Let's Encrypt issues 35 certs every second
twitter.com
Let's Encrypt issues 35 certs every second
1–10 of 31 posts
Re: Let's Encrypt issues 35 certs every second
#2Re: Let's Encrypt issues 35 certs every second
#3Re: Let's Encrypt issues 35 certs every second
#4And somehow having one of these prevents your website from being "illegitimate"...
Before HTTPS was popular, I used to see ISPs inject tracking JavaScript or ads into arbitrary websites for their "customers".
So, in some sense yes, this preserves a legitimate version of your website for the requester.
Re: Let's Encrypt issues 35 certs every second
#5And somehow having one of these prevents your website from being "illegitimate"...
Or are you just being snarky for the sake of being snarky?
Re: Let's Encrypt issues 35 certs every second
#6Let's Encrypt has definitely been a net positive to the internet as a whole. I do wish more services/tools had cleaner integration. I've switched to mostly using Caddy for personal web and reverse proxy chores as it's just much easier to deal with imo.
Re: Let's Encrypt issues 35 certs every second
#7And somehow having one of these prevents your website from being "illegitimate"...
Bad actors can get TLS certificates issued for their phishing sites just the same as you can for a regular website. Encryption is for everybody.
Re: Let's Encrypt issues 35 certs every second
#8And somehow having one of these prevents your website from being "illegitimate"...
It prevents the data between you and the requester from being read or tampered with in-transit. Before HTTPS was popular, I used to see ISPs inject tracking JavaScript or ads into arbitrary websites for their "customers". So, in some sense yes, this preserves a legitimate version of your website for the requester.
Re: Let's Encrypt issues 35 certs every second
#9Earlier quoted context omitted.
It prevents the data between you and the requester from being read or tampered with in-transit. Before HTTPS was popular, I used to see ISPs inject tracking JavaScript or ads into arbitrary websites for their "customers". So, in some sense yes, this preserves a legitimate version of your website for the requester.
And browsers would give a huge red alert for self-signed certs but say nothing about plaintext HTTP. Presumably that’s where the snark is coming from. Clearly the plaintext HTTP was less secure than self-signed certs but browsers perpetuated the “trusted” cert cartel.