Live data from Hacker News

Let's Encrypt had a higher error rate for 90 minutes today

letsencrypt.status.io

21–30 of 115 posts

Re: Let's Encrypt had a higher error rate for 90 minutes today

#21
post #6

What are the viable alternatives to LE? And in case none exists, what does it take to build one? Requirements: free, available to everyone, automation friendly, issues certificates that are actually considered trustworthy by other parties.

> What are the viable alternatives to LE?

None. Big tech intentionally made Let's Encrypt a single point of giant failure.

> And in case none exists, what does it take to build one?

A new Internet and Web standards stack. The whole problem is self-imposed -- we could have published self-signed Ed25519 keys on the DNS instead, and the result would be more secure than whatever it is we have now.

Re: Let's Encrypt had a higher error rate for 90 minutes today

#22

I realize this is very much not the point, but the fact that the "Active Incident" banner is green is upsetting.

The banner's colour is based on the "Incident Status;" it's green because services are currently operational. It would be yellow or red if the impact were more severe.

Re: Let's Encrypt had a higher error rate for 90 minutes today

#23
That explains why one of my IoT vendors is using an expired certificate.

I wish Firefox would just give a mild warning for a recently expired certificate, instead of treating it the same as a true man-in-the-middle attach. It's not like someone who couldn't factor the private key in 200 days could in 201 days or even 300 days.

I'm convinced that we'd have better security, if we didn't have so much security theater. You'd think TLS is useless, from the warning my phone gives if I connected to a public Wi-Fi AP, but then again there's nothing in TLS (or WPA) that prevents it from being used in a way that is completely useless: https://www.youtube.com/watch?v=M1si1y5lvkk

Re: Let's Encrypt had a higher error rate for 90 minutes today

#24
post #10

Earlier quoted context omitted.

I see you are unfamiliar with status page-ese. “Degraded performance” is a term which means some form of “the entire datacenter is probably on fire”.

Although I only post here personally, I work for Let’s Encrypt.

Let them know that they're having an outage. If their monitors aren't telling them so, they might need to host them off-site.

Re: Let's Encrypt had a higher error rate for 90 minutes today

#25
post #10

Earlier quoted context omitted.

I see you are unfamiliar with status page-ese. “Degraded performance” is a term which means some form of “the entire datacenter is probably on fire”.

Although I only post here personally, I work for Let’s Encrypt.

Thanks you for your work!

Re: Let's Encrypt had a higher error rate for 90 minutes today

#26

I realize this is very much not the point, but the fact that the "Active Incident" banner is green is upsetting.

Their monitors don't seem to be detecting the outage. Sometimes they run directly on the server, and aren't able to detect routing or DNS problems.

Re: Let's Encrypt had a higher error rate for 90 minutes today

#27
post #10

Earlier quoted context omitted.

Although I only post here personally, I work for Let’s Encrypt.

Let them know that they're having an outage. If their monitors aren't telling them so, they might need to host them off-site.

Let's Encrypt is operating normally. If you're having trouble, please post the details on the community forum so that folks can help you out. There is external monitoring in place.

Re: Let's Encrypt had a higher error rate for 90 minutes today

#29
post #5

To be clear, “Degraded Performance” means just that, not “down.” Let’s Encrypt’s issuance is mostly working fine.

I see you are unfamiliar with status page-ese. “Degraded performance” is a term which means some form of “the entire datacenter is probably on fire”.

I thought it meant "electricity has ceased to be a physical phenomenon in the general vicinity of our servers"

Re: Let's Encrypt had a higher error rate for 90 minutes today

#30

Seems not ideal for an entity who seems to be pushing for shorter expiration periods all the time

If it goes past 24 hours, that becomes a real worry.

If anyone is renewing certificates with less than a day remaining, that's an issue on their end far more than anything else.

Post reply on HN