Live data from Hacker News

Our First Certificate Is Now Live

letsencrypt.org

101–110 of 263 posts

Re: Our First Certificate Is Now Live

#101
post #44

Does anybody know if there is any protection built in against MITM or DNS poisoning attacks? It feels like this makes network hop security far more important. If I'm able to insert a MITM or DNS poisoning anywhere between where letsencrypt.org's servers are and where it thinks the requesting server should be then I can generate a false certificate. For example, Amazon's DNS resolves for letsencrypt as 1.2.3.4 which r…

According to their 31C3 talk, they will use multiple connections from multiple locations (possibly including Tor?) to mitigate against these attacks.

Re: Our First Certificate Is Now Live

#103
post #75

I feel like these initiatives to make SSL available for everybody just lead to the same conclusion: EV will be the only viable alternative to show real trust, and EV is much, much more expensive than regular SSL ever was.

As far as I can tell EV certificates are completely worthless.

You know the TLS certificate you got from bankofamerica.com is legitimately from bankofamerica.com because of domain validation. What EV tells you on top of that is only that bankofamerica.com belongs to Bank of America Corporation. But you already have that information. Their website is written on the walls of all their bank branches and all the documents they've ever given you. You don't need a CA to verify that because you can trivially do it your own self. And the same is true for any person you actually know. You know their domain belongs to them because it's the domain they personally told you belongs to them.

So that leaves domains belonging to entities you've never otherwise encountered outside of their internet site. You may have never been to a Google office before. But if you've never encountered the entity outside of its internet site then the association is meaningless. What am I supposed to know of Google other than google.com?

Re: Our First Certificate Is Now Live

#104

Quick question, apart from having a prettier website, what's the differentiator with StartSSL which is also free, automated, and open?

Certificate revocation for free (which is a big deal!), commercial use for free, multiple hosts for free…

StartSSL might also refuse you if you try to request a certificate on behalf of a friend or a client, as they sometimes checks if WHOIS lines up with your identity validation. Quite the hassle for domain-validated certs :-/

Re: Our First Certificate Is Now Live

#105

Quick question, apart from having a prettier website, what's the differentiator with StartSSL which is also free, automated, and open?

Unless things have changed drastically recently (it's been a little while since I've used them), StartSSL is not "open" for any meaningful definition of the word.

Re: Our First Certificate Is Now Live

#106
dance song! daffy dance prod vivid official video worldwide soon new dance song hit the daffy produced by vivid! if you like music check this dance song out this is the the official video too the dance! tutorial on HOW to do the Dance coming soon make sure you guysa be on the look for more exclusive videos! this the link guys! https://youtu.be/Hub032PuylU

Re: Our First Certificate Is Now Live

#107

Earlier quoted context omitted.

But that's nothing new. If you need real trust, you need EV. The win from LetsEncrypt and any other attempt to make SSL more mainstream is the encryption, not the trust. If you're using SSL you're protected from some government and ISP snooping, and from having the contents of your message or webpage altered in mid-stream by a nefarious third party like AT&T.

I think people are making too big of a deal of SSL. So what if my browser connection to Target or Home Depot is encrypted?

Well it's possible and reasonable that you don't want to have what products your browsing to be snooped on by some sort of MITM attack. While probably not from MITM snooping, Target found out a teenage girl was pregnant before her own parents, and sent her parent's address Diaper and Baby advertisements: http://www.forbes.com/sites/kashmirhill/2012/02/16/how-targe...

Re: Our First Certificate Is Now Live

#108
post #75

I feel like these initiatives to make SSL available for everybody just lead to the same conclusion: EV will be the only viable alternative to show real trust, and EV is much, much more expensive than regular SSL ever was.

Who do you expect to care whether the certificate is EV or not? (serious question) Google is not EV, facebook isn't either, banks are 50/50, almost none of the big online shops are EV (amazon included). I've never heard anyone raise this as an issue - technical or not.

Re: Our First Certificate Is Now Live

#109
post #63

Earlier quoted context omitted.

I run https://certsimple.com : we only do EV certificates, we're the fastest place to get an EV cert, we check as much as we can before you pay us a cent, and our application process is 80 seconds.

Is it possible to get a wildcard EV certificate?

Wildcards are prohibited on EV certificates per CA/B Forum requirements: https://cabforum.org/wp-content/uploads/EV-V1_5_61.pdf (Section 9.2.2)

Re: Our First Certificate Is Now Live

#110
post #75

I feel like these initiatives to make SSL available for everybody just lead to the same conclusion: EV will be the only viable alternative to show real trust, and EV is much, much more expensive than regular SSL ever was.

As far as I can tell EV certificates are completely worthless. You know the TLS certificate you got from bankofamerica.com is legitimately from bankofamerica.com because of domain validation. What EV tells you on top of that is only that bankofamerica.com belongs to Bank of America Corporation. But you already have that information . Their website is written on the walls of all their bank branches and all the documen…

There's one difference (I don't think it really matters though) - if you go to bankofarnerica.com and get a valid certificate for bankofarnerica.com, if would not be owned by "Bank of America Corporation". But I agree it's worthless because it relies on you remembering that bankofamerica.com has an EV cert normally. And people are terrible at noticing what's missing.
Post reply on HN