Live data from Hacker News

Let's Encrypt has issued its first million certificates

eff.org

121–130 of 156 posts

Re: Let's Encrypt has issued its first million certificates

#121
post #2

> It is clear that the cost and bureaucracy of obtaining certificates was forcing many websites to continue with the insecure HTTP protocol I never realized this so clearly, but it's true. The biggest hindrance to security until LE was that certs were expensive and hard to install. I don't think it was so much the former as the latter. I'd gladly pay 10% more for my cert if it meant my server could renew automaticall…

And hosting companies selling certs are incentivised to not provide HTTPS by default.

The number of not https wordpress admin pages and plain text ftp logins still in regular use is chilling and directly attributable to this misaligned incentive.

Re: Let's Encrypt has issued its first million certificates

#122
post #29

Earlier quoted context omitted.

I personally find the hassle of installing, configuring and, crucially, testing , both LetsEncrypts scripts, and an accompanying cronjob, much more work and worry than a static nginx ssl config.

What are you talking about? My nginx ssl config is static as well. It looks at a specific path for my certs, which just happens to be a symlink managed my by letsencrypt tooling. You're going to have to renew anyway. Previously you would have to remember to do that once a year, or maybe once every two years. Now let's ignore the security implications of having certificates that are valid for a year for a moment, and…

Can you update the certificate without taking down your nginx server? I assume you need port 443 for LE to verify your domain, right? Can you use a different port?

Re: Let's Encrypt has issued its first million certificates

#123
post #29
post #2

> It is clear that the cost and bureaucracy of obtaining certificates was forcing many websites to continue with the insecure HTTP protocol I never realized this so clearly, but it's true. The biggest hindrance to security until LE was that certs were expensive and hard to install. I don't think it was so much the former as the latter. I'd gladly pay 10% more for my cert if it meant my server could renew automaticall…

I personally find the hassle of installing, configuring and, crucially, testing , both LetsEncrypts scripts, and an accompanying cronjob, much more work and worry than a static nginx ssl config.

that has to be one of the dumbest things I've read all year.

this is too hard: https://antipaucity.com/2016/02/26/automated-lets-encrypt-ss... ?

Re: Let's Encrypt has issued its first million certificates

#124
post #37

Earlier quoted context omitted.

What are you talking about? My nginx ssl config is static as well. It looks at a specific path for my certs, which just happens to be a symlink managed my by letsencrypt tooling. You're going to have to renew anyway. Previously you would have to remember to do that once a year, or maybe once every two years. Now let's ignore the security implications of having certificates that are valid for a year for a moment, and…

"Once" assuming nothing randomly breaks while you're not looking. What if your cronjob doesn't fire? What if LEs script has a bug and you're not up to date? What if one of the (Python?) dependencies has a bug or breaks? What if LEs servers are being DDoS'd? Can you enumerate and account for all the failure scenarios? I've already botched things with acme-tiny&LE in several different ways. I'm not claiming these risks…

run it @weekly

it's what I do

Re: Let's Encrypt has issued its first million certificates

#125

Earlier quoted context omitted.

What are you talking about? My nginx ssl config is static as well. It looks at a specific path for my certs, which just happens to be a symlink managed my by letsencrypt tooling. You're going to have to renew anyway. Previously you would have to remember to do that once a year, or maybe once every two years. Now let's ignore the security implications of having certificates that are valid for a year for a moment, and…

Can you update the certificate without taking down your nginx server? I assume you need port 443 for LE to verify your domain, right? Can you use a different port?

sure - run the renewal from a different server

Re: Let's Encrypt has issued its first million certificates

#126

Earlier quoted context omitted.

What are you talking about? My nginx ssl config is static as well. It looks at a specific path for my certs, which just happens to be a symlink managed my by letsencrypt tooling. You're going to have to renew anyway. Previously you would have to remember to do that once a year, or maybe once every two years. Now let's ignore the security implications of having certificates that are valid for a year for a moment, and…

Can you update the certificate without taking down your nginx server? I assume you need port 443 for LE to verify your domain, right? Can you use a different port?

Yes, use the "webroot" method of the official Let's Encrypt client.

Re: Let's Encrypt has issued its first million certificates

#127

I host many small sites on a $10/month shared server with a typical LAMP stack host. Unfortunately, SSH access is limited so I keep running into issues getting Let's Encrypt running. Has anyone else run into any issues? Not looking for step-by-step help, just wondering if I'm alone. I have seen paid software promising to solve this [0], but I'd rather not pay to get a free certificate. [0] https://letsencrypt-for-cpa…

Get a shared host that supports Lets Encrypt, there are many.

https://github.com/letsencrypt/letsencrypt/wiki/Web-Hosting-...

Re: Let's Encrypt has issued its first million certificates

#128

Earlier quoted context omitted.

Can you update the certificate without taking down your nginx server? I assume you need port 443 for LE to verify your domain, right? Can you use a different port?

sure - run the renewal from a different server

You can do it on the same server without downtime by using the "webroot" method of the LE client.

Re: Let's Encrypt has issued its first million certificates

#129

Earlier quoted context omitted.

Honest question: why is EV bullshit? It's easier for my mom to check for a green bar saying "Bank of America" than to understand the difference between bankofamerica.com and bankofamerica-onlinebanking491.com. EV may not be bulletproof, but it potentially makes some rather popular attacks way harder to execute at scale.

Well, for one because EV certs are ridiculously overpriced. Also, EV once again just guarantees that someone somewhere has a credit card and some papers they filed. Can I start a "Bang of America" and get an EV cert for that? Sure I can! (Don't google that). Another example of where I think it's confusing is when EV actually uses the company name. Go to https://lastpass.com/ and take a look at their EV green bar. It…

If you think EV certs are over-priced, then there's a big market opportunity waiting for you: just make a CA that sells them cheaper!

In practice, you probably won't do that, because if you look into the various costs EV CAs have, you'll find that the cost of what they're doing is actually non-trivial and it's not exactly a license to print money. Add up the costs of the company, the audits, the hardware to protect the keys, the humans to perform the manual verifications of the cert requests, the OCSP servers, the software dev costs etc ... it's not zero.

With respect to phishing, yes, you could get "Bang of America" (possibly), but this comes with two MASSIVE caveats:

• You cannot do so anonymously, or at least it's very difficult to do so.

• You cannot get something like "Bank of America System Network" because the CAs have procedures in place to stop that sort of thing ... like human review.

In practice, phishing sites based on similar looking letters were a thing decades ago but haven't been so for a long time, partly because there's only a tiny number of such combinations and the legit companies normally own them all. My experience of phishing sites from a few years ago was that they either used misleading DNS names like "www.bankofamerica.com.net.cdn.co.cn" which exploit the fact that people stop reading at ".com", or just didn't care at all and used phishing sites hosted on hacked web servers, which exploit the fact that a lot of people don't ever look at the URL bar at all.

EV is a key step towards fixing both problems, by giving people sensible human meaningful identifiers that are read left to right instead of right to left, and by providing a friendly name that could (in a smart browser) replace the junk in the URL bar entirely. If most sites used EV certs there's a chance users would actually start reading the URL bar again, and then they'd know where they are online.

I agree that companies whose primary web identities don't match their legal identities are an issue for EV certs, although arguably that problem will confuse users sooner or later anyway (e.g. if they need to send/receive money from that company). Better to have the names synced.

Re: Let's Encrypt has issued its first million certificates

#130
post #126

Earlier quoted context omitted.

Can you update the certificate without taking down your nginx server? I assume you need port 443 for LE to verify your domain, right? Can you use a different port?

Yes, use the "webroot" method of the official Let's Encrypt client.

I see, thanks. I use the docker container "version", so I assume I have to somehow mount a volume to the container, that's also accessible from my nginx ( or whatever ) container, so it can serve the static file LE creates. Is there something more to it?
Post reply on HN