Live data from Hacker News

A Year-End Letter from our Executive Director

letsencrypt.org

1–10 of 155 posts

Re: A Year-End Letter from our Executive Director

#5
post #4

I love them. I'm not really sure how SSL works or what it is (and frankly I don't care to know the details) but with 2 commands I can get that magical lock on any website. I'm glad they're doing well. Thank you!

I'm not sure that's a good thing

What's a downside of that?

Re: A Year-End Letter from our Executive Director

#7
post #4

I love them. I'm not really sure how SSL works or what it is (and frankly I don't care to know the details) but with 2 commands I can get that magical lock on any website. I'm glad they're doing well. Thank you!

I'm not sure that's a good thing

It saves me from the implementation details, this way I don't need to wear another engineer/sysadmin hat. I think the website content is more important than the SSL implementation!

Re: A Year-End Letter from our Executive Director

#8
Before Letsencrypt, SSL signing was cumbersome and downright scary sometimes. With cPanel + letsencrypt (or whatever their default Auto SSL provider is [0]), it's a few clicks and done. If there's a downside, I have never seen nor heard of it.

Side note: I was expecting this CEO letter to end with layoffs.

[0] https://docs.cpanel.net/whm/ssl-tls/manage-autossl/

Re: A Year-End Letter from our Executive Director

#9

Quoted post unavailable.

> some shady websites

What are you talking about?

A clever design aspect of Let’s Encrypt is the deliberately short expiry. That forces administrators to automate the issuance and renewal process.

Not to mention that you’re not supposed to “download” the private key!

The whole idea of PKI is to generate the private key locally and then have a CA sign only the public part.

If you’re doing anything else you’ve undermined the entire purpose of the thing.

I mean you are literally -- not figuratively -- handing your secrets over to Russian hackers and complaining about the people politely showing you how to make your systems safe.

Learn about the ACME protocol and certificate automation: https://letsencrypt.org/docs/client-options/

Re: A Year-End Letter from our Executive Director

#10
post #6

Quoted post unavailable.

>Why letsencrypt director writes about nvme driver? Why people can't focus on one specific thing. It's literally a director's job to focus on more than one specific thing.

And Josh is the ED of the Internet Security Research Group, of which Lets Encrypt is just one product/service. As mentioned in his letter, they also run and support Prossimo (https://www.memorysafety.org) -- so the Rust drivers and memory safe kernel are directly in their area of interest and are something they're investing in and supporting.
Post reply on HN