Live data from Hacker News

Our First Certificate Is Now Live

letsencrypt.org

211–220 of 263 posts

Re: Our First Certificate Is Now Live

#211
post #183

Earlier quoted context omitted.

Green lock = EV cert. People are trained to look for the green, not for the lock - few people other than techies even look for a grey lock. EV certs generally have much more stringent requirements than "hey, give me a cert!".

Chrome has a green lock and green 'https' for this site, which hasn't an EV cert.

That's correct - only Chrome shows green locks for domain validated certs.

Firefox uses a grey lock for domain validated certs.

Edge uses a hollowed-out grey lock for domain validated certs.

Re: Our First Certificate Is Now Live

#212

I still don't get why Mozilla and Google don't accept CACerts. Couldn't a lot of this be solved by just removing the warnings?

They'll need to pass a webtrust audit, which covers how they handle their key material amongst others. Additionally the Microsoft, Apple and Android roots have their own extra requirements added.

Re: Our First Certificate Is Now Live

#213
post #203
post #188

Earlier quoted context omitted.

Surely you would at least need access to a relevant email address on that domain? How would you bypass that?

He would need to be in control of that domain entirely. thecitibank.com is just an address that looks legitimate and is purchasable.

Ok, I understand.

On a slight side note he may not necessarily need to control the domain entirely, just have access to a privileged email address [1]

However, now it seems you won't even need access to an email address. What would stop someone creating a cert for the real citibank.com and using it for a MITM attack? How many people actually check the green bar?

[1] http://arstechnica.com/security/2015/03/bogus-ssl-certificat...

Re: Our First Certificate Is Now Live

#214
post #212

I still don't get why Mozilla and Google don't accept CACerts. Couldn't a lot of this be solved by just removing the warnings?

They'll need to pass a webtrust audit, which covers how they handle their key material amongst others. Additionally the Microsoft, Apple and Android roots have their own extra requirements added.

It always seemed odd to me how strictly CACert is treated given that TrustWave got a pass when they deliberately sold a root CA certificate for man-in-the-middle purposes.

It's almost as if money is more important than key management practices.

Re: Our First Certificate Is Now Live

#215
post #207

Earlier quoted context omitted.

Either wait for the certificate to expire, register a new certificate for the domain with another CA which LE will see and can then be used to prove ownership, or ask the originally issuing CA to revoke the certificate which will remove the need for the challenge completely.

I interpreted "you must prove control over both the server and the key used in the existing certificate" as meaning that if a Let's Encrypt certificate for the domain has been created in the past, you need to own its key (presumably proved by signing something with it) to get another one. Is that wrong? Waiting for certificates to expire could mean waiting for years, unless they have auto-renewing very short-lived ce…

LetsEncrypt does use very short-lived certificates (90 days) for this reason. However, you have to remember than when you buy a domain you already have no idea if any CA has issued valid certificates for it.

Re: Our First Certificate Is Now Live

#216

Earlier quoted context omitted.

Yes, you can. You can also do the same at every existing CA that provides domain verified certificates. From personal experience neither StartSSL nor Comodo have a human in the look – until you want more than domain verification (e.g., "green bar" EV certificates).

StartSSL at least have a human in the loop for your initial identity validation. They got in touch with me because I'd put a work address in instead of my home address, and they worked it out and sent me a very human-like email asking me to correct it.

I got also an email from a guy because my domain name had been registered that same day, telling me to wait, sure you can automate the check, but at least the email didn't look automated.

Re: Our First Certificate Is Now Live

#218
post #76
post #68

Earlier quoted context omitted.

> But a Padlock in my browser is something I trust. On the padlock note, Microsoft Edge shows a hollowed out, grey padlock for DV certificates. Only EV certs get a full green one (as well as the legal name as other browsers show for EV). See https://certsimple.com/blog/dv-ssl-in-microsoft-edge

Now we just need to add a big red icon for http sites...

Mozilla actually have announced their plans to deprecate plain HTTP: https://blog.mozilla.org/security/2015/04/30/deprecating-non...

Re: Our First Certificate Is Now Live

#219
post #75

I feel like these initiatives to make SSL available for everybody just lead to the same conclusion: EV will be the only viable alternative to show real trust, and EV is much, much more expensive than regular SSL ever was.

But that's nothing new. If you need real trust, you need EV. The win from LetsEncrypt and any other attempt to make SSL more mainstream is the encryption, not the trust. If you're using SSL you're protected from some government and ISP snooping, and from having the contents of your message or webpage altered in mid-stream by a nefarious third party like AT&T.

Protected from criminals or from the ISP snooping, yes (with a certain confidence), protected from the government (any government really) snooping most likely no. If not through their own ca (just find the one controlled by your local government. High chances there is at least one in default ca stores) than always by obtaining a warrant and requiring the website in question to share information.

Re: Our First Certificate Is Now Live

#220
post #191

Is there any possibility of peer2peer voting/vetting for certificate genuity?

No there is not.

And I don't think they will/should ever go for it. After the CAcert experience, I don't believe community based certificate signing will work in the current TLS ecosystem.

Post reply on HN