Live data from Hacker News

Let's Encrypt makes certs for 30% of web domains

leebutterman.com

111–120 of 147 posts

Re: Let's Encrypt makes certs for 30% of web domains

#111
post #39

Earlier quoted context omitted.

Just so people don't get an oversimplified view of what it takes to start a CA from this comment, you will have much bigger challenges than access to application software. Your first issue will be securing millions of dollars per year for the staff that it takes to run the CA responsibly. Your next issue will be getting trusted by browsers. Also, the open source Let's Encrypt CA software is tailored for how we do thi…

What do you think is a realistic estimate to get a new CA off the ground? Just the minimal cost for hardware and audits and whatnot to create the required artifacts and get them into the three major root programs. Not including staff and ongoing operational expenses (I can estimate that myself). I’ve heard it can be done for as little as $250,000. Also, timeline. It took Let’s Encrypt a couple years to get in root pr…

Not much: https://bugzilla.mozilla.org/show_bug.cgi?id=647959

It's not about the money, either. LetsEncrypt had their intermediate certificates cross-signed by IdenTrust, otherwise they wouldn't have the 30% market share.

It takes a lot of time with the CA application process. You will need to convince Microsoft, Apple, Mozilla, Java, etc that you will be a good CA with good practices. Multiple security audits (starting at about $40K... KPMG don't come cheap), hardware (HSM, servers for validation, OCSP, CT, etc) and people (needs to be trusted people, and often are paid top dollars).

It's easy to _buy_ a CA than creating one. You can get your new root certificates included later easily now that you have a root already, from which you can cross-sign until they are included. CAs are sold out more often than many of us think.

Re: Let's Encrypt makes certs for 30% of web domains

#112
post #16

This kind of centralization is not good. Even thought let's encrypt is non profit and has a very good service record. We desperately need more like it spread around the globe.

What problems would decentralization solve here?

You mean like Linux and Git, or do you mean like "blockchain brofedora authoritarian lulz"?

Re: Let's Encrypt makes certs for 30% of web domains

#113
post #22
post #16

Earlier quoted context omitted.

What problems would decentralization solve here?

Competition is always good. For one, a completely decoupled and separately managed system on a different stack would improve availability of ACME-based certificates. It would also reduce the concentration of trust in one entity. While LE is awesome, the target on their back is only getting bigger. For what it's worth, I'm pretty sure even Let's Encrypt wants to see competitors to Let's Encrypt.

If you're working for profit, competition is awful. If you're not working for profit competition may or may not be good. Regardless, how you personally feel about competition isn't relevant here.

Re: Let's Encrypt makes certs for 30% of web domains

#114
post #68
post #58

Earlier quoted context omitted.

> It would also reduce the concentration of trust in one entity. No it wouldn't. If there are 9999 CAs, you need to trust every single one of them. A better argument for having multiple CAs is that it would increase resilience (against takedowns, bugs, money running out, etc.)

Convergence was a project to have multiple notaries to vouch for a TLS certificate instead of a chain of CAs. There are way to decentralize the internet, but there never will be much interest for it.

Extremely funny video by Moxie Marlinspike about it:

https://m.youtube.com/watch?v=Z7Wl2FW2TcA

Re: Let's Encrypt makes certs for 30% of web domains

#115
post #34
post #19

Earlier quoted context omitted.

Letsencrypt doesnt issue certs to Iran, Syria, Cuba, Sudan et al.

Yes we do. On what basis did you make that statement? We comply with U.S. sanctions by not issuing to entities on the SDN list, but that doesn't prevent us from serving the vast majority of people in those countries.

Well that's interesting, so these are political certs?

Re: Let's Encrypt makes certs for 30% of web domains

#116

Earlier quoted context omitted.

Yeah the software is open source, any other CA has the ability to pick it up ajd implement a similar service.

Yup, but no incentive. They are literally making millions of dollars for a fraction of a penny in CPU time to sign a cert. Why offer the same thing for free? Try to sell it as more secure and trick lots of people...

who ever said free? they could make a paid service like LE with automated renewals etc that integrates better with enterprise software, or that does better audit logging, or any number of things. let’s encrypt is a great service, but there’s still plenty of money to be made off overzealous corporate security policies

Re: Let's Encrypt makes certs for 30% of web domains

#118
post #111

Earlier quoted context omitted.

What do you think is a realistic estimate to get a new CA off the ground? Just the minimal cost for hardware and audits and whatnot to create the required artifacts and get them into the three major root programs. Not including staff and ongoing operational expenses (I can estimate that myself). I’ve heard it can be done for as little as $250,000. Also, timeline. It took Let’s Encrypt a couple years to get in root pr…

Not much: https://bugzilla.mozilla.org/show_bug.cgi?id=647959 It's not about the money, either. LetsEncrypt had their intermediate certificates cross-signed by IdenTrust, otherwise they wouldn't have the 30% market share. It takes a lot of time with the CA application process. You will need to convince Microsoft, Apple, Mozilla, Java, etc that you will be a good CA with good practices. Multiple security audits (start…

That link is amazing. Thank you for that.

Yea I have a pretty good idea of what’s involved. None of that is impossible to do. Time consuming? Sure. Impossible? Far from it. The root programs have documented processes to get included and will (eventually) accept a legit new CA that’s passed WebTrust audit and has good practices (afaik). Hardest thing is finding someone to cross-sign to accelerate the process. That’s why I asked jaas if he would do so :P.

I run a company that does public key infrastructure stuff (smallstep.com) so I have the software and some of the people. I think I could track down some hosting and a couple operators from a partner or two. What’s left seems like maybe a few hundred thousand a year for audits and HSMs, mostly. Pretty sure I could scrape that together too.

Idunno though. Mostly it’s Friday night and this is a fun thought experiment.

Good thought on buying an existing CA. Are any currently up for sale, I wonder? If anyone who reads this knows, plz email me (mike at smallstep).

Re: Let's Encrypt makes certs for 30% of web domains

#119

This kind of centralization is not good. Even thought let's encrypt is non profit and has a very good service record. We desperately need more like it spread around the globe.

Right. What happens when Let's Encrypt is the only CA and they decide that they don't like you for some reason? All tech companies are under tremendous Twitter pressure not to serve the wrong kinds of people, and this pressure will only intensify. The window of acceptability narrow. Infrastructure diversity is an important check against the ability of vocal but small groups of activists to effectively censor the internet.

Re: Let's Encrypt makes certs for 30% of web domains

#120
post #111

Earlier quoted context omitted.

Not much: https://bugzilla.mozilla.org/show_bug.cgi?id=647959 It's not about the money, either. LetsEncrypt had their intermediate certificates cross-signed by IdenTrust, otherwise they wouldn't have the 30% market share. It takes a lot of time with the CA application process. You will need to convince Microsoft, Apple, Mozilla, Java, etc that you will be a good CA with good practices. Multiple security audits (start…

That link is amazing. Thank you for that. Yea I have a pretty good idea of what’s involved. None of that is impossible to do. Time consuming? Sure. Impossible? Far from it. The root programs have documented processes to get included and will (eventually) accept a legit new CA that’s passed WebTrust audit and has good practices (afaik). Hardest thing is finding someone to cross-sign to accelerate the process. That’s w…

LE are pretty open about their expenses, ~$3.6m a year currently, if I remember correctly.

They got bootstrapped with a cross-signing from IdenTrust and so were able to get off the ground fairly quickly. That won't have been cheap, and I'd be very surprised if anyone would offer the same service now - there's some pretty big risks associated with it.

Getting a new trusted CA off the ground is slow and expensive, sadly, and of course you can't really issue anything 'trusted' until you get a critical mass of browsers and OSs to include and distribute the root. Of course it's quicker now than it used to be, with automated updates and better update cadence. You'll still have problems in some areas (embedded devices, older Android devices). Funny how a project can have problems because there's a ton of customers with 'smart' TVs that only support old roots and have no update mechanism...

Buying a CA or an existing root is the best way for now, probably. Not cheap. Amazon and Google both did this (roots from GoDaddy and Globalsign respectively). Not sure if any are for sale at the moment, but it would never hurt to ask - although the pricetag might be scary!

(Disclosure: I've been doing this over 16 years, at one of the larger CAs. nick -at- sectigo -dot- com)

Post reply on HN