Live data from Hacker News

Standing on our own two feet

letsencrypt.org

141–150 of 200 posts

Re: Standing on our own two feet

#141
I too have wondered why IdenTrust would want to do this. As has been mentioned in this thread, it appears they focus on enterprise-level customers, governments, medical, among others.

Generally speaking, the way that new competitors enter a given market is with low-cost options that are often inferior to established players. Then, as those entrants expand upmarket by offering better and improved products, the existing/established players abandon parts of their downmarket products to the new entrants. This cycle repeats until there's nowhere left for the established players to go. At that point, these upstarts can often replace the existing players and become the dominant ones.

I'm not sure if the above was a deliberate strategic move on the part of IdenTrust or not, but in cross-signing the Let's Encrypt certificate, it effectively killed off the potential for new players in the low-cost TLS/SSL certificate market because there's no margin in $0. [Citation needed] Further, because the purpose of Let's Encrypt is to serve the base level of the market [1] with no apparent desire (as per the parent organization which is effectively a non-profit/public-benefit organization) to expand upmarket. This move would appear to solidify (whether intentional or not) the position of larger players who cater to larger customers while keeping any potential newer players from disrupting the space.

Aside: I love Let's Encrypt and have about a dozen or so certificates issued through them that I am in charge of. They're awesome and kudos to their team for what they've been able to accomplish. When they first offered certificates, the 90-day validity period felt very restrictive. Now it feels great because the certificates are automatically rotated every 60 days per various automation tools and painful certificate renewals are very much a thing of the past for me.

[1] https://letsencrypt.org/about/

Re: Standing on our own two feet

#142
It appears the built-in time expiry period in the trust relationships between various organisations and clients will increasing become a weak point in the world in the future. Whether these moving parts are in trust only for three months, three years or more is not the issue, it is the fact that periodic resync and retrust needs to happen, means that it may result in a cascadable failure of our infrastructure in the future. Say if a nuclear disaster / earthquake take down one city, will it lead to paralysis of servers and services across the world? Perhaps it is time to start auditing the Internet and identify the weak points.

Re: Standing on our own two feet

#143

Earlier quoted context omitted.

Good. Those devices are unsafe, and should not be used.

I think you might be ignorant with regards to how the rest of the world uses the internet.

But for certain businesses, there is a case to be made for not serving these kinds of customers. Someone using a shitty old Android phone might not even be able/willing to pay for your product, and if they do, might cost more in technical support and/or fraud (due to their device being vulnerable) than what they bring in revenue.

Re: Standing on our own two feet

#144

Somewhat related, but in other thread two weeks ago people complain Google has too much power over Android ecosystem: https://news.ycombinator.com/item?id=24917918 Now, here people are suggesting Google should somehow update the old Androids. Be damned one way or the other.

Yes and Yes. And both are reasonable and not excluding. Google sells you a pocket computer with a locked down OS, not for your safety but to control the ability to run ads. If they cared about user security, they would provide updates, no matter how "slow" (their excuse) the device gets. If they didn't want full control to show ads (ads are downloaded by the GooglePlayServices, which is pretty much the kernel of all…

Google does provide updates. It's the device manufacturers and/or mobile operators who choose not to push them.

Re: Standing on our own two feet

#145

It appears the built-in time expiry period in the trust relationships between various organisations and clients will increasing become a weak point in the world in the future. Whether these moving parts are in trust only for three months, three years or more is not the issue, it is the fact that periodic resync and retrust needs to happen, means that it may result in a cascadable failure of our infrastructure in the…

That doesn’t feel like a weak point to me. In the case you described, trust likely is broken. As a user, I may not care and instruct my browser to ignore the fact that the certificate is broken because I understand the likely cause.

Re: Standing on our own two feet

#146

Does anyone have experiences with ZeroSSL? Caddy has been building in support so I think it could be a drop-in replacement for Caddy/CertMagic/ACMEx users.

Just tried to switch to them from LE since I don't want to just drop 33% of Android users, but it looks like their ACME implementation is not RFC8555-compliant as their 'newAccount' endpoint can only be used only once in violation of section 7.3.1 of the RFC. They also seem to be pushing people to use their own proprietary API instead. So thanks but no thanks.

Re: Standing on our own two feet

#147
The answer there would be strong "rights to repair" legislation. In the most affected markets it would be a viable option to go to the phone shop and have a new operating system image installed for 20 Euros/Dollars.

But those markets don't have the legal power against Google or Samsung.

And markets that would have the legal power, don't care about unnecessary electronic waste ruining the planet.

(Sent from Android 4.1 without Playstore.)

Re: Standing on our own two feet

#148

Earlier quoted context omitted.

Does anyone in enterprise actually need publicly trusted certificates for documents and email? Seems like it's an inside-the-firewall Exchange server for internal traffic, and a white-label "secure messaging center" portal for external traffic.

IdenTrust's buisness also spans to managing private CAs for companies, which includes managing the HSM and private keys. Also, the companies who hire IdenTrust and similar companies are not that involved in technology. Also, security experts who can manage this safely is a tad harder to find and requests higher wages than your standard IT staff. TLDR: yes, but some companies wants another company to manage their cert…

In those cases IdenTrust bought an insane amount of goodwill from some of the most technical people online by supporting Let’s Encrypt.

Re: Standing on our own two feet

#149
post #2

Let’s Encrypt cross-signature with IdenTrust "DST Root X3" is ending on September 1, 2021 but 33.8% of Android devices are running versions under 7.1 which don't trust Let’s Encrypt new root certificate "ISRG Root X1"

The most impressive thing it that Let’s Encrypt are the ones who are trying to fix a problem that should be fixed by phone manufactures and telcos.

I can see why, but I would also have like the phones to “break” so the owners would avoid those brands in the future, and pick one who care enough to push out update.

Still, I can blame Let’s Encrypt, they just want to be the good guys, and the do it so beautifully and transparently.

Re: Standing on our own two feet

#150

The answer there would be strong "rights to repair" legislation. In the most affected markets it would be a viable option to go to the phone shop and have a new operating system image installed for 20 Euros/Dollars. But those markets don't have the legal power against Google or Samsung. And markets that would have the legal power, don't care about unnecessary electronic waste ruining the planet. (Sent from Android 4.…

The scenario you describe unfortunately requires more than just right to repair. It requires the SoC vendors to either keep updating their kernels, or to open source their driver blobs. Without these, you can't build a proper new OS image, you're stuck on the latest one provided by the SoC manufacturer.
Post reply on HN