Live data from Hacker News

Our First Certificate Is Now Live

letsencrypt.org

201–210 of 263 posts

Re: Our First Certificate Is Now Live

#202
post #183

Earlier quoted context omitted.

"This comment is the exact perception about HTTPS that we need to change. It's not the job of HTTPS to say whether a website is safe or unsafe." Too late. The web industry has spent about 20 years training regular people to look for that green lock sign in the address bar and feel all warm and fuzzy about how safe the site is. You can post on hacker news all you want about what perceptions need to be changed. It's no…

Green lock = EV cert. People are trained to look for the green, not for the lock - few people other than techies even look for a grey lock. EV certs generally have much more stringent requirements than "hey, give me a cert!".

Chrome has a green lock and green 'https' for this site, which hasn't an EV cert.

Re: Our First Certificate Is Now Live

#203
post #188

Earlier quoted context omitted.

A valid certificate only allows you to have a secure connection without errors and warnings popping up all over. It does nothing to guarantee that the domain is "legit". You can already set up thecitibank.com and get an SSL certificate for it without any problem. What you can't do is get the EV (green bar) certificate where indeed you need to go through a human. But I'm pretty sure Let's Encrypt won't be giving away…

Surely you would at least need access to a relevant email address on that domain? How would you bypass that?

He would need to be in control of that domain entirely. thecitibank.com is just an address that looks legitimate and is purchasable.

Re: Our First Certificate Is Now Live

#206

Earlier quoted context omitted.

I don't think the owner of "co.uk" should have the power to issue certificates for everything below it.

To make the original comment more precise, should not proving ownership of: be enough to imply ownership of anything under that? i.e., DNS is a hierarchy — right? At the top level (a bit closer to how the original comment phrased it, I'd say that proving ownership of, . should prove ownership of all domains under that. To address the specific case of "co.uk", anyone in control of a public suffix[1] should just fail t…

Because client support isn't there for nameConstraints. I really wish it was though.

Re: Our First Certificate Is Now Live

#207
post #73

Earlier quoted context omitted.

What happens if the user loses the key? What happens if a certificate is requested, the domain is sold to a new owner and the new owner tries to request a certificate, but doesn't have access to the keys for the old one? Also, how can the new owner revoke all certificates delivered to previous owners?

Either wait for the certificate to expire, register a new certificate for the domain with another CA which LE will see and can then be used to prove ownership, or ask the originally issuing CA to revoke the certificate which will remove the need for the challenge completely.

I interpreted "you must prove control over both the server and the key used in the existing certificate" as meaning that if a Let's Encrypt certificate for the domain has been created in the past, you need to own its key (presumably proved by signing something with it) to get another one.

Is that wrong?

Waiting for certificates to expire could mean waiting for years, unless they have auto-renewing very short-lived certificates (but then you have the same problem for the authentication used to automatically get those certificates).

Re: Our First Certificate Is Now Live

#208

Earlier quoted context omitted.

But that's nothing new. If you need real trust, you need EV. The win from LetsEncrypt and any other attempt to make SSL more mainstream is the encryption, not the trust. If you're using SSL you're protected from some government and ISP snooping, and from having the contents of your message or webpage altered in mid-stream by a nefarious third party like AT&T.

I think people are making too big of a deal of SSL. So what if my browser connection to Target or Home Depot is encrypted?

Would you really want you credit card details to be sent in plaintext?

Re: Our First Certificate Is Now Live

#210
post #197
post #190

Earlier quoted context omitted.

As per the guidelines, please keep discussions civil on HN and please don't complain about being downvoted. https://news.ycombinator.com/newsguidelines.html

I am civil, but those who can't help the sick urge to downvote every single comment of mine although they all represent the same points are not civilized.

No, cpach is right. You can't post comments like "it shows your subpar human material" to Hacker News. Personal attacks are not allowed here, regardless of whether someone downvoted unfairly.

There's also the guideline specifically asking you not to go on about being downvoted.

https://news.ycombinator.com/newsguidelines.html

Post reply on HN