SSL certs sound like something that should be in a blockchain. Why isnt it?
Because where is the incentive? Why would anyone be a "miner"? What reward would there be?
Let's Encrypt makes certs for 30% of web domains
81–90 of 147 posts
Re: Let's Encrypt makes certs for 30% of web domains
#82SSL certs sound like something that should be in a blockchain. Why isnt it?
How would proving control of a domain work?
Re: Let's Encrypt makes certs for 30% of web domains
#83Earlier quoted context omitted.
What problems would decentralization solve here?
Competition is always good. For one, a completely decoupled and separately managed system on a different stack would improve availability of ACME-based certificates. It would also reduce the concentration of trust in one entity. While LE is awesome, the target on their back is only getting bigger. For what it's worth, I'm pretty sure even Let's Encrypt wants to see competitors to Let's Encrypt.
Re: Let's Encrypt makes certs for 30% of web domains
#84Earlier quoted context omitted.
Competition is always good. For one, a completely decoupled and separately managed system on a different stack would improve availability of ACME-based certificates. It would also reduce the concentration of trust in one entity. While LE is awesome, the target on their back is only getting bigger. For what it's worth, I'm pretty sure even Let's Encrypt wants to see competitors to Let's Encrypt.
> It would also reduce the concentration of trust in one entity. No it wouldn't. If there are 9999 CAs, you need to trust every single one of them. A better argument for having multiple CAs is that it would increase resilience (against takedowns, bugs, money running out, etc.)
Re: Let's Encrypt makes certs for 30% of web domains
#85Earlier quoted context omitted.
Letsencrypt doesnt issue certs to Iran, Syria, Cuba, Sudan et al.
Yes we do. On what basis did you make that statement? We comply with U.S. sanctions by not issuing to entities on the SDN list, but that doesn't prevent us from serving the vast majority of people in those countries.
https://community.letsencrypt.org/t/certificates-for-us-sanc...
Re: Let's Encrypt makes certs for 30% of web domains
#86This doesn't make sense. Even assuming you included the ones that had expired certs in "had a cert that expired in the 2010s", it would only be 1.6+3.7~=5.3M.
Where does the rest 4.3M come from?
Re: Let's Encrypt makes certs for 30% of web domains
#87Earlier quoted context omitted.
Start a LetTheRestOfUsEncrypt.org based in a different country whose government isn't so full of themselves? Or better yet, is there a way to start a decentralized organization itself so that no jurisdiction has absolute power over it?
How are you going to trust that decentralized org? Is it just voting? Can we all vote to revoke anyone's cert at any time for no reason? What happens when someone performs a 51% attack and takes over google.com's cert? CAs exist solely because you CAN trust them, otherwise what's the point? We'd just have every site self-sign and let the users choose who to trust.
That's the idea, but in practice, I don't really trust the vast majority of them.
Re: Let's Encrypt makes certs for 30% of web domains
#88A few of these things, while not necessarily wrong, should be put into context. E.g. "Hundreds of thousands of domains' certs expire after 2099". Yeah, but no publicly trusted certs. They're capped at a bit more than 2 years and there's a discussion to cap them even more. The certs they're seeing are almost certainly mostly: "let's create a test selfsigned cert for this host. how long should it last? let's type in a…
Yes, but... Historically there were some certs that kept getting grandfathered in after lifetimes were restricted because they'd been issued before there were any rules - maybe ten years to expire or even more? I think the last of those probably went away because of the Symantec distrust (not that they were issued by Symantec, but they were issued by a CA which was bought by a CA which in turn was bought by Symantec…
Re: Let's Encrypt makes certs for 30% of web domains
#89Earlier quoted context omitted.
Limiting a bit the impacts if Let's Encrypt is compromised in any way. If Let's encrypt is compromised, either by being able to issue certificate for arbitrary domains or if the CA itself is compromised, the impact would be huge given the current number of certificates signed by it and this number is likely to grow in the futur. With several CAs in different organizations, you have a far lower risk of seeing all the…
What exactly happens if a CA is compromised (private keys stolen etc)? Wouldn't existing certificates before the compromise date still be valid?
Re: Let's Encrypt makes certs for 30% of web domains
#90>Almost 1.6M domains had a cert that had recently expired (in July, the month of the scan). Almost 3.7M domains had a cert that expired in 2019 (the year of the scan). Over 9.6M domains had a cert that expired in the 2010s! This doesn't make sense. Even assuming you included the ones that had expired certs in "had a cert that expired in the 2010s", it would only be 1.6+3.7~=5.3M. Where does the rest 4.3M come from?