Live data from Hacker News

A Year-End Letter from our Executive Director

letsencrypt.org

41–50 of 155 posts

Re: A Year-End Letter from our Executive Director

#41

Earlier quoted context omitted.

> some shady websites What are you talking about? A clever design aspect of Let’s Encrypt is the deliberately short expiry. That forces administrators to automate the issuance and renewal process. Not to mention that you’re not supposed to “download” the private key! The whole idea of PKI is to generate the private key locally and then have a CA sign only the public part. If you’re doing anything else you’ve undermin…

I know better what am I supposed to do. Type "download letsencrypt certificate online" in the Google and you'll find out what I'm talking about. You can think of forcing administrators all the day while Internet is full of expired letsencrypt websites that I regularly stumble upon. The world does not work like that. Letsencrypt should serve its users, not force them onto anything. If I think that I should generate ke…

If people want longer certificate lifespans, they can get their certificates elsewhere. Part of the deal with getting a free certificate is that you're supposed to set up autorenewal with ACME. If you can't or don't want to do that, there are plenty of other CAs out there that will get you a long-life certificate.

Re: A Year-End Letter from our Executive Director

#42

I don't understand why Let's Encrypt is OK but DANE isn't. They both use DNS to authenticate certificates, why not cut out the middleman?

Not much has changed since "Why not DANE in browsers (17 Jan 2015)": https://www.imperialviolet.org/2015/01/17/notdane.html

Re: A Year-End Letter from our Executive Director

#43
I am glad it looks like the IETF ACME specification only addresses the HTTP-01 challenge. I really would like to see improvements made to the DNS-01 challenge before it's ratified, namely, let us publish a public key to a TXT record and use the private key to sign the renewal request. Then I can revoke certbot's access to my DNS records and stop hacking the `.well-known` path.

Re: A Year-End Letter from our Executive Director

#44
post #35

Let's Encrypt has had such a positive impact, I think I'll start donating to them instead of Wikipedia. They're a lot more subtle with their calls to donate, but they seem to deliver a lot of good things to a lot of users, with a much smaller budget. I'm just really grateful for the service, and glad to see the Prossimo work continuing as well. (On a tangential note, I suspect the way Let's Encrypt makes me feel is t…

What a bizarre comment. These two aren't competing?

Re: A Year-End Letter from our Executive Director

#45
post #35

Let's Encrypt has had such a positive impact, I think I'll start donating to them instead of Wikipedia. They're a lot more subtle with their calls to donate, but they seem to deliver a lot of good things to a lot of users, with a much smaller budget. I'm just really grateful for the service, and glad to see the Prossimo work continuing as well. (On a tangential note, I suspect the way Let's Encrypt makes me feel is t…

They seem a whole lot less bloated than Wikipedia as well. Given that something around 3% of donations to Wikipedia actually go to the website, they'll be fine with less donations despite what their nag popups suggest.

I stopped donating to Wikipedia after the size of their cash reserves were revealed.

I get that's designed to protect themselves for the long term and it sounds like they've made it so they don't need my money for now, at least not at the expense of other projects that don't have such cash reserves like Let's Encrypt.

Re: A Year-End Letter from our Executive Director

#46
post #26

Earlier quoted context omitted.

Those instructions were always so clunky as was the process. Re: Godaddy, I was using their "EV" (Extended Validation) cert which added a company name indicator in the address bar. I then learned that it's unwise to bring up security when someone isn't thinking about it because it puts them on undue alert. A couple years ago the browsers have done away with that EV badge altogether.

Browsers did away with it because it says nothing about the actual security status of a page compared to any other SSL page. All it means is that the organization was verified. Customers were seeing the prominent green text and assuming a heightened level of security and trust. Legal names are also not unique, and this loophole could be used for phishing. Instead, what browsers did was promote SSL as a default (regar…

And make it almost impossible to use an out of date or self-signed cert. Some browsers make you click 3 times you know what you are doing, others don't seem to let you at all.

Re: A Year-End Letter from our Executive Director

#47

Earlier quoted context omitted.

> some shady websites What are you talking about? A clever design aspect of Let’s Encrypt is the deliberately short expiry. That forces administrators to automate the issuance and renewal process. Not to mention that you’re not supposed to “download” the private key! The whole idea of PKI is to generate the private key locally and then have a CA sign only the public part. If you’re doing anything else you’ve undermin…

I know better what am I supposed to do. Type "download letsencrypt certificate online" in the Google and you'll find out what I'm talking about. You can think of forcing administrators all the day while Internet is full of expired letsencrypt websites that I regularly stumble upon. The world does not work like that. Letsencrypt should serve its users, not force them onto anything. If I think that I should generate ke…

> Type "download letsencrypt certificate online" in the Google

> generate key online, provide me this service with sane implementation on a safe website

Well there's your problem right there. Either go on youtube and watch some videos about how TLS works or just use an http server like Caddy that automatically generates TLS certs and renews them with Let's Encrypt.

Re: A Year-End Letter from our Executive Director

#48

Earlier quoted context omitted.

I know better what am I supposed to do. Type "download letsencrypt certificate online" in the Google and you'll find out what I'm talking about. You can think of forcing administrators all the day while Internet is full of expired letsencrypt websites that I regularly stumble upon. The world does not work like that. Letsencrypt should serve its users, not force them onto anything. If I think that I should generate ke…

If people want longer certificate lifespans, they can get their certificates elsewhere. Part of the deal with getting a free certificate is that you're supposed to set up autorenewal with ACME. If you can't or don't want to do that, there are plenty of other CAs out there that will get you a long-life certificate.

Nobody offers more than a year now. It’s annoying. So many old devices still need to be supported and can’t automatically update.

Re: A Year-End Letter from our Executive Director

#49
post #48

Earlier quoted context omitted.

If people want longer certificate lifespans, they can get their certificates elsewhere. Part of the deal with getting a free certificate is that you're supposed to set up autorenewal with ACME. If you can't or don't want to do that, there are plenty of other CAs out there that will get you a long-life certificate.

Nobody offers more than a year now. It’s annoying. So many old devices still need to be supported and can’t automatically update.

If these devices have internet access they can auto renew. If they don't, they don't need a cert signed by a public CA.

Re: A Year-End Letter from our Executive Director

#50
post #35

Let's Encrypt has had such a positive impact, I think I'll start donating to them instead of Wikipedia. They're a lot more subtle with their calls to donate, but they seem to deliver a lot of good things to a lot of users, with a much smaller budget. I'm just really grateful for the service, and glad to see the Prossimo work continuing as well. (On a tangential note, I suspect the way Let's Encrypt makes me feel is t…

What a bizarre comment. These two aren't competing?

Competing for his donations?
Post reply on HN