Live data from Hacker News

Standing on our own two feet

letsencrypt.org

71–80 of 200 posts

Re: Standing on our own two feet

#71
post #37

Earlier quoted context omitted.

No play services on an Android phone in the US probably implies willingness to tinker. No play services on an Android phone in China only implies it's an Android phone. In the developing world, it most likely implies a very low cost Android phone of Chinese origin. Bundling things that need timely updates with the OS with no mechanism to update them individually is a design error. Things like root certificates, time…

In an ideal world carriers wouldn't have a say in what software updates were installed on my phone. Comcast doesn't control the software on the computers it services. Why should Telus control what updates are made available for my phone?

Because they're the ones who push updates over the cell network. Comcast absolutely controls what software you run on your modem. You can update "out of band" manually, at least on recent Android Pixel phones. Any other manufacturer could also make their updates public, but since installing the one not for your carrier band makes the phone unusable as a phone, it's not likely to be common.

Re: Standing on our own two feet

#72
post #2

Let’s Encrypt cross-signature with IdenTrust "DST Root X3" is ending on September 1, 2021 but 33.8% of Android devices are running versions under 7.1 which don't trust Let’s Encrypt new root certificate "ISRG Root X1"

Workaround is Firefox Mobile (because it ships with its own root certs), but that's a significant burden to place on the user.

A Workaround is not something that the user does.

Re: Standing on our own two feet

#74
post #18

now the corporates got a valid point, why you dont want to use lets encrypt? still the 33% of the devices is a quite a large number to consider.

But like they said in the article, those 33% of Android phones represent "1-5% of the traffic" of the "large integrators" websites that LE communicated with.

Well that's an easy choice, lose 1-5% of traffic or pay $100 for a certificate from a vendor whose root doesn't expire next year?

Re: Standing on our own two feet

#75
post #5

Earlier quoted context omitted.

Also the post says that Firefox doesn't work on Androids older than 5.0 which according to the dashboard are still 5.9% of devices. For those older devices, the only option is to install the new root certificate. Anyways, there are billions of Android devices out there. 33% of those is a large number. You can't just tell all of them that they are wrong. If this happens, people will move away from Let's encrypt in mas…

Not sure about that. Move away from Let's Encrypt to what? More likely, most smaller to medium sized sites will say forget those old Android guys.

Too cheap to update can be seen as too cheap to buy your product or service, so I can see this happening.

Re: Standing on our own two feet

#76

i hate how google puts warnings on non-ssl sites. why doe a static page that has no forms need ssl? non-ssl worked fine for 20 years for webpages and google comes along and says noooo not good enough.

A MITM can add a "Donate" button to news.ycombinator.com. The money doesn't actually go to Hacker News, though. It goes to the MITM.

Re: Standing on our own two feet

#77
post #5

Earlier quoted context omitted.

Workaround is Firefox Mobile (because it ships with its own root certs), but that's a significant burden to place on the user.

Also the post says that Firefox doesn't work on Androids older than 5.0 which according to the dashboard are still 5.9% of devices. For those older devices, the only option is to install the new root certificate. Anyways, there are billions of Android devices out there. 33% of those is a large number. You can't just tell all of them that they are wrong. If this happens, people will move away from Let's encrypt in mas…

33% of devices, but per the article, only 1-5% of traffic on sites using LetsEncrypt. I don't see any site owners moving to a different CA when this affects less than 5% of their visitors, who are likely the poorest fraction of their userbase , i.e. probably not many paying users.

Re: Standing on our own two feet

#78
post #23

They propose to install Firefox to work around the root certificate problem on old android devices. But can’t you just manually install their root certificate on most phones?

I'm not sure if it's the same on older versions, but on recent Android versions, that requires a rooted device.

Re: Standing on our own two feet

#79
post #74

Earlier quoted context omitted.

But like they said in the article, those 33% of Android phones represent "1-5% of the traffic" of the "large integrators" websites that LE communicated with.

Well that's an easy choice, lose 1-5% of traffic or pay $100 for a certificate from a vendor whose root doesn't expire next year?

1-5% of traffic that comes from people using devices that are at least 4 years old. Someone who can't or won't upgrade from a phone that still uses Android Marshmallow is probably not bringing in much revenue.

Re: Standing on our own two feet

#80
post #68

Does anyone have experiences with ZeroSSL? Caddy has been building in support so I think it could be a drop-in replacement for Caddy/CertMagic/ACMEx users.

ACMEz* ;) Seconding regecks' comment. We're gradually making ZeroSSL a default CA for Caddy. (I am currently implementing multi-CA support into Caddy and CertMagic, so that Caddy will be able to use both Let's Encrypt and ZeroSSL for redundancy. It's the first server to support this!) This is a good thing for the ecosystem.

> We're gradually making ZeroSSL a default CA for Caddy.

As in, replacing LE as the default, or supplementing it? (And if the former, why?)

Post reply on HN