Live data from Hacker News

A Year-End Letter from our Executive Director

letsencrypt.org

151–155 of 155 posts

Re: A Year-End Letter from our Executive Director

#151
post #13

Earlier quoted context omitted.

It saves me from the implementation details, this way I don't need to wear another engineer/sysadmin hat. I think the website content is more important than the SSL implementation!

Indeed! It's how security should work, and should be the default dual-goal of any piece of security software: provide as much security as possible to as many people as possible.

Having people do things without understanding what exactly they are doing is a good way to create a website with a very good ssl certificate and their private key available on the website itself… or similar issues.

Re: A Year-End Letter from our Executive Director

#152
post #141

Earlier quoted context omitted.

There is no upper bound on how much profit they can take out as wages, and there is no lower bound either. They don't need to match wages with oil companies. Charities have a common guideline that a maximum of 25% of donations is allowed to go to operations of the charity and minimum of 75% must go to the purpose of the charity. That mean if you donate to cancer research, 75% should go to cancer research and a maximu…

You've confused some words and missed the forest for the trees. It's recommended they spend 65% on program activities for certain third party charity ratings, for which Wikimedia Foundation passes.

Resulting to insults doesn't makes conversations more interesting nor do they convince anyone.

When Wikipedia is asking for donations to keep the servers running then people expect more than 2% of the donations will go to that purpose. If they asked for donations to operate and pay wages to the foundation then they a perfectly free to do so and people wouldn't call them out as much when 49% is taken out as wages.

Re: A Year-End Letter from our Executive Director

#153
post #120

Earlier quoted context omitted.

A company extranet locked by a whitelist of IP addresses comes to mind. You still want a SSL installed for security.

Yeah but that's a lot less common these days: https://www.usenix.org/system/files/login/articles/login_dec... I don't want LE to waste money supporting such use cases.

Ever since LE added wildcards it’s not as bad - get the cert on one machine, copy it via scripts to all.

Re: A Year-End Letter from our Executive Director

#154
post #124

We need someone to pull a Let's Encrypt in the identity space. A nonprofit that provides the convenience of single-click social login without the tracking. All it would need to do is provide a domain that verifies you control an email address, then let's services do OIDC flows to that domain to log you in.

Aren't there too many free services that already do that? LE won on cost, automation, and no upselling

No post body was provided.

Re: A Year-End Letter from our Executive Director

#155
post #152

Earlier quoted context omitted.

You've confused some words and missed the forest for the trees. It's recommended they spend 65% on program activities for certain third party charity ratings, for which Wikimedia Foundation passes.

Resulting to insults doesn't makes conversations more interesting nor do they convince anyone. When Wikipedia is asking for donations to keep the servers running then people expect more than 2% of the donations will go to that purpose. If they asked for donations to operate and pay wages to the foundation then they a perfectly free to do so and people wouldn't call them out as much when 49% is taken out as wages.

[deleted]
Post reply on HN