Live data from Hacker News

10 Years of Let's Encrypt

letsencrypt.org

11–20 of 361 posts

Re: 10 Years of Let's Encrypt

#11
post #7
post #3

Earlier quoted context omitted.

Agreed! What were we using before Let's Encrypt again? Maybe just plain HTTP

either you used http, self signed if you did not mind the warning, and i remember there being one company that did offer free certificates that validated, but cant remember the name of it

I believe it was StartSSL and/or WoSign back then

Re: 10 Years of Let's Encrypt

#12
post #3

Wow. Feels like Let’s encrypt been around for longer.

Agreed! What were we using before Let's Encrypt again? Maybe just plain HTTP

SSL/TLS via expensive and hard to work with providers and tooling. Let's Encrypt made it free and easy to maintain.

Re: 10 Years of Let's Encrypt

#13
post #7
post #3

Earlier quoted context omitted.

Agreed! What were we using before Let's Encrypt again? Maybe just plain HTTP

either you used http, self signed if you did not mind the warning, and i remember there being one company that did offer free certificates that validated, but cant remember the name of it

> i remember there being one company that did offer free certificates that validated, but cant remember the name of it

You're probably thinking of StartSSL, and it was a bit of a pain to get it done.

Re: 10 Years of Let's Encrypt

#14
post #3

Wow. Feels like Let’s encrypt been around for longer.

Agreed! What were we using before Let's Encrypt again? Maybe just plain HTTP

Mostly Verisign, which required faxing forms and eye-watering amounts of money. Then Thawte, which brought down prices to a more manageable US$500 per host or so. Which might seem excessive, but was really peanuts compared to the price of the 'SSL accelerator' SBus card that you also needed to serve more than, like, 2 concurrent HTTPS connections.

And you try telling young people that ACME is a walk in the park, and they won't believe you...

Re: 10 Years of Let's Encrypt

#15
post #5

Let's Encrypt was _huge_ in making it's absurd to not have TLS and now we (I, at least) take it for granted because it's just the baseline for any website I build. Incredible, free service that helped make the web a more secure place. What a wonderful service - thank you to the entire team. The CEO at my last company (2022) refused to use Let's Encrypt because "it looked cheap to customers". That is absurd to me beca…

> It coming from GoDaddy is not a selling point...

I just people who use GoDaddy. They were the one company supporting SOPA when the entire rest of the internet was opposed to SOPA. It's very obvious GoDaddy is run by "business-bros" and not hackers or tech bros.

Re: 10 Years of Let's Encrypt

#16
I am glad to be one of the users using that for around 7 years. I can't think of how much better is life of people just doing blogs or some silly websites with free https certs. Would I pay 50$ bucks a year for ability to self host nextcloud? Probably not. But security enhancement is so enormous with that service. Thanks to everyone involved for making world a little bit better.

Re: 10 Years of Let's Encrypt

#17
New baseline expectation that web traffic will be encrypted on the wire: very good!

New de-facto requirement that you need to receive the blessing of a CA to make use of basic web platform features... not so good.

Re: 10 Years of Let's Encrypt

#19
post #5

Let's Encrypt was _huge_ in making it's absurd to not have TLS and now we (I, at least) take it for granted because it's just the baseline for any website I build. Incredible, free service that helped make the web a more secure place. What a wonderful service - thank you to the entire team. The CEO at my last company (2022) refused to use Let's Encrypt because "it looked cheap to customers". That is absurd to me beca…

I've seen people complain that Let's Encrypt is so easy that it's enabling the forced phaseout of long-lived certificates and unencrypted HTTP.

I sort of understand this, although it does feel like going "bcrypt is so easy to use it's enabling standards agencies to force me to use something newer than MD5". Like, yeah, once the secure way is sufficiently easy to use, we can then push everyone off the insecure way; that's how it's supposed to work.

Re: 10 Years of Let's Encrypt

#20
post #5

Let's Encrypt was _huge_ in making it's absurd to not have TLS and now we (I, at least) take it for granted because it's just the baseline for any website I build. Incredible, free service that helped make the web a more secure place. What a wonderful service - thank you to the entire team. The CEO at my last company (2022) refused to use Let's Encrypt because "it looked cheap to customers". That is absurd to me beca…

I have worked at companies that refused to use LetsEncrypt for the same reason.
Post reply on HN