Live data from Hacker News

10 Years of Let's Encrypt

letsencrypt.org

41–50 of 361 posts

Re: 10 Years of Let's Encrypt

#41
post #18

> 10 Years of Let's Encrypt Aren't they only 45 days [1] old ? [1] https://letsencrypt.org/2025/12/02/from-90-to-45

Not sure if you're joking or not, but I have to deal with this upcoming change at some point and still haven't read in detail why they decided to do this.

Could anyone clarify?

Re: 10 Years of Let's Encrypt

#42
post #26

Earlier quoted context omitted.

Can you elaborate a bit about what you mean by "the blessing of a CA"? I agree that it's true that you need a certificate to do TLS, but importantly Let's Encrypt isn't interested in what you do with your certificate, just that you actually control the domain name. See: https://letsencrypt.org/2015/10/29/phishing-and-malware.html

Their policy today is to grant certificates liberally. There is no technical guarantee that this remains the case indefinitely, only a political one. I don't doubt the sincerity of this guarantee, but I wish I didn't have to rely on it.

I agree that technical guarantees are better than policy guarantees.

Re: 10 Years of Let's Encrypt

#43
post #33

Earlier quoted context omitted.

What about OV?

I've never seen (noticed) an OV cert in real life, and no business I've ever been responsible for pushed for OV over DV. It was always EV or "huh?"

Before LE, we did lots of OV (which you generally could get a couple of for free from somewhere). We had to dig up stuff like a heating bill, because evidently that is proof of organizational control to some people.

Re: 10 Years of Let's Encrypt

#45
post #33

Earlier quoted context omitted.

What about OV?

I've never seen (noticed) an OV cert in real life, and no business I've ever been responsible for pushed for OV over DV. It was always EV or "huh?"

I think I've seen one or two, and only because I noticed them as a weird callout in a $LARGE_FINANCE_INSTITUTION infosec bingo sheet. Of course I had to check that they really were running with OV certs.

Some of the outfits in that space will be heavily hit by the shortening certificate max-lifetimes, and I do hope that the insurance companies at some point also stop demanding a cert rotation before 90 days to expiry. It's a weird feeling to redline a corporate insurance policy when their standard requirements are 15 years out of date.

Re: 10 Years of Let's Encrypt

#47
I'm not sure that I'm more surprised that it's only been 10 years or that it's been that long. I mean, that's a relatively quick turn around to pretty much dominate TLS certs to the point that it's the default for so many platforms... that HTTPS has become such a norm over the exception.

On the other hand, has it really been that long, it seems just yesterday I was first trying to configure nginx for it. That said, since I discovered Caddy, I haven't really looked back, though I do use Traefik too.

I mean, by comparison, it feels like IE6 took longer to die than Let's Encrypt has been around.

Re: 10 Years of Let's Encrypt

#48
post #5

Let's Encrypt was _huge_ in making it's absurd to not have TLS and now we (I, at least) take it for granted because it's just the baseline for any website I build. Incredible, free service that helped make the web a more secure place. What a wonderful service - thank you to the entire team. The CEO at my last company (2022) refused to use Let's Encrypt because "it looked cheap to customers". That is absurd to me beca…

I have heard, but do not aggree, that Let‘s Encrypt is risky, because phishing sites use it. It’s implied that other CAs do checks against it.

Re: 10 Years of Let's Encrypt

#49
post #5

Let's Encrypt was _huge_ in making it's absurd to not have TLS and now we (I, at least) take it for granted because it's just the baseline for any website I build. Incredible, free service that helped make the web a more secure place. What a wonderful service - thank you to the entire team. The CEO at my last company (2022) refused to use Let's Encrypt because "it looked cheap to customers". That is absurd to me beca…

> has anyone actually commented to you in a negative way about using Let's Encrypt? A friend of mine has had a negative experience insofar as they are working for a small company, using maybe only 15–20 certs and one day they started getting hounded by Let's Encrypt multiple times on the email address they used for ACME registration. Let's Encrcypt were chasing donations and were promptly told where to stick it with…

>one day they started getting hounded by Let's Encrypt multiple times

>trying to get a small company to shell out $50k as a "donation".

>Even more so if, like Let's Encrypt, you are turning up on the doorstep asking for $50k a pop.

Does your friend have anything to corroborate this claim? Perhaps the email with identifying details censored?

I have a received an occasional email mentioning donations. They are extremely infrequent and never ask me for a specific amount. I would be incredibly surprised to see evidence of "hounding" and requests for $50,000.

Re: 10 Years of Let's Encrypt

#50
post #5

Let's Encrypt was _huge_ in making it's absurd to not have TLS and now we (I, at least) take it for granted because it's just the baseline for any website I build. Incredible, free service that helped make the web a more secure place. What a wonderful service - thank you to the entire team. The CEO at my last company (2022) refused to use Let's Encrypt because "it looked cheap to customers". That is absurd to me beca…

> has anyone actually commented to you in a negative way about using Let's Encrypt? A friend of mine has had a negative experience insofar as they are working for a small company, using maybe only 15–20 certs and one day they started getting hounded by Let's Encrypt multiple times on the email address they used for ACME registration. Let's Encrcypt were chasing donations and were promptly told where to stick it with…

“They sent a few emails soliciting donations” isn’t exactly a horror story in my experience. Seems hardly worth mentioning!
Post reply on HN