Live data from Hacker News

Defending Our Brand

letsencrypt.org

111–120 of 275 posts

Re: Defending Our Brand

#111
post #96

Earlier quoted context omitted.

So, "Pay it Forward" is playing out for real on Hacker News to fight mass or criminal surveillance? Hell, I'm in! Threw them some dough. :)

Is there an easy way to switch from CloudFlare's COMODO to Let's Encrypt? If so I'm in !

Not without turning off CloudFlare. Maybe the CloudFlare Business Plan as well, though I don't know whether it supports multiple non-wildcard certificates.

Re: Defending Our Brand

#114
post #82

Earlier quoted context omitted.

I'm also puzzled that Let's Encrypt's Trademark policy [1] strongly suggests that 'Let's Encrypt' is a trademark (word mark?) that they have registered, and yet according to the most recent letter sent by the USPTO [2] "The Office records have been searched and there are no similar registered or pending marks that would bar registration [...]" [1] https://letsencrypt.org/trademarks/ [2] http://tsdr.uspto.gov/document…

I don't see anything in their trademark policy that implies they have registered any of their marks yet. In fact, all the marks in the "included, but not limited to" list use ™ instead of ®, the later which can only be used with registered trademarks. Searching the USPTO database[1] for "let's encrypt" only reveals Comodo's 1B registrations. All that being said, under US law you still have trademark rights even befor…

This seems like a good example of why you should go through the registration though. Because now they are going to have to use the courts to resolve the situation; presumably (I hope?), if they'd registered, a new registration application for the exact same mark would not even be accepted.

Re: Defending Our Brand

#115
post #107
post #4

The bullshit the CAs pull never ceases to amaze me.

The entire CA model is fundamentally broken: I rely on an entity I have no relationship to vouch for entities it has a relationship with. That makes no sense. The way it should work is that I rely on an entity I do have a relationship with to vouch for entities. Could be public, could be private (I'd prefer private, since that would make resiliency, competition & experimentation more likely).

Technically, you have a relationship: you have their certificate in your computer for your browser to validate against. You can remove it and/or add others.

The problem is that a single entity can vouch for each site, so if you don't want to trust it, you can't validate the site at all. Moxie's Convergence[¹] proposal - like Carnegie Mellon's Perspectives Project before - avoids this problem by allowing many entities to vouch for the same site.

[1] https://en.wikipedia.org/wiki/Convergence_%28SSL%29

Re: Defending Our Brand

#117
post #57

Earlier quoted context omitted.

Lets encrypt certs are only valid for 3 months. In many situations the auto-renewal stuff is inconvenient. Then its easier to just buy a commercial cert that's valid for a few years.

I always use acme-tiny [0] to set up LE certs. You can follow their README to set up everything, including automatic reneweal cronjob in a couple minutes. 0: https://github.com/diafygi/acme-tiny#readme

That's not always an option. For example, when I was looking into it for google app engine, I came across these directions: http://blog.seafuj.com/lets-encrypt-on-google-app-engine and http://igorartamonov.com/2015/12/lets-encrypt-ssl-google-app...

That's not so bad if you have to do it once a year or better yet once every two years, but I'm not doing that every 3 months.

There's an issue open to allow for the process to be automated, hopefully by the next time I need to renew it'll be available. But as it stands today I went with a paid certificate.

Re: Defending Our Brand

#118
post #82

Earlier quoted context omitted.

I'm also puzzled that Let's Encrypt's Trademark policy [1] strongly suggests that 'Let's Encrypt' is a trademark (word mark?) that they have registered, and yet according to the most recent letter sent by the USPTO [2] "The Office records have been searched and there are no similar registered or pending marks that would bar registration [...]" [1] https://letsencrypt.org/trademarks/ [2] http://tsdr.uspto.gov/document…

I don't see anything in their trademark policy that implies they have registered any of their marks yet. In fact, all the marks in the "included, but not limited to" list use ™ instead of ®, the later which can only be used with registered trademarks. Searching the USPTO database[1] for "let's encrypt" only reveals Comodo's 1B registrations. All that being said, under US law you still have trademark rights even befor…

Ah, ok. I hadn't realised there was a difference between registering a trademark and just publicly claiming it as your own. That helps to clear up what the situation is here.

Re: Defending Our Brand

#119

Learning this, I will not renew my certs with Comodo. This is childish behaviour on Comodos part. If it helps I'll advise any companies I consult to do the same until this changes. Money is the only thing this company will understand.

I've avoided the big issuers for a while now. Big plug for Digicert who are excellent - they're independent (so not conflicted), have great infrastructure (fastest on OSCP), super support and active in pushing standards such as CT, short-lived certs, and adopting .onion support after internal names were deprecated.

I use LetsEncrypt in most cases (and have companies I work with donate a portion of what they used to spend) and then DigiCert for EV SAN.

Re: Defending Our Brand

#120

There are also others trying to cash in on this. StartSSL recently started a "Start Encrypt" product which is based on similar ideas.

I see "Start Encrypt" as a capitalist answer to a competing product with (very) cheesy marketing, while what Comodo tries to do is purely malicious. IMHO we can't put them in the same basket.

> I see "Start Encrypt" as a capitalist answer to a competing product with (very) cheesy marketing

Also with very cheesy and bad grammar.

Post reply on HN