Live data from Hacker News

Let’s Encrypt Receives the Levchin Prize for Real-World Cryptography

abetterinternet.org

11–20 of 29 posts

Re: Let’s Encrypt Receives the Levchin Prize for Real-World Cryptography

#11
post #2

The post Snowden decade wouldn't have been the same without them. Cudos!

post-Snowden approach is E2EE

TLS only addresses minor threats, it doesn't help against NSA/CIA/etc and their equivalent in other jurisdictions. corporate websites will give up your plaintexts, the cloud providers will give up your private keys hosted on their servers.

Re: Let’s Encrypt Receives the Levchin Prize for Real-World Cryptography

#13
post #9

This is a very nice recognition! I realized that the registrar I have my personal site with purposefully does not support Let's Encrypt as a CA. Anyone have a registrar they'd recommend these days to transfer a domain to? FYI, the crappy registrar/host in question is namecheap.com so you can avoid them in the future.

NameSilo [0] is reliable and has the cheapest pricing for .com and some other TLDs. You can also look into Cloudflare [1]

I personally use NameSilo over Cloudflare because I don't want to give Cloudflare everything.

[0] https://www.namesilo.com/domain/transfer-domains

[1] https://www.cloudflare.com/en-gb/products/registrar/

https://developers.cloudflare.com/registrar/get-started/tran...

Re: Let’s Encrypt Receives the Levchin Prize for Real-World Cryptography

#14
post #6
post #2

The post Snowden decade wouldn't have been the same without them. Cudos!

What about the theory that the NIST encryption curves may be backdoored ? If this is the case, if I would be the NSA I would strongly push for free cryptography, to make sure that only the US can decrypt the communications and have a strategic advantage.

Let's Encrypt is a CA. Their involvement with web cryptography begins and ends with signing certificates which are used for authentication -- they have no say over what cryptography actually gets used for a TLS connection.

Re: Let’s Encrypt Receives the Levchin Prize for Real-World Cryptography

#15

Congratulations to Let’s Encrypt. I would also like to do a shoutout to software like Caddy Server which automatically provisions with TLS using Let’s Encrypt. Doing this removes another barrier to adoption.

I’d add Traefik to that list! Maybe not quite as simple to get up and running as Caddy with LE but still pretty smooth.

Re: Let’s Encrypt Receives the Levchin Prize for Real-World Cryptography

#16
post #9

This is a very nice recognition! I realized that the registrar I have my personal site with purposefully does not support Let's Encrypt as a CA. Anyone have a registrar they'd recommend these days to transfer a domain to? FYI, the crappy registrar/host in question is namecheap.com so you can avoid them in the future.

Is this a new development with namecheap? I currently have a domain with them that is set up with let's encrypt. I haven't touched my site in a long time now but visiting it now shows https.

Re: Let’s Encrypt Receives the Levchin Prize for Real-World Cryptography

#17
post #9

This is a very nice recognition! I realized that the registrar I have my personal site with purposefully does not support Let's Encrypt as a CA. Anyone have a registrar they'd recommend these days to transfer a domain to? FYI, the crappy registrar/host in question is namecheap.com so you can avoid them in the future.

Is this a new development with namecheap? I currently have a domain with them that is set up with let's encrypt. I haven't touched my site in a long time now but visiting it now shows https.

Apparently not, but I only just noticed after their free 1 year trial of SSL certs expired. They're listed on the Let's Encrypt site as having no plans to support and the source is pretty hilarious:

https://community.letsencrypt.org/t/web-hosting-who-support-...

Yes, you can set it up manually, but you have to do it every 90 days as opposed to having it automatically updated in a supported hoster.

Re: Let’s Encrypt Receives the Levchin Prize for Real-World Cryptography

#18
post #10
post #9

This is a very nice recognition! I realized that the registrar I have my personal site with purposefully does not support Let's Encrypt as a CA. Anyone have a registrar they'd recommend these days to transfer a domain to? FYI, the crappy registrar/host in question is namecheap.com so you can avoid them in the future.

The registrar doesn't really have much to say about which CA you use, but a hosting provider would. Given that all certs are limited to a year, we're only a few steps away from the Let's Encrypt setup being automated everywhere.

Just imagine:

- Not allowed to change authoritative DNS

- CAA set to everything except LE

- cannot set CAA to LE

Wouldn't it be nice?

Re: Let’s Encrypt Receives the Levchin Prize for Real-World Cryptography

#19
post #9

This is a very nice recognition! I realized that the registrar I have my personal site with purposefully does not support Let's Encrypt as a CA. Anyone have a registrar they'd recommend these days to transfer a domain to? FYI, the crappy registrar/host in question is namecheap.com so you can avoid them in the future.

The domain registrar is unrelated to LE and can’t block LE.

Just install caddy on a $5/mo VPS instead of using your domain registrar as a host. It will automatically renew LE certs. Your current setup is almost always a terrible idea.

Re: Let’s Encrypt Receives the Levchin Prize for Real-World Cryptography

#20
post #6

Earlier quoted context omitted.

What about the theory that the NIST encryption curves may be backdoored ? If this is the case, if I would be the NSA I would strongly push for free cryptography, to make sure that only the US can decrypt the communications and have a strategic advantage.

Let's Encrypt is a CA. Their involvement with web cryptography begins and ends with signing certificates which are used for authentication -- they have no say over what cryptography actually gets used for a TLS connection.

They are concentrating authority which is never good
Post reply on HN