Earlier quoted context omitted.
If you just want to post a link, I'd rather you submit a story with a title than put a "see, this is concerning:" in the comments. Moreover, I don't see how this article is relevant to Let's Encrypt's popularity. There are only two mentions in the article about LE, this is one: "These actors use Let's Encrypts, Comodo, Sectigo, and self-signed certificates in their MitM servers to gain the initial round of credential…
You are most welcome.
Let's Encrypt makes certs for 30% of web domains
141–147 of 147 posts
Re: Let's Encrypt makes certs for 30% of web domains
#142Earlier quoted context omitted.
I doubt anybody has ever issued a "real" (Web PKI) leaf certificate (leaves are the edge of the tree, the certificates presented by TLS servers this work connected to) for 21 years let alone 30. Back in 2011 when the Baseline Requirements were first written, they set 60 months (5 years) as the upper limit, with the intent to further restrict to 39 months in a few years and that eventually happened in 2015 or so. Last…
With raising automation of issuance for certificates (I might work soon on a project to add an api to issue certificatates) I don't see any reason to not go any lower. Like just a few days or weeks.
These applications are also frequently heavily firewalled to the internet so security risks are limited, but not with smaller operations, you might not have PKI infrastructure in place to manage your own root certs (especially in BYOD orgs).
If a certificate rollover takes your application offline for an hour, your not going to want to do it every week.
Re: Let's Encrypt makes certs for 30% of web domains
#143This kind of centralization is not good. Even thought let's encrypt is non profit and has a very good service record. We desperately need more like it spread around the globe.
Right. What happens when Let's Encrypt is the only CA and they decide that they don't like you for some reason? All tech companies are under tremendous Twitter pressure not to serve the wrong kinds of people, and this pressure will only intensify. The window of acceptability narrow. Infrastructure diversity is an important check against the ability of vocal but small groups of activists to effectively censor the inte…
Or, more importantly, what happens when the US government decides you're too brown or Jewish and decides to sanction you?
Let's Encrypt has to follow US sanctions, so no more certs for you!
Re: Let's Encrypt makes certs for 30% of web domains
#144A few of these things, while not necessarily wrong, should be put into context. E.g. "Hundreds of thousands of domains' certs expire after 2099". Yeah, but no publicly trusted certs. They're capped at a bit more than 2 years and there's a discussion to cap them even more. The certs they're seeing are almost certainly mostly: "let's create a test selfsigned cert for this host. how long should it last? let's type in a…
Yes, but... Historically there were some certs that kept getting grandfathered in after lifetimes were restricted because they'd been issued before there were any rules - maybe ten years to expire or even more? I think the last of those probably went away because of the Symantec distrust (not that they were issued by Symantec, but they were issued by a CA which was bought by a CA which in turn was bought by Symantec…
The real concern is the percentage of people using browsers that are no longer supported and therefore do not implement on the new standards like Internet Explorer. Microst really needs to stop caving to pressure and get rid of these ancient applications like paint.exe and internet explorer. That or just make new applications and give them the same names.
Re: Let's Encrypt makes certs for 30% of web domains
#145Earlier quoted context omitted.
Right. What happens when Let's Encrypt is the only CA and they decide that they don't like you for some reason? All tech companies are under tremendous Twitter pressure not to serve the wrong kinds of people, and this pressure will only intensify. The window of acceptability narrow. Infrastructure diversity is an important check against the ability of vocal but small groups of activists to effectively censor the inte…
>Right. What happens when Let's Encrypt is the only CA and they decide that they don't like you for some reason? Or, more importantly, what happens when the US government decides you're too brown or Jewish and decides to sanction you? Let's Encrypt has to follow US sanctions, so no more certs for you!
Re: Let's Encrypt makes certs for 30% of web domains
#146Earlier quoted context omitted.
What problems would decentralization solve here?
Let's Encrypt goes down, certs can't be renewed, people can't access websites securely (or at all if HSTS was used).
Re: Let's Encrypt makes certs for 30% of web domains
#147Earlier quoted context omitted.
How are you going to trust that decentralized org? Is it just voting? Can we all vote to revoke anyone's cert at any time for no reason? What happens when someone performs a 51% attack and takes over google.com's cert? CAs exist solely because you CAN trust them, otherwise what's the point? We'd just have every site self-sign and let the users choose who to trust.
My thinking was that it would be similar to a GPG trust network.