Live data from Hacker News

Let’s Encrypt Receives the Levchin Prize for Real-World Cryptography

letsencrypt.org

1–10 of 37 posts

Re: Let’s Encrypt Receives the Levchin Prize for Real-World Cryptography

#2
The main thing I'm thankful for Let's Encrypt for is breaking the idea that an SSL-secured website is somehow magically less likely to be phishing or even anything but claiming it's the data from the domain you connected to, without changes.

Mainly this was propagated by EV cert sellers, but it was all kinda silly.

Re: Let’s Encrypt Receives the Levchin Prize for Real-World Cryptography

#3
"Let’s Encrypt is currently used by more than 280 million websites, issuing between two and three million certificates per day. I often think about how we got here, looking for some nugget of wisdom that might be useful to others."

I guess it's keep trying. Keep patiently explaining, educating and building.

I remember people saying "You'll never be able to topple the certs racket" - and here we are... in a age where every day I read about how we'll 'never' be able to break the big-tech stranglehold and build a distributed network owned by the people, 'never' have privacy and real end-to-end encryption because 'nobody cares', 'never' have practical p2p digital currencies of our own, and where we'll never have open, verifiable hardware. Keep believing.

Re: Let’s Encrypt Receives the Levchin Prize for Real-World Cryptography

#4
post #2

The main thing I'm thankful for Let's Encrypt for is breaking the idea that an SSL-secured website is somehow magically less likely to be phishing or even anything but claiming it's the data from the domain you connected to, without changes. Mainly this was propagated by EV cert sellers, but it was all kinda silly.

That idea is unfortunately alive and well. Many organizations require it, much like they require 90-day password rotation and other questionable security standards.

Re: Let’s Encrypt Receives the Levchin Prize for Real-World Cryptography

#5
post #2

The main thing I'm thankful for Let's Encrypt for is breaking the idea that an SSL-secured website is somehow magically less likely to be phishing or even anything but claiming it's the data from the domain you connected to, without changes. Mainly this was propagated by EV cert sellers, but it was all kinda silly.

That idea is unfortunately alive and well. Many organizations require it, much like they require 90-day password rotation and other questionable security standards.

There are plenty of good reasons to require it. Proving a trustworthy counter-party for the request is just not one of them.

Re: Let’s Encrypt Receives the Levchin Prize for Real-World Cryptography

#6
post #2

The main thing I'm thankful for Let's Encrypt for is breaking the idea that an SSL-secured website is somehow magically less likely to be phishing or even anything but claiming it's the data from the domain you connected to, without changes. Mainly this was propagated by EV cert sellers, but it was all kinda silly.

Let's Encrypt's own community forums get posts every day from people saying, wait, I got scammed/ phished/ whatever on this site, it has your certificate, shouldn't you shut it down? They do have a page to link those enquiries to, explaining the policy (and indeed they even have standard legal briefs because periodically lawyers get the same idea and a court has to be told why that's wrong).

It would be interesting to know if, say, US citizens write to the Department of State saying hey, revoke this guy's passport, I heard he ripped off somebody on Craig's List...

Re: Let’s Encrypt Receives the Levchin Prize for Real-World Cryptography

#7
Use of Lets Encrypt has grown steadily over the years:

https://trends.shodan.io/search?query=ssl%3A%22Let+s+Encrypt...

Its use is also growing in mail servers so it's not limited to HTTPS:

https://trends.shodan.io/search?query=ssl%3A%22Let+s+Encrypt...

Re: Let’s Encrypt Receives the Levchin Prize for Real-World Cryptography

#8
post #2

The main thing I'm thankful for Let's Encrypt for is breaking the idea that an SSL-secured website is somehow magically less likely to be phishing or even anything but claiming it's the data from the domain you connected to, without changes. Mainly this was propagated by EV cert sellers, but it was all kinda silly.

That idea is unfortunately alive and well. Many organizations require it, much like they require 90-day password rotation and other questionable security standards.

Ironic that 90 day certificate rotation makes even less sense than 90 day password rotation.

Re: Let’s Encrypt Receives the Levchin Prize for Real-World Cryptography

#9

"Let’s Encrypt is currently used by more than 280 million websites, issuing between two and three million certificates per day. I often think about how we got here, looking for some nugget of wisdom that might be useful to others." I guess it's keep trying. Keep patiently explaining, educating and building. I remember people saying "You'll never be able to topple the certs racket" - and here we are... in a age where…

Some people care in the intelligence community ;) It's better to have LetsEncrypt and CloudFlare in the loop to protect national interests and fight against maliciouses actors.

Re: Let’s Encrypt Receives the Levchin Prize for Real-World Cryptography

#10
God bless Let’s Encrypt. I used to tell my clients they need to cough up $100+/year for a cert and jump through a bunch of hoops to get it working. Now it’s built into the UI of many of the control panels I use and I simply click a button. The pre LE days were the dark ages.
Post reply on HN