Live data from Hacker News

Milestone: 100M Certificates Issued

letsencrypt.org

11–20 of 197 posts

Re: Milestone: 100M Certificates Issued

#11
post #6

Nearly 20K of them for Paypal phishing sites and who knows how many for others. While a noble intention, one can't ignore the damage they've done.

0.02% is a lot less than I thought there'd be. There's also nothing stopping people from buying certificates from legacy CAs, do you have the stats on how many non-letsencrypt phishing certificates there are?

Re: Milestone: 100M Certificates Issued

#12
post #6

Nearly 20K of them for Paypal phishing sites and who knows how many for others. While a noble intention, one can't ignore the damage they've done.

That's .02% of all certs issued. A road might enable a bank robber to get away faster, but nobody is complaining that we shouldn't build roads because of it.

Re: Milestone: 100M Certificates Issued

#13
post #6

Nearly 20K of them for Paypal phishing sites and who knows how many for others. While a noble intention, one can't ignore the damage they've done.

I think you misunderstand how domain validated certs work. DV certs have always been issued with the simple check that you own the domain (either by email or by DNS). The email check was always a bit scary because email is so readily forgeable.

Re: Milestone: 100M Certificates Issued

#14
post #2

I think they nail their point with "it illustrates the strong demand for our services." Letsencrypt is cheap (free) and easy to use. Even people with not a lot experience can secure their sites and apps, and it just works. Yes, you have to update it every three months, but that's worth the price and the excellent documentation. Before letsencrypt I always wanted to secure my blog with https but never got around to it…

> Even people with not a lot experience can secure their sites and apps, and it just works. Yes, you have to update it every three months, but that's worth the price and the excellent documentation. This is just a cronjob, no?

If you're comfortable with said cronjob having access to your private key

Re: Milestone: 100M Certificates Issued

#15
post #7
post #6

Nearly 20K of them for Paypal phishing sites and who knows how many for others. While a noble intention, one can't ignore the damage they've done.

What prevented Paypal phishing sites from buying certificates from other providers?

checks they're supposed to be performing. Some are ignoring them but being punished for it. http://www.bbc.com/news/technology-39365315

Re: Milestone: 100M Certificates Issued

#16
post #2

I think they nail their point with "it illustrates the strong demand for our services." Letsencrypt is cheap (free) and easy to use. Even people with not a lot experience can secure their sites and apps, and it just works. Yes, you have to update it every three months, but that's worth the price and the excellent documentation. Before letsencrypt I always wanted to secure my blog with https but never got around to it…

> Even people with not a lot experience can secure their sites and apps, and it just works. Yes, you have to update it every three months, but that's worth the price and the excellent documentation. This is just a cronjob, no?

Cronjob with a script that needs to do some back-and-forth/handshaking, but yes, it is.

Re: Milestone: 100M Certificates Issued

#17
post #6

Nearly 20K of them for Paypal phishing sites and who knows how many for others. While a noble intention, one can't ignore the damage they've done.

Damn it, those people creating those safety belts. Now drug dealers use them too and they don't die when they run away with drugs in their fast cars !

Re: Milestone: 100M Certificates Issued

#18
post #2

I think they nail their point with "it illustrates the strong demand for our services." Letsencrypt is cheap (free) and easy to use. Even people with not a lot experience can secure their sites and apps, and it just works. Yes, you have to update it every three months, but that's worth the price and the excellent documentation. Before letsencrypt I always wanted to secure my blog with https but never got around to it…

I've been very happy with certbot-- the LetsEncrypt automation tool-- and can attest to the ease of use.

Re: Milestone: 100M Certificates Issued

#19
post #6

Nearly 20K of them for Paypal phishing sites and who knows how many for others. While a noble intention, one can't ignore the damage they've done.

Why is nobody complaining about the fraudulent domain names and the registries that enable them? This is where the problem starts. The certificate only proves that the owner has access to the domain, nothing more.

Re: Milestone: 100M Certificates Issued

#20
post #15
post #7

Earlier quoted context omitted.

What prevented Paypal phishing sites from buying certificates from other providers?

checks they're supposed to be performing. Some are ignoring them but being punished for it. http://www.bbc.com/news/technology-39365315

I'd definitely recommend clicking through that article and reading the source of the announcement:

https://groups.google.com/a/chromium.org/forum/m/#!msg/blink...

> As captured in Chrome’s Root Certificate Policy, root certificate authorities are expected to perform a number of critical functions commensurate with the trust granted to them. This includes properly ensuring that domain control validation is performed for server certificates, to audit logs frequently for evidence of unauthorized issuance, and to protect their infrastructure in order to minimize the ability for the issuance of fraudulent certs.

> On the basis of the details publicly provided by Symantec, we do not believe that they have properly upheld these principles, and as such, have created significant risk for Google Chrome users. Symantec allowed at least four parties access to their infrastructure in a way to cause certificate issuance, did not sufficiently oversee these capabilities as required and expected, and when presented with evidence of these organizations’ failure to abide to the appropriate standard of care, failed to disclose such information in a timely manner or to identify the significance of the issues reported to them.

i.e. they apparently weren't even checking requesters controlled the domain they requested a certificate for in some instances!! And that's pretty much the only requirement for DV certificates?

My point is that the legacy ssl providers you're referring to were doing less checks than Lets Encrypt!

Post reply on HN