Earlier quoted context omitted.
I used to configure all of this manually on Apache following crappy instructions from online certificate providers. Copying .pem, .key, .csr files PRAYING Apache would start without complaining. I'm still old school but can set this up all using the letsencrypt command line utilities that configure everything for me. Oh, and whatever the hell GoDaddy's intermediate chain certificate was.
> I'm still old school but can set this up all using the letsencrypt command line utilities that configure everything for me. Actually Apache recently introduced mod_md, which allows provisioning certificates from Let's Encrypt directly (or anything else that supports ACME): https://httpd.apache.org/docs/2.4/mod/mod_md.html Because of this, you no longer need external software like certbot for Apache (though it's goo…
A Year-End Letter from our Executive Director
51–60 of 155 posts
Re: A Year-End Letter from our Executive Director
#52Let's Encrypt has had such a positive impact, I think I'll start donating to them instead of Wikipedia. They're a lot more subtle with their calls to donate, but they seem to deliver a lot of good things to a lot of users, with a much smaller budget. I'm just really grateful for the service, and glad to see the Prossimo work continuing as well. (On a tangential note, I suspect the way Let's Encrypt makes me feel is t…
What a bizarre comment. These two aren't competing?
Re: A Year-End Letter from our Executive Director
#53Earlier quoted context omitted.
It saves me from the implementation details, this way I don't need to wear another engineer/sysadmin hat. I think the website content is more important than the SSL implementation!
Indeed! It's how security should work, and should be the default dual-goal of any piece of security software: provide as much security as possible to as many people as possible.
Re: A Year-End Letter from our Executive Director
#54Let's Encrypt has had such a positive impact, I think I'll start donating to them instead of Wikipedia. They're a lot more subtle with their calls to donate, but they seem to deliver a lot of good things to a lot of users, with a much smaller budget. I'm just really grateful for the service, and glad to see the Prossimo work continuing as well. (On a tangential note, I suspect the way Let's Encrypt makes me feel is t…
What a bizarre comment. These two aren't competing?
Re: A Year-End Letter from our Executive Director
#55Let's Encrypt has had such a positive impact, I think I'll start donating to them instead of Wikipedia. They're a lot more subtle with their calls to donate, but they seem to deliver a lot of good things to a lot of users, with a much smaller budget. I'm just really grateful for the service, and glad to see the Prossimo work continuing as well. (On a tangential note, I suspect the way Let's Encrypt makes me feel is t…
What a bizarre comment. These two aren't competing?
This person is advertising their consideration of donating to LE instead of Wikipedia, and by doing so encouraging others to consider the same. That’s allllll that’s happening here.
Re: A Year-End Letter from our Executive Director
#56Let's Encrypt has had such a positive impact, I think I'll start donating to them instead of Wikipedia. They're a lot more subtle with their calls to donate, but they seem to deliver a lot of good things to a lot of users, with a much smaller budget. I'm just really grateful for the service, and glad to see the Prossimo work continuing as well. (On a tangential note, I suspect the way Let's Encrypt makes me feel is t…
Re: A Year-End Letter from our Executive Director
#57Earlier quoted context omitted.
Browsers did away with it because it says nothing about the actual security status of a page compared to any other SSL page. All it means is that the organization was verified. Customers were seeing the prominent green text and assuming a heightened level of security and trust. Legal names are also not unique, and this loophole could be used for phishing. Instead, what browsers did was promote SSL as a default (regar…
And make it almost impossible to use an out of date or self-signed cert. Some browsers make you click 3 times you know what you are doing, others don't seem to let you at all.
Re: A Year-End Letter from our Executive Director
#58Earlier quoted context omitted.
An Ex-facebook ml engineer who doesn't know what ssl is and takes pride in not having to learn it? Not sure it's a downside/upside thing. It might shed light on the types of people who get hired at facebook.
It's perfectly reasonable for someone to be into programming and not want to have to care about the details of setting up a networking stack.
Pick the brain of any accomplished engineer, and you'll quickly see that the technical knowledge they use to write code on a day to day basis is only the tip of the iceberg.
It's not reasonable to expect everyone to know everything all the time, but I don't agree people should be aspiring to just know the bare minimum either. Mediocrity is like gravity: if you don't (at least occasionally) aim higher, your trajectory will be lower than you want.
Re: A Year-End Letter from our Executive Director
#59Let's Encrypt has had such a positive impact, I think I'll start donating to them instead of Wikipedia. They're a lot more subtle with their calls to donate, but they seem to deliver a lot of good things to a lot of users, with a much smaller budget. I'm just really grateful for the service, and glad to see the Prossimo work continuing as well. (On a tangential note, I suspect the way Let's Encrypt makes me feel is t…
Can also attest to them having comfy t-shirts if you're interested in that option.
Re: A Year-End Letter from our Executive Director
#60Let's Encrypt has had such a positive impact, I think I'll start donating to them instead of Wikipedia. They're a lot more subtle with their calls to donate, but they seem to deliver a lot of good things to a lot of users, with a much smaller budget. I'm just really grateful for the service, and glad to see the Prossimo work continuing as well. (On a tangential note, I suspect the way Let's Encrypt makes me feel is t…
If you want a web-related alternative also consider archive.org (and their Wayback Machine).