Live data from Hacker News

Let's Encrypt had a higher error rate for 90 minutes today

letsencrypt.status.io

111–115 of 115 posts

Re: Let's Encrypt had a higher error rate for 90 minutes today

#111
post #6

What are the viable alternatives to LE? And in case none exists, what does it take to build one? Requirements: free, available to everyone, automation friendly, issues certificates that are actually considered trustworthy by other parties.

ZeroSSL – free 90-day certs via ACME, also has a web UI for cert management Google Trust Services – free ACME certs, requires a Google account for registration SSL.com Free DV SSL – offers free 90-day certs through ACME

[deleted]

Re: Let's Encrypt had a higher error rate for 90 minutes today

#112
post #108

Earlier quoted context omitted.

Hot take, but in general single points of failure are less of an issue than it seems because usually outages simply aren't that common. Meanwhile maintaining whole infrastructure to avoid single point of failure is often very expensive.

In theory this sounds great, but you only realize how much do you rely on a single point of failure, once it fails. Just see github outages or even electricity outages at your home.

> electricity outages at your home

I haven't had one in 20 years, which kinda proves my point.

Re: Let's Encrypt had a higher error rate for 90 minutes today

#113
post #109

Earlier quoted context omitted.

No, it's not. You can always switch to a different SSL provider. There are other free ones (as mentioned in other comments). However, thinking about how to make your own setup more robust without having to manually change configuration when one SSL provider stops working is a good exercise. I wonder if you can just get your server's private key signed by multiple SSL providers, and serve multiple certificates to clie…

If you couldn't switch, that would be a monopoly. But single point of failure is when you put all your fruit in one basket. Airplanes have redundant systems, even though you can always buy new components. But it's much harder to change them mid-flight.

Ok, but that would just be your own website having a single point of failure, not that Let's Encrypt is a single point of failure. Otherwise you could call every certificate authority a single point of failure.

Re: Let's Encrypt had a higher error rate for 90 minutes today

#114

Earlier quoted context omitted.

> What are the viable alternatives to LE? None. Big tech intentionally made Let's Encrypt a single point of giant failure. > And in case none exists, what does it take to build one? A new Internet and Web standards stack. The whole problem is self-imposed -- we could have published self-signed Ed25519 keys on the DNS instead, and the result would be more secure than whatever it is we have now.

Do you remember the early days of SSL certificates? It took an act of god just to get a certificate: verification rituals like faxing corporate paper work, phone calls, manually reissuing certs because someone forgot the "www", forgotten renewals... Let's Encrypt is incredible.

This is Stockholm syndrome. You were taken hostage and beaten and raped. Now the rape has stopped and you get gruel on schedule, and you're enamored with your captor.

Re: Let's Encrypt had a higher error rate for 90 minutes today

#115

Earlier quoted context omitted.

Do you remember the early days of SSL certificates? It took an act of god just to get a certificate: verification rituals like faxing corporate paper work, phone calls, manually reissuing certs because someone forgot the "www", forgotten renewals... Let's Encrypt is incredible.

This is Stockholm syndrome. You were taken hostage and beaten and raped. Now the rape has stopped and you get gruel on schedule, and you're enamored with your captor.

[deleted]
Post reply on HN