let's Encrypt is doing. However, this is not free. In return for getting an SSL certificate, your users will need to trust an organization to protect the secrets they share with you and vice versa. This organization has no economic incentive to do good for you or to do harm to you. What happens when this organization is compelled by the TLA to give up the lucky charms, and there is no…

I think there's a misconception here about the CA model. Let's Encrypt users (in almost every respect) are not more exposed to risks of Let's Encrypt misissuing certificates. (They are more exposed to risks of Let's Encrypt wrongly revoking a certificate, but that creates an availability risk rather than an integrity or confidentiality risk.) In particular, Let's Encrypt never has access to your server's private key…

Let me also add that there is a "team of lawyers" to help resist attempts to force ISRG to violate its policies or betray its users. It's not clear to me that all for-profit CAs would resist such attempts better than a CA founded by EFF and Mozilla and with a Stanford law professor on the board.

I'll also note that ISRG is publishing legal transparency reports, something which is still not very common in the CA industry.

https://letsencrypt.org/documents/ISRG-Legal-Transparency-Re...

Re: Let's Encrypt is Trusted

#282

The headline is wrong and not very clever for such a project. The project was able to get a CA to sign their keys, this is what happened. Using the word "trust" is simply wrong and might be interpreted as a too simple kind of propaganda after we learned a lot about the untrustable nature of a hierarchical certification infrastructure. Another, even bigger trust-breaking elephant in the room is the fact that this proj…

There is no U.S. law that compels us to "offer MITM access to every Let's Encrypt trusted network stream".

TLS sessions are negotiated between TLS clients and servers. Their confidentiality is guaranteed by that negotiation and the certificate authority, if any, doesn't have the server's private key and can't read the server's TLS sessions.

What CAs have the power to do is misissue certificates. Using a CA's services generally does not increase your exposure to misissuance attacks by that CA. If Let's Encrypt misissues certificates, it could misissue them for sites that are not and never have been Let's Encrypt users, just as any other CA can issue certificates for any public Internet service.

As I've said elsewhere, Let's Encrypt wants to use, and encourage others to use, technologies that limit our power to do the wrong thing, including HPKP and Certificate Transparency. We want more limits on our power and other CAs' power, not fewer, that lead to misissuance events getting caught and attacks on TLS users failing.

Re: Let's Encrypt is Trusted

#283

Earlier quoted context omitted.

Nothing you said is a reason for not using Let's Encrypt.

To be clear, I am massively excited to use Let's Encrypt and plan on setting up SSL for the first time ever when it launches. I am legit broke so I can't afford to pay a lot of money for someone to have an automated process of: gpg --gen-key I was responding to parent, that announcing trust is a werid quirk of the CA model. TBH, that is correct, but I find it more bizarre Let's Encrypt has to be "trusted" by an unkno…

Although I loved your sarcastic remarks about the cool pictures, I do want to point out that there are two issues with your argument:

a) There is something else that you know about IdenTrust, and that is that your browser vendor trusts them. This is the whole point of this CA thing: in the end you trust whom your browser vendor trusts (with the option of removing CAs for which you disagree). This is far from perfect (especially since the vendors' vetting process can be quite opaque), but it is not nothing - after all, you should trust your browser vendor, otherwise all the encryption of the world can't save you from someone eavesdropping on your websurfing.

b) Your argument can be read (or misconstrued?) to state that it would be perfectly reasonable to trust IdenTrust if they had a 2015-looking, professional website written in Angular and node instead. Which, of course, is not the case as many who entrusted their money to fraudsters with professional looking websites will be able to attest to.

Re: Let's Encrypt is Trusted

#284
post #270

Earlier quoted context omitted.

They are not quite the same thing: * CloudFlare doesn't give you a certificate. It terminates your TLS connection at their endpoint with a certificate they own the private key to. * StartSSL free tier is for non-commerical use only. * Haven't used WoSign so no idea what it is, but clicking on the link took was so laggy it didn't give me much confidence. (I personally wouldn't work with a company in China jurisdiction…

FYI, StartSSL's free personal SSL certificate only valid for new users for the first year, requires a valid U.S. physical non-commercial address for registration and is subject to $79 for revocation fee. Oh, it's definitely not automated, someone would have to email you back and force a couple times to complete the provision process. I wouldn't bother with StartSSL with that many catches and hassles. How do I know? I…

> FYI, StartSSL's free personal SSL certificate only valid for new users for the first year

They only allow one-year certs to be generated, but you can renew them and get as many of them as you want. I've got class one certs from them for two different domains, and I've replaced both those certs twice as they've expired.

Then again, maybe they've changed their policies in the past six months.

> requires a valid U.S. physical non-commercial address for registration

Does it? I'm based in Ireland, and I haven't had to provide the with a valid US physical address, unless this is something new that they've brought in during the last half a year or so.

> and is subject to $79 for revocation fee.

Yup, that's the most annoying thing about dealing with them.

> Oh, it's definitely not automated, someone would have to email you back and force a couple times to complete the provision process.

I can't say I've had that issue myself. They're not as fast as I'd like, but I've never had any major problems with them.

Re: Let's Encrypt is Trusted

#285

Earlier quoted context omitted.

Wouldn't they just need to verify control of the domain, instead of a single host on the domain? If I control example.com, it's fair to believe I can control all hosts on the domain.

How do you verify control of a domain? Their current mechanisms verify control of a _host_ pointed to by a hostname, not of a domain. They'd need different mechanisms to verify control of a domain. If you control the domain `example.com`, sure. if you just control the single host that `example.com` points to, that doesn't neccesarily mean you control the domain, and in fact DNS contortions are needed to even have exa…

If you can contort DNS in such a way that the domain example.com directs to a host you control...then I'd say you control the domain.

Re: Let's Encrypt is Trusted

#286

I truly appreciate the hard work Let's Encrypt is doing. However, this is not free. In return for getting an SSL certificate, your users will need to trust an organization to protect the secrets they share with you and vice versa. This organization has no economic incentive to do good for you or to do harm to you. What happens when this organization is compelled by the TLA to give up the lucky charms, and there is no…

I personally argued with the W3C TAG against an HTTPS-only web for this reason. Tim Berners Lee, who heads the TAG, ceremonially speaking, argued against it, too, but on different ground. The browser vendor 'experts' on the TAG totally dismissed any and all argument against forcing everyone to use HTTPS. They were basically told by their employers (the big browser vendors and CDNs like Akamai) to make it happen. HTTP…

>Now anyone who wants to setup a website, for whatever reason, has to go thru some central authority

Which 99% of people already do when the buy a domain name.

There is NO evidence that using SSL restricts your freedom of speech. There is evidence to the contrary though, where SSL allowed people to speak freely without having their communications intercepted or monitored.

Certificate Authorities only reject websites for certificates in rare cases where the domain bears resemblance to a well known company (such as "paaypal.com" or "microsoftproducts.com"). This is not something that every CA does not something that a CA HAS to do.

There is no "false" sense of security HTTPS IS encrypted, and CA signed certificates ARE authenticated. Claims that the whole CA system is MiTM by government are largely unsupported, and if you believe that, then you are screwed over HTTP anyway.

I dont disagree that there are some disadvantages to an HTTPS-only web, but those generalizations are wrong.

Re: Let's Encrypt is Trusted

#287
post #65

Earlier quoted context omitted.

I tried to sign up for one, once, and it was broken. I don't remember the circumstances, precisely. Have you actually ever gotten one?

The last time I tried to use StartSSL, I kept getting an SSL failure on https://auth.startssl.com/.. . Go figure. I ended up paying $10 on namecheap instead.

Probably an issue with the client cert. I remember running into that the last time I attempted to get a cert through them.

Re: Let's Encrypt is Trusted

#288

Earlier quoted context omitted.

Wouldn't they just need to verify control of the domain, instead of a single host on the domain? If I control example.com, it's fair to believe I can control all hosts on the domain.

How do you verify control of a domain? Their current mechanisms verify control of a _host_ pointed to by a hostname, not of a domain. They'd need different mechanisms to verify control of a domain. If you control the domain `example.com`, sure. if you just control the single host that `example.com` points to, that doesn't neccesarily mean you control the domain, and in fact DNS contortions are needed to even have exa…

You could verify ownership of the DNS config for the domain. It's not all that uncommon to verify ownership of a domain for various services by sticking something in a TXT record on that domain (or on a specially-named subdomain). LetsEncrypt could do something similar to verify top-level ownership. After all, if I have control over the DNS zone, then I trivially have control of any host on the domain too (just point the DNS at my own server).

Another benefit of this is ownership can be validated on an ongoing basis (is the TXT record still there? yup, still valid) without requiring any software to be running on any hosts at that domain. And you can validate a domain without even having an A record if you want (say, if you're getting all your ducks in a row before exposing your server to the world).

Re: Let's Encrypt is Trusted

#289

Earlier quoted context omitted.

How is this any worse than trusting the original CA? There's almost assuredly some high standard they use to cross sign, and they'd get revoked if they do that incorrectly. You're failing to note that MCS was revoked as was CNNIC. So, boom, 2 bad/laughably incompetent players are out. Trusting a CA means trusting them to write certs, even via an intermediary. If you don't actually trust them, remove those CAs. The CA…

Because it doesn't settle with having as many single points of failure as the number of CA entries in your root CA list, they are getting multiplied over and over.

How would it be any different if these CA's made a choice to instead issue end-user certs but based off of Let's Encrypt's authorization?

Re: Let's Encrypt is Trusted

#290
What does this mean to a new user? Can I now get a ssl certificate? will it be cheaper, or even free? I saw they have a beta-program for the certificate but don't know what it exactly does.
Post reply on HN