Let’s Encrypt Receives the Levchin Prize for Real-World Cryptography
1–10 of 37 posts
Re: Let’s Encrypt Receives the Levchin Prize for Real-World Cryptography
#2Mainly this was propagated by EV cert sellers, but it was all kinda silly.
Re: Let’s Encrypt Receives the Levchin Prize for Real-World Cryptography
#3I guess it's keep trying. Keep patiently explaining, educating and building.
I remember people saying "You'll never be able to topple the certs racket" - and here we are... in a age where every day I read about how we'll 'never' be able to break the big-tech stranglehold and build a distributed network owned by the people, 'never' have privacy and real end-to-end encryption because 'nobody cares', 'never' have practical p2p digital currencies of our own, and where we'll never have open, verifiable hardware. Keep believing.
Re: Let’s Encrypt Receives the Levchin Prize for Real-World Cryptography
#4The main thing I'm thankful for Let's Encrypt for is breaking the idea that an SSL-secured website is somehow magically less likely to be phishing or even anything but claiming it's the data from the domain you connected to, without changes. Mainly this was propagated by EV cert sellers, but it was all kinda silly.
Re: Let’s Encrypt Receives the Levchin Prize for Real-World Cryptography
#5The main thing I'm thankful for Let's Encrypt for is breaking the idea that an SSL-secured website is somehow magically less likely to be phishing or even anything but claiming it's the data from the domain you connected to, without changes. Mainly this was propagated by EV cert sellers, but it was all kinda silly.
That idea is unfortunately alive and well. Many organizations require it, much like they require 90-day password rotation and other questionable security standards.
Re: Let’s Encrypt Receives the Levchin Prize for Real-World Cryptography
#6The main thing I'm thankful for Let's Encrypt for is breaking the idea that an SSL-secured website is somehow magically less likely to be phishing or even anything but claiming it's the data from the domain you connected to, without changes. Mainly this was propagated by EV cert sellers, but it was all kinda silly.
It would be interesting to know if, say, US citizens write to the Department of State saying hey, revoke this guy's passport, I heard he ripped off somebody on Craig's List...
Re: Let’s Encrypt Receives the Levchin Prize for Real-World Cryptography
#7https://trends.shodan.io/search?query=ssl%3A%22Let+s+Encrypt...
Its use is also growing in mail servers so it's not limited to HTTPS:
https://trends.shodan.io/search?query=ssl%3A%22Let+s+Encrypt...
Re: Let’s Encrypt Receives the Levchin Prize for Real-World Cryptography
#8The main thing I'm thankful for Let's Encrypt for is breaking the idea that an SSL-secured website is somehow magically less likely to be phishing or even anything but claiming it's the data from the domain you connected to, without changes. Mainly this was propagated by EV cert sellers, but it was all kinda silly.
That idea is unfortunately alive and well. Many organizations require it, much like they require 90-day password rotation and other questionable security standards.
Re: Let’s Encrypt Receives the Levchin Prize for Real-World Cryptography
#9"Let’s Encrypt is currently used by more than 280 million websites, issuing between two and three million certificates per day. I often think about how we got here, looking for some nugget of wisdom that might be useful to others." I guess it's keep trying. Keep patiently explaining, educating and building. I remember people saying "You'll never be able to topple the certs racket" - and here we are... in a age where…