The Internet Security Research Group maintaining Let's Encrypt seems quite independent. But Let's Encrypt is free. It already has 0.1% market share (https://w3techs.com/technologies/overview/ssl_certificate/all) despite being on the market for only 5 years. Isn't this simply too good to be true & trusted?
Ask HN: Conspiracy theory – What motivation is behind Let's Encrypt?
1–5 of 5 posts
Re: Ask HN: Conspiracy theory – What motivation is behind Let's Encrypt?
#2LE is currently a big single point of failure, and I want to be able to point my ACME client somewhere else if I need to.
Re: Ask HN: Conspiracy theory – What motivation is behind Let's Encrypt?
#3I don't personally think there's a conspiracy, but I'd definitely like to see an LE 'competitor' - one that is equally as free and open, but not in any way related to the ISRG. LE is currently a big single point of failure, and I want to be able to point my ACME client somewhere else if I need to.
Re: Ask HN: Conspiracy theory – What motivation is behind Let's Encrypt?
#4I don't personally think there's a conspiracy, but I'd definitely like to see an LE 'competitor' - one that is equally as free and open, but not in any way related to the ISRG. LE is currently a big single point of failure, and I want to be able to point my ACME client somewhere else if I need to.
Have you checked out Buypass? https://www.buypass.com/ssl/products/acme
I wasn't aware of Buypass and it looks awesome, unfortunately however it doesn't appear to support SAN or wildcard certificates which could be a dealbreaker for a few (that said, it could also be considered a feature).
But thanks for bringing it up and raising awareness of alternative ACME providers, I'm probably going to spend some time playing around with Buypass Go this week.
Edit: It also appears that Buypass Go certificates are valid for 180 days as opposed to Let's Encrypt's 90 days (haven't verified this yet), which is interesting. I've simply become accustomed to the 90 day LE validity, I'm curious why they went with 180 days.
Re: Ask HN: Conspiracy theory – What motivation is behind Let's Encrypt?
#5I don't personally think there's a conspiracy, but I'd definitely like to see an LE 'competitor' - one that is equally as free and open, but not in any way related to the ISRG. LE is currently a big single point of failure, and I want to be able to point my ACME client somewhere else if I need to.
Have you checked out Buypass? https://www.buypass.com/ssl/products/acme
Looks like a workable alternative, but it still seems to be a commercial organisation behind it though. We need something open, transparent and charitable ideally.