Live data from Hacker News

Let's Encrypt makes certs for 30% of web domains

leebutterman.com

81–90 of 147 posts

Re: Let's Encrypt makes certs for 30% of web domains

#82
post #20

SSL certs sound like something that should be in a blockchain. Why isnt it?

How would proving control of a domain work?

that's the hardest part, but how is it proved now? by providing evidence. A nonprofit like letsencrypt could be the custodian responsible for onboarding a new cert, after that they dont need to provide anything else. It is a problem that appears exactly once in a blockchain, while cert renewals are their achilles' heel

Re: Let's Encrypt makes certs for 30% of web domains

#83
post #22
post #16

Earlier quoted context omitted.

What problems would decentralization solve here?

Competition is always good. For one, a completely decoupled and separately managed system on a different stack would improve availability of ACME-based certificates. It would also reduce the concentration of trust in one entity. While LE is awesome, the target on their back is only getting bigger. For what it's worth, I'm pretty sure even Let's Encrypt wants to see competitors to Let's Encrypt.

I agree => small question: in this context wouldn't "diversification" be more appropriate than "competition"?

Re: Let's Encrypt makes certs for 30% of web domains

#84
post #58
post #22

Earlier quoted context omitted.

Competition is always good. For one, a completely decoupled and separately managed system on a different stack would improve availability of ACME-based certificates. It would also reduce the concentration of trust in one entity. While LE is awesome, the target on their back is only getting bigger. For what it's worth, I'm pretty sure even Let's Encrypt wants to see competitors to Let's Encrypt.

> It would also reduce the concentration of trust in one entity. No it wouldn't. If there are 9999 CAs, you need to trust every single one of them. A better argument for having multiple CAs is that it would increase resilience (against takedowns, bugs, money running out, etc.)

[deleted]

Re: Let's Encrypt makes certs for 30% of web domains

#85
post #34
post #19

Earlier quoted context omitted.

Letsencrypt doesnt issue certs to Iran, Syria, Cuba, Sudan et al.

Yes we do. On what basis did you make that statement? We comply with U.S. sanctions by not issuing to entities on the SDN list, but that doesn't prevent us from serving the vast majority of people in those countries.

indeed I misread it. you don't provide certs for the governments of those countries (still a limitation tbh). I got that from this post of one of your employees

https://community.letsencrypt.org/t/certificates-for-us-sanc...

Re: Let's Encrypt makes certs for 30% of web domains

#86
>Almost 1.6M domains had a cert that had recently expired (in July, the month of the scan). Almost 3.7M domains had a cert that expired in 2019 (the year of the scan). Over 9.6M domains had a cert that expired in the 2010s!

This doesn't make sense. Even assuming you included the ones that had expired certs in "had a cert that expired in the 2010s", it would only be 1.6+3.7~=5.3M.

Where does the rest 4.3M come from?

Re: Let's Encrypt makes certs for 30% of web domains

#87
post #44

Earlier quoted context omitted.

Start a LetTheRestOfUsEncrypt.org based in a different country whose government isn't so full of themselves? Or better yet, is there a way to start a decentralized organization itself so that no jurisdiction has absolute power over it?

How are you going to trust that decentralized org? Is it just voting? Can we all vote to revoke anyone's cert at any time for no reason? What happens when someone performs a 51% attack and takes over google.com's cert? CAs exist solely because you CAN trust them, otherwise what's the point? We'd just have every site self-sign and let the users choose who to trust.

> CAs exist solely because you CAN trust them, otherwise what's the point?

That's the idea, but in practice, I don't really trust the vast majority of them.

Re: Let's Encrypt makes certs for 30% of web domains

#88
post #9

A few of these things, while not necessarily wrong, should be put into context. E.g. "Hundreds of thousands of domains' certs expire after 2099". Yeah, but no publicly trusted certs. They're capped at a bit more than 2 years and there's a discussion to cap them even more. The certs they're seeing are almost certainly mostly: "let's create a test selfsigned cert for this host. how long should it last? let's type in a…

Yes, but... Historically there were some certs that kept getting grandfathered in after lifetimes were restricted because they'd been issued before there were any rules - maybe ten years to expire or even more? I think the last of those probably went away because of the Symantec distrust (not that they were issued by Symantec, but they were issued by a CA which was bought by a CA which in turn was bought by Symantec…

Minor point - SHA1 root CA certs are trusted by identity, so SHA1 is of no consequence.

Re: Let's Encrypt makes certs for 30% of web domains

#89
post #76
post #64

Earlier quoted context omitted.

Limiting a bit the impacts if Let's Encrypt is compromised in any way. If Let's encrypt is compromised, either by being able to issue certificate for arbitrary domains or if the CA itself is compromised, the impact would be huge given the current number of certificates signed by it and this number is likely to grow in the futur. With several CAs in different organizations, you have a far lower risk of seeing all the…

What exactly happens if a CA is compromised (private keys stolen etc)? Wouldn't existing certificates before the compromise date still be valid?

That's precisely the benefit of requiring a multitude of CA signatures -- no single compromise is capable of having a catastrophic impact.

Re: Let's Encrypt makes certs for 30% of web domains

#90

>Almost 1.6M domains had a cert that had recently expired (in July, the month of the scan). Almost 3.7M domains had a cert that expired in 2019 (the year of the scan). Over 9.6M domains had a cert that expired in the 2010s! This doesn't make sense. Even assuming you included the ones that had expired certs in "had a cert that expired in the 2010s", it would only be 1.6+3.7~=5.3M. Where does the rest 4.3M come from?

Those are certs that not-so-recently expired, the heading is "Millions of certs served have expired".
Post reply on HN