Live data from Hacker News

Progress Towards 100% HTTPS, June 2016

letsencrypt.org

11–20 of 109 posts

Re: Progress Towards 100% HTTPS, June 2016

#11

Let’s Encrypt has issued more than 5 million certificates in total since we launched to the general public on December 3, 2015. Approximately 3.8 million of those are active, meaning unexpired and unrevoked. Our active certificates cover more than 7 million unique domains. How can you cover 7 million unique domains if you've only issued 5 million certificates?

One certificate can be for more than one domain.

For example, a single cert can serve www.example.com as well as example.com

Re: Progress Towards 100% HTTPS, June 2016

#12
post #11

Earlier quoted context omitted.

One certificate can be for more than one domain.

For example, a single cert can serve www.example.com as well as example.com

That is true, but in this case I think Let's Encrypt and also parent to your comment mean different domains as in e.g. one certificate to cover all three of example.com, example.net and example.org.

Re: Progress Towards 100% HTTPS, June 2016

#13
post #7

Is it still problematic to issue lots of certs for lots of subdomains? I mean, still no wildcard certs and crazy rate limits, that disallow issuing 1000s of certs per day for user-generated subdomains?

If you're generating that many subdomains (and you control the subdomains), it's probably worth investing in a traditional wildcard cert.

Though, it would be nice if the likes of dyndns names were given exception, since they are effectively second level tld's.

Re: Progress Towards 100% HTTPS, June 2016

#14
Just at the entire world is going HTTPS, my faith in the system is seriously waning. When Symantec bought Blue Coat, it made me start to think about how fragile this is. How long before Symantec gets an NSL demanding an appliance that can mint bogus certs on the fly for dropbox.com, facebook.com, twitter.com, etc...?

How effective is something like certificate pinning against fraudulent certs?

Re: Progress Towards 100% HTTPS, June 2016

#15

Let’s Encrypt has issued more than 5 million certificates in total since we launched to the general public on December 3, 2015. Approximately 3.8 million of those are active, meaning unexpired and unrevoked. Our active certificates cover more than 7 million unique domains. How can you cover 7 million unique domains if you've only issued 5 million certificates?

[deleted]

Re: Progress Towards 100% HTTPS, June 2016

#16
I'm still bitter about this chain of trust model. The fact that I have to get some other party to tell my users that they can trust me just seems wrong. They trust me because of personal history, not because some banner says they should.

Browsers and OS vendors shipping CAs seems to be the root of the problem, in my mind. Those should be distributed by the service providers, who are the actual trustworthy entities in the user's minds.

Re: Progress Towards 100% HTTPS, June 2016

#17

Just at the entire world is going HTTPS, my faith in the system is seriously waning. When Symantec bought Blue Coat, it made me start to think about how fragile this is. How long before Symantec gets an NSL demanding an appliance that can mint bogus certs on the fly for dropbox.com, facebook.com, twitter.com, etc...? How effective is something like certificate pinning against fraudulent certs?

I don't think they would be considered fraudulent at all, and in fact I'm pretty sure that's the "safety valve" built into the system and why public encryption is now being encouraged. I share your tinfoil hatted feelings wholeheartedly.

Re: Progress Towards 100% HTTPS, June 2016

#18
post #11

Earlier quoted context omitted.

For example, a single cert can serve www.example.com as well as example.com

That is true, but in this case I think Let's Encrypt and also parent to your comment mean different domains as in e.g. one certificate to cover all three of example.com, example.net and example.org.

The same mechanism in cert generation provides that functionality. Hostnames are hostnames. SAN certs just take a list of them.

Re: Progress Towards 100% HTTPS, June 2016

#19
post #16

I'm still bitter about this chain of trust model. The fact that I have to get some other party to tell my users that they can trust me just seems wrong. They trust me because of personal history, not because some banner says they should. Browsers and OS vendors shipping CAs seems to be the root of the problem, in my mind. Those should be distributed by the service providers, who are the actual trustworthy entities in…

And when we visit your site for the first time, having never heard of you before, why should we trust you?

That's the point. Having some authority who did at least some minimal checking, to extensive checking, and who will verify you really are who you purport to be. Trust but verify probably plays a part in this.

But, remember, you don't have to go to HTTPS. There is no requirement for you to do so.

Re: Progress Towards 100% HTTPS, June 2016

#20
post #17

Just at the entire world is going HTTPS, my faith in the system is seriously waning. When Symantec bought Blue Coat, it made me start to think about how fragile this is. How long before Symantec gets an NSL demanding an appliance that can mint bogus certs on the fly for dropbox.com, facebook.com, twitter.com, etc...? How effective is something like certificate pinning against fraudulent certs?

I don't think they would be considered fraudulent at all, and in fact I'm pretty sure that's the "safety valve" built into the system and why public encryption is now being encouraged. I share your tinfoil hatted feelings wholeheartedly.

> I don't think they would be considered fraudulent at all

Er, by whom?

Post reply on HN