Any one else getting a 'Secure Connection Failed' error at https://helloworld.letsencrypt.org/ in FF after adding the root certificate?
Our First Certificate Is Now Live
201–210 of 263 posts
Re: Our First Certificate Is Now Live
#202Earlier quoted context omitted.
"This comment is the exact perception about HTTPS that we need to change. It's not the job of HTTPS to say whether a website is safe or unsafe." Too late. The web industry has spent about 20 years training regular people to look for that green lock sign in the address bar and feel all warm and fuzzy about how safe the site is. You can post on hacker news all you want about what perceptions need to be changed. It's no…
Green lock = EV cert. People are trained to look for the green, not for the lock - few people other than techies even look for a grey lock. EV certs generally have much more stringent requirements than "hey, give me a cert!".
Re: Our First Certificate Is Now Live
#203Earlier quoted context omitted.
A valid certificate only allows you to have a secure connection without errors and warnings popping up all over. It does nothing to guarantee that the domain is "legit". You can already set up thecitibank.com and get an SSL certificate for it without any problem. What you can't do is get the EV (green bar) certificate where indeed you need to go through a human. But I'm pretty sure Let's Encrypt won't be giving away…
Surely you would at least need access to a relevant email address on that domain? How would you bypass that?
Re: Our First Certificate Is Now Live
#204Re: Our First Certificate Is Now Live
#205Re: Our First Certificate Is Now Live
#206Earlier quoted context omitted.
I don't think the owner of "co.uk" should have the power to issue certificates for everything below it.
To make the original comment more precise, should not proving ownership of: be enough to imply ownership of anything under that? i.e., DNS is a hierarchy — right? At the top level (a bit closer to how the original comment phrased it, I'd say that proving ownership of, . should prove ownership of all domains under that. To address the specific case of "co.uk", anyone in control of a public suffix[1] should just fail t…
Re: Our First Certificate Is Now Live
#207Earlier quoted context omitted.
What happens if the user loses the key? What happens if a certificate is requested, the domain is sold to a new owner and the new owner tries to request a certificate, but doesn't have access to the keys for the old one? Also, how can the new owner revoke all certificates delivered to previous owners?
Either wait for the certificate to expire, register a new certificate for the domain with another CA which LE will see and can then be used to prove ownership, or ask the originally issuing CA to revoke the certificate which will remove the need for the challenge completely.
Is that wrong?
Waiting for certificates to expire could mean waiting for years, unless they have auto-renewing very short-lived certificates (but then you have the same problem for the authentication used to automatically get those certificates).
Re: Our First Certificate Is Now Live
#208Earlier quoted context omitted.
But that's nothing new. If you need real trust, you need EV. The win from LetsEncrypt and any other attempt to make SSL more mainstream is the encryption, not the trust. If you're using SSL you're protected from some government and ISP snooping, and from having the contents of your message or webpage altered in mid-stream by a nefarious third party like AT&T.
I think people are making too big of a deal of SSL. So what if my browser connection to Target or Home Depot is encrypted?
Re: Our First Certificate Is Now Live
#209Re: Our First Certificate Is Now Live
#210Earlier quoted context omitted.
As per the guidelines, please keep discussions civil on HN and please don't complain about being downvoted. https://news.ycombinator.com/newsguidelines.html
I am civil, but those who can't help the sick urge to downvote every single comment of mine although they all represent the same points are not civilized.
There's also the guideline specifically asking you not to go on about being downvoted.