Live data from Hacker News

10 Years of Let's Encrypt

letsencrypt.org

241–250 of 361 posts

Re: 10 Years of Let's Encrypt

#241
post #40

Earlier quoted context omitted.

It's absolutely new. No HTML5 features were restricted to secure origins only pre-LE. Today, many are. Google was able to push these requirements in large part due to Let's Encrypt's success making secure origins ubiquitous.

The order of events is a bit more complicated than this. Google initially proposed restricting powerful features to secure origins back in February of 2015 ( https://web.archive.org/web/20150125103531/https://www.chrom... ) and Mozilla proposed requiring secure origins for all new features in April of 2015 ( https://blog.mozilla.org/security/2015/04/30/deprecating-non... ). Let's Encrypt issued its first certificate…

I'd also argue, very necessary.

A lot of thd new APIs have to do with accessing hardware. Camera, Microphone, Serial ports (currently experimental) etc.

Given how easy a MITM attack to injection JavaScript or HTML into insecure pages is, a world where insecure pages had access to hardware makes that hardware very vulnerable.

Even though all you'd be doing is reading some random blog etc.

To those who still think serving HTTP is some sort of principled stand, just be aware that injecting malware onto your page at delivery time is pretty trivial. Quite honestly, and I mean this in a constructive way, it doesn't signal "principles" it signals "incompetence".

Re: 10 Years of Let's Encrypt

#242

It’s easy to forget how awful TLS was before Let’s Encrypt: you’d pay per-hostname, file tickets, manually validate domains, and then babysit a 1-year cert renewal calendar. Today it’s basically “install an ACME client once and forget it” and the web quietly shifted from The impressive bit isn’t just the crypto, it’s that they attacked the operational problem: automation (ACME), good client ecosystem, and a nonprofit…

My experience was: get 3-year certificate for free, install it and forget about it. With LetsEncrypt, it's always pain, expired websites everywhere. Too bad that american IT mafia put these good CA out of business.

American IT Mafia? That provides free certificates? You'd think setting up renewal would be less of a hassle than dealing and paying CAs even if it's once every 3 years, so that would be a rather benevolent mafia. Which of those CAs went out of business by the way?

Do you think Let's encrypt is less popular outside the US?

Re: 10 Years of Let's Encrypt

#243
post #138

Another amazing success born at Mozilla: "The Let's Encrypt project was started in 2012 by two Mozilla employees, Josh Aas and Eric Rescorla, together with Peter Eckersley at the Electronic Frontier Foundation and J. Alex Halderman at the University of Michigan." https://en.wikipedia.org/wiki/Let%27s_Encrypt What was Mozilla's role, beyond conception? Parenting? Care and feeding? A roof?

A lot of this is covered in the Let's Encrypt retrospective paper from 2019: https://www.abetterinternet.org/documents/letsencryptCCS2019....

From Section 3.1.

"Let’s Encrypt was created through the merging of two simultaneous efforts to build a fully automated certificate authority. In 2012, a group led by Alex Halderman at the University of Michigan and Peter Eckersley at EFF was developing a protocol for automatically issuing and renewing certificates. Simultaneously, a team at Mozilla led by Josh Aas and Eric Rescorla was working on creating a free and automated certificate authority. The groups learned of each other’s efforts and joined forces in May 2013.

...

Initially, ISRG had no full-time staff. Richard Barnes of Mozilla, Jacob Hoffman-Andrews of EFF, and Jeff Hodges (under contract with ISRG) began developing Let’s Encrypt’s CA software stack. Josh Aas and J.C. Jones, both with Mozilla at the time, led infrastructure development with assistance from Cisco and IdenTrust engineers. ISRG’s first full-time employee, Dan Jeffery, joined in April 2015 to help prepare the CA’s infrastructure for launch. Simultaneously, James Kasten, Peter Eckersley, and Seth Schoen worked on the initial ACME client (which would eventually become Certbot) while at the University of Michigan and EFF. Kevin Dick of Right Side Capital Management, John Hou of Hou & Villery, and Josh Aas constituted the team responsible for completing a trusted root partnership deal and signing initial sponsors."

Re: 10 Years of Let's Encrypt

#244
A couple of years ago, I went through the process of signing a kenel minifiter that I wrote for our endpoint-security product. It was complicated, to put it mildly.

Imagine if we had a similar process for websites! Thanks Let's Encrypt.

Re: 10 Years of Let's Encrypt

#246

Earlier quoted context omitted.

A related issue is that most consumer devices (both iPhone and current Android) make it impossible or extremely difficult to trust your own root CA for signing such certs.

Android is pretty easy, you just add it to the keystore and that's it. I've had my own CA long before Let's Encrypt, but now mostly only use it for non-public devices that can't easily use Let's Encrypt (printers, switches, etc).

You can add it to your user CA store, but no app will trust it since it's treated differently from the system CA store, which you can't modify without root or building your own ROM. In effect it is out of reach for most normal users, as well as people using security focused ROMs like Graphene, when ironically it can improve security in transit in many cases.

Re: 10 Years of Let's Encrypt

#247
post #5

Let's Encrypt was _huge_ in making it's absurd to not have TLS and now we (I, at least) take it for granted because it's just the baseline for any website I build. Incredible, free service that helped make the web a more secure place. What a wonderful service - thank you to the entire team. The CEO at my last company (2022) refused to use Let's Encrypt because "it looked cheap to customers". That is absurd to me beca…

I have also heard a negative about it being somehow "cheap" and we can "afford" a proper wildcard for our website from managers back in the day, like, few years ago. Never mind the hours wasted every year changing that certificate in every system out there and always forgetting a few.

Also a valid point from security people is that you leak your internal hostnames to certificate transparency lists once you get a cert for your "internal-service.example.com" and every bot in existence will know about it and try to poke it.

I solved these problems by just not working with people like that anymore and also getting a wildcard Let's Encrypt it certificate for every little service hosted - *.example.com and not thinking about something being on the list anymore.

Re: 10 Years of Let's Encrypt

#248
post #5

Let's Encrypt was _huge_ in making it's absurd to not have TLS and now we (I, at least) take it for granted because it's just the baseline for any website I build. Incredible, free service that helped make the web a more secure place. What a wonderful service - thank you to the entire team. The CEO at my last company (2022) refused to use Let's Encrypt because "it looked cheap to customers". That is absurd to me beca…

Old browsers on old hardware without its CA baked in.

Re: 10 Years of Let's Encrypt

#249

Earlier quoted context omitted.

Many host providers (Those acquired by companies like Web.Com, allegedly) disable all ability to use outside certs since Google made encryption a requirement in Chrome Browser... They do things like blocking containers & SSH to make installing free certs impossible. They also have elevated the price of their own certs (that they can conveniently provide) to ridiculous prices in contrast to free certs their customers…

There are literally thousands of web hosts out there. If your web host is doing something shitty like that, it's trivial to find a new one.

I'd be happy to hear about a traditional hosting company that allows clients to install lets Encrypt certs if you can name any...

Most of my clients don't have budgets big enough for cloud hosting.

Re: 10 Years of Let's Encrypt

#250

Earlier quoted context omitted.

Many host providers (Those acquired by companies like Web.Com, allegedly) disable all ability to use outside certs since Google made encryption a requirement in Chrome Browser... They do things like blocking containers & SSH to make installing free certs impossible. They also have elevated the price of their own certs (that they can conveniently provide) to ridiculous prices in contrast to free certs their customers…

> It would be a huge price-fixing scandal if Congress had any idea of how technology works. It's shady, but technically not price-fixing unless they are a monopoly. You are free to take your business to somewhere else.

If you read into Web.Com, yes, they are quickly becoming a monopoly on host companies. They do not disclose many of the hosting companies they now own.

If you can find a company that allows clients to install Let's Encrypt Certs on shared hosting, please let me know.

Post reply on HN