Live data from Hacker News

A Year-End Letter from our Executive Director

letsencrypt.org

11–20 of 155 posts

Re: A Year-End Letter from our Executive Director

#11
post #5
post #4

Earlier quoted context omitted.

I'm not sure that's a good thing

What's a downside of that?

As someone that supports Let's Encrypt's efforts and playing devil's advocate, I imagine a downside is that the bar is lowered and nefarious websites can easily get SSL-equipped channels compared to the high paywall of prior.

Re: A Year-End Letter from our Executive Director

#12
post #5
post #4

Earlier quoted context omitted.

I'm not sure that's a good thing

What's a downside of that?

An Ex-facebook ml engineer who doesn't know what ssl is and takes pride in not having to learn it?

Not sure it's a downside/upside thing. It might shed light on the types of people who get hired at facebook.

Re: A Year-End Letter from our Executive Director

#13
post #4

Earlier quoted context omitted.

I'm not sure that's a good thing

It saves me from the implementation details, this way I don't need to wear another engineer/sysadmin hat. I think the website content is more important than the SSL implementation!

Indeed! It's how security should work, and should be the default dual-goal of any piece of security software: provide as much security as possible to as many people as possible.

Re: A Year-End Letter from our Executive Director

#14
post #8

Before Letsencrypt, SSL signing was cumbersome and downright scary sometimes. With cPanel + letsencrypt (or whatever their default Auto SSL provider is [0]), it's a few clicks and done. If there's a downside, I have never seen nor heard of it. Side note: I was expecting this CEO letter to end with layoffs. [0] https://docs.cpanel.net/whm/ssl-tls/manage-autossl/

I used to configure all of this manually on Apache following crappy instructions from online certificate providers. Copying .pem, .key, .csr files PRAYING Apache would start without complaining.

I'm still old school but can set this up all using the letsencrypt command line utilities that configure everything for me.

Oh, and whatever the hell GoDaddy's intermediate chain certificate was.

Re: A Year-End Letter from our Executive Director

#15
post #5

Earlier quoted context omitted.

What's a downside of that?

As someone that supports Let's Encrypt's efforts and playing devil's advocate, I imagine a downside is that the bar is lowered and nefarious websites can easily get SSL-equipped channels compared to the high paywall of prior.

What is the downside of this?

Re: A Year-End Letter from our Executive Director

#16
post #5

Earlier quoted context omitted.

What's a downside of that?

As someone that supports Let's Encrypt's efforts and playing devil's advocate, I imagine a downside is that the bar is lowered and nefarious websites can easily get SSL-equipped channels compared to the high paywall of prior.

A plain domain validated certificate cost like $10 for a year or two. So roughly the same cost as the domain name. Hardly a "high paywall".

Re: A Year-End Letter from our Executive Director

#17
post #5

Earlier quoted context omitted.

What's a downside of that?

As someone that supports Let's Encrypt's efforts and playing devil's advocate, I imagine a downside is that the bar is lowered and nefarious websites can easily get SSL-equipped channels compared to the high paywall of prior.

Commercial CAs verify exactly two things: Administrative control over a domain name and a working credit card number.

Let’s Encrypt only gets rid of the latter, and given that fraudsters able to spoof the former can probably spare the $10 for the latter, I‘d argue that this is a good thing.

Re: A Year-End Letter from our Executive Director

#18
post #12
post #5

Earlier quoted context omitted.

What's a downside of that?

An Ex-facebook ml engineer who doesn't know what ssl is and takes pride in not having to learn it? Not sure it's a downside/upside thing. It might shed light on the types of people who get hired at facebook.

It's perfectly reasonable for someone to be into programming and not want to have to care about the details of setting up a networking stack.

Re: A Year-End Letter from our Executive Director

#19
post #5

Earlier quoted context omitted.

What's a downside of that?

As someone that supports Let's Encrypt's efforts and playing devil's advocate, I imagine a downside is that the bar is lowered and nefarious websites can easily get SSL-equipped channels compared to the high paywall of prior.

Before Let's Encrypt there were all kinds of bullshit CAs that would distribute secure sites "seals", and lie all over the internet on how those meant anything.

All of that noise is gone now. That makes the internet much safer.

Post reply on HN