Live data from Hacker News

Let's Encrypt makes certs for 30% of web domains

leebutterman.com

141–147 of 147 posts

Re: Let's Encrypt makes certs for 30% of web domains

#141
post #138
post #133

Earlier quoted context omitted.

If you just want to post a link, I'd rather you submit a story with a title than put a "see, this is concerning:" in the comments. Moreover, I don't see how this article is relevant to Let's Encrypt's popularity. There are only two mentions in the article about LE, this is one: "These actors use Let's Encrypts, Comodo, Sectigo, and self-signed certificates in their MitM servers to gain the initial round of credential…

You are most welcome.

Not sure what you mean by that. It's clearly sarcastic but I can't tell what you mean to say.

Re: Let's Encrypt makes certs for 30% of web domains

#142

Earlier quoted context omitted.

I doubt anybody has ever issued a "real" (Web PKI) leaf certificate (leaves are the edge of the tree, the certificates presented by TLS servers this work connected to) for 21 years let alone 30. Back in 2011 when the Baseline Requirements were first written, they set 60 months (5 years) as the upper limit, with the intent to further restrict to 39 months in a few years and that eventually happened in 2015 or so. Last…

With raising automation of issuance for certificates (I might work soon on a project to add an api to issue certificatates) I don't see any reason to not go any lower. Like just a few days or weeks.

That doesn't work if your running software supplied by a vendor that needs an SSL certificate. Often they have manual processes, that require shutting down the application and restarting, taking the service offline through the process.

These applications are also frequently heavily firewalled to the internet so security risks are limited, but not with smaller operations, you might not have PKI infrastructure in place to manage your own root certs (especially in BYOD orgs).

If a certificate rollover takes your application offline for an hour, your not going to want to do it every week.

Re: Let's Encrypt makes certs for 30% of web domains

#143

This kind of centralization is not good. Even thought let's encrypt is non profit and has a very good service record. We desperately need more like it spread around the globe.

Right. What happens when Let's Encrypt is the only CA and they decide that they don't like you for some reason? All tech companies are under tremendous Twitter pressure not to serve the wrong kinds of people, and this pressure will only intensify. The window of acceptability narrow. Infrastructure diversity is an important check against the ability of vocal but small groups of activists to effectively censor the inte…

>Right. What happens when Let's Encrypt is the only CA and they decide that they don't like you for some reason?

Or, more importantly, what happens when the US government decides you're too brown or Jewish and decides to sanction you?

Let's Encrypt has to follow US sanctions, so no more certs for you!

Re: Let's Encrypt makes certs for 30% of web domains

#144
post #9

A few of these things, while not necessarily wrong, should be put into context. E.g. "Hundreds of thousands of domains' certs expire after 2099". Yeah, but no publicly trusted certs. They're capped at a bit more than 2 years and there's a discussion to cap them even more. The certs they're seeing are almost certainly mostly: "let's create a test selfsigned cert for this host. how long should it last? let's type in a…

Yes, but... Historically there were some certs that kept getting grandfathered in after lifetimes were restricted because they'd been issued before there were any rules - maybe ten years to expire or even more? I think the last of those probably went away because of the Symantec distrust (not that they were issued by Symantec, but they were issued by a CA which was bought by a CA which in turn was bought by Symantec…

The old certificates aren't a huge concern moving forward because the new standards for trust libraries is requiring that all certificates not be trusted if the expiration is too far out. Chrome and most other browsers have already implemented these standards.

The real concern is the percentage of people using browsers that are no longer supported and therefore do not implement on the new standards like Internet Explorer. Microst really needs to stop caving to pressure and get rid of these ancient applications like paint.exe and internet explorer. That or just make new applications and give them the same names.

Re: Let's Encrypt makes certs for 30% of web domains

#145
post #143

Earlier quoted context omitted.

Right. What happens when Let's Encrypt is the only CA and they decide that they don't like you for some reason? All tech companies are under tremendous Twitter pressure not to serve the wrong kinds of people, and this pressure will only intensify. The window of acceptability narrow. Infrastructure diversity is an important check against the ability of vocal but small groups of activists to effectively censor the inte…

>Right. What happens when Let's Encrypt is the only CA and they decide that they don't like you for some reason? Or, more importantly, what happens when the US government decides you're too brown or Jewish and decides to sanction you? Let's Encrypt has to follow US sanctions, so no more certs for you!

Getting caught up in what kind of censorship is most vexing is missing the point if we can agree that nobody should be able to silence people on the internet.

Re: Let's Encrypt makes certs for 30% of web domains

#146
post #16

Earlier quoted context omitted.

What problems would decentralization solve here?

Let's Encrypt goes down, certs can't be renewed, people can't access websites securely (or at all if HSTS was used).

You may be conflating HSTS with public key pinning. HSTS doesn't care which cert provider you use. CAA and HPKP do. If LE go away or get untrusted, you can get certs from another CA, albeit not free in most cases.

Re: Let's Encrypt makes certs for 30% of web domains

#147
post #99

Earlier quoted context omitted.

How are you going to trust that decentralized org? Is it just voting? Can we all vote to revoke anyone's cert at any time for no reason? What happens when someone performs a 51% attack and takes over google.com's cert? CAs exist solely because you CAN trust them, otherwise what's the point? We'd just have every site self-sign and let the users choose who to trust.

My thinking was that it would be similar to a GPG trust network.

We’ve seen nearly 30 years of web-of-trust failure and yet you still think it’s a workable idea?
Post reply on HN