Live data from Hacker News

Let's Encrypt makes certs for 30% of web domains

leebutterman.com

121–130 of 147 posts

Re: Let's Encrypt makes certs for 30% of web domains

#121
post #111

Earlier quoted context omitted.

What do you think is a realistic estimate to get a new CA off the ground? Just the minimal cost for hardware and audits and whatnot to create the required artifacts and get them into the three major root programs. Not including staff and ongoing operational expenses (I can estimate that myself). I’ve heard it can be done for as little as $250,000. Also, timeline. It took Let’s Encrypt a couple years to get in root pr…

Not much: https://bugzilla.mozilla.org/show_bug.cgi?id=647959 It's not about the money, either. LetsEncrypt had their intermediate certificates cross-signed by IdenTrust, otherwise they wouldn't have the 30% market share. It takes a lot of time with the CA application process. You will need to convince Microsoft, Apple, Mozilla, Java, etc that you will be a good CA with good practices. Multiple security audits (start…

If convincing about security best practices was hard, Comodo along with GoDaddy and many other providers would be out of the market.

Re: Let's Encrypt makes certs for 30% of web domains

#122
post #68

Earlier quoted context omitted.

Convergence was a project to have multiple notaries to vouch for a TLS certificate instead of a chain of CAs. There are way to decentralize the internet, but there never will be much interest for it.

Extremely funny video by Moxie Marlinspike about it: https://m.youtube.com/watch?v=Z7Wl2FW2TcA

Thanks, in some twist of irony, I’ve mistaken Convergence for Perspectives.

Re: Let's Encrypt makes certs for 30% of web domains

#123
post #81

Earlier quoted context omitted.

Because where is the incentive? Why would anyone be a "miner"? What reward would there be?

could be a nonprofit, like letsencrypt

That's not the point. In a decentralized system, every actor needs an incentive to mine new blocks in the chain. In cryptocurrencies, the incentive is the creation of new money attached to your name. But what if we're not dealing with a currency, but something else?

Re: Let's Encrypt makes certs for 30% of web domains

#124
post #34
post #19

Earlier quoted context omitted.

Letsencrypt doesnt issue certs to Iran, Syria, Cuba, Sudan et al.

Yes we do. On what basis did you make that statement? We comply with U.S. sanctions by not issuing to entities on the SDN list, but that doesn't prevent us from serving the vast majority of people in those countries.

> We comply with U.S. sanctions

What are good non-US CAs?

Re: Let's Encrypt makes certs for 30% of web domains

#125
post #81

Earlier quoted context omitted.

could be a nonprofit, like letsencrypt

That's not the point. In a decentralized system, every actor needs an incentive to mine new blocks in the chain. In cryptocurrencies, the incentive is the creation of new money attached to your name. But what if we're not dealing with a currency, but something else?

you are thinking of bitcoin. there are many different blockchain setups . and there is already namecoin

Re: Let's Encrypt makes certs for 30% of web domains

#126
post #111

Earlier quoted context omitted.

Not much: https://bugzilla.mozilla.org/show_bug.cgi?id=647959 It's not about the money, either. LetsEncrypt had their intermediate certificates cross-signed by IdenTrust, otherwise they wouldn't have the 30% market share. It takes a lot of time with the CA application process. You will need to convince Microsoft, Apple, Mozilla, Java, etc that you will be a good CA with good practices. Multiple security audits (start…

That link is amazing. Thank you for that. Yea I have a pretty good idea of what’s involved. None of that is impossible to do. Time consuming? Sure. Impossible? Far from it. The root programs have documented processes to get included and will (eventually) accept a legit new CA that’s passed WebTrust audit and has good practices (afaik). Hardest thing is finding someone to cross-sign to accelerate the process. That’s w…

I would try contacting some of the lesser known CAs. Those who voted "No" on recent CA/B forum ballot to reduce certificate lifetime are probably having some hard time keeping up with ACME, and might as well sell the business. A root valid for next 3-4 years gotta do because Android updates are faster now and current shitty IOT devices and "smart" devices would be dead by then. In recent Symantec sellout to Digicert, it looks like the more pressure a CA has, more likely it would be to buy them out. It's gotta cost in millions though I suppose.

Re: Let's Encrypt makes certs for 30% of web domains

#127
post #120

Earlier quoted context omitted.

That link is amazing. Thank you for that. Yea I have a pretty good idea of what’s involved. None of that is impossible to do. Time consuming? Sure. Impossible? Far from it. The root programs have documented processes to get included and will (eventually) accept a legit new CA that’s passed WebTrust audit and has good practices (afaik). Hardest thing is finding someone to cross-sign to accelerate the process. That’s w…

LE are pretty open about their expenses, ~$3.6m a year currently, if I remember correctly. They got bootstrapped with a cross-signing from IdenTrust and so were able to get off the ground fairly quickly. That won't have been cheap, and I'd be very surprised if anyone would offer the same service now - there's some pretty big risks associated with it. Getting a new trusted CA off the ground is slow and expensive, sadl…

Considering the amount of VC money being burnt every day by some startups with no future, this $3.6m is well spent.

Re: Let's Encrypt makes certs for 30% of web domains

#128

Earlier quoted context omitted.

> Yeah, but no publicly trusted certs. > (Over 1.5M expire in the 2040s alone!) I doubt ~75% of the self signed certs expire in this dataset expire 21-30 years from now. Surely the author is correct that there are a good number of public certs with a very long expiration. Would need to download and filter the dataset to know for sure though.

I doubt anybody has ever issued a "real" (Web PKI) leaf certificate (leaves are the edge of the tree, the certificates presented by TLS servers this work connected to) for 21 years let alone 30. Back in 2011 when the Baseline Requirements were first written, they set 60 months (5 years) as the upper limit, with the intent to further restrict to 39 months in a few years and that eventually happened in 2015 or so. Last…

With raising automation of issuance for certificates (I might work soon on a project to add an api to issue certificatates) I don't see any reason to not go any lower. Like just a few days or weeks.

Re: Let's Encrypt makes certs for 30% of web domains

#129
post #44

Earlier quoted context omitted.

That's due to US sanctions.

Start a LetTheRestOfUsEncrypt.org based in a different country whose government isn't so full of themselves? Or better yet, is there a way to start a decentralized organization itself so that no jurisdiction has absolute power over it?

As far as I am aware, the only organizations that aren't under the jurisdiction of any nation state or authority are those sponsored by/derived from the United Nations.

Re: Let's Encrypt makes certs for 30% of web domains

#130
post #34

Earlier quoted context omitted.

Yes we do. On what basis did you make that statement? We comply with U.S. sanctions by not issuing to entities on the SDN list, but that doesn't prevent us from serving the vast majority of people in those countries.

Well that's interesting, so these are political certs?

no, they are legal certs.
Post reply on HN