10 Years of Let's Encrypt
261–270 of 361 posts
Re: 10 Years of Let's Encrypt
#262Earlier quoted context omitted.
Don't pick on this particular SSL requirement, pick on the deluge of requirements that only make sense for a site that sells something or handles personal data (i.e. has accounts). They get extended to $RANDOM_SITE that only serves static text and the occasional cat photo for no good reason except "your cats will be more secure!".
GP: At least on business plans this is incorrect, it defaults to (last time I checked) accepting any SSL certificate including self signed from edge to origin and it’s a low friction option to enforce either valid or provided CA/PubKey certs for the same path. Parent: those innocuous cat photos are fine in the current political climate… “First they came for the cat pic viewers, but I did not speak up…”
How does SSL on a -ing public site protect you from being arrested by miniluv?
It’s public, you want everyone to see the cat photos, that’s why you set up the site. On the contrary, SSL certs mean another party through which miniluv can track you. They prove or are supposed to prove identity not hide it.
Re: 10 Years of Let's Encrypt
#263Earlier quoted context omitted.
Let’s Encrypt currently has a single primary with a handful of replicas, split across a primary and backup DC. We’re in progress of adopting Vitess to shard into a handful of smaller instances, as our single big database is getting unwieldy.
Thanks. Would love to see a tech blog post once you get Vitess implemented.
Re: 10 Years of Let's Encrypt
#264Earlier quoted context omitted.
American IT Mafia? That provides free certificates? You'd think setting up renewal would be less of a hassle than dealing and paying CAs even if it's once every 3 years, so that would be a rather benevolent mafia. Which of those CAs went out of business by the way? Do you think Let's encrypt is less popular outside the US?
StartSSL, WoSign were the ones I've used. Very convenient services, much more convenient, compared to this certbot insanity. I think that the rest of the world does not have much choice, because US uses their IT superiority to force political decisions to the rest of the world. I experienced that first-hand. When my country wanted to implement MITM to improve Internet usability for their citizens, US companies blackl…
Re: 10 Years of Let's Encrypt
#265Earlier quoted context omitted.
Just a few months ago my company was going through some transitions and wanted to get some certs to cover us while we migrated to a different stack with let's encrypt and automated cert renewals. We had some legacy systems on our network that needed certs and had various subdomains that prevented us from just having a wildcard cert. It ended up that we needed a few dozen subdomains with wildcard certs for each, and i…
I think the best analogy for this are scams. Once a scammer finds a mark they'll pay, there's a desire to soak them for as much as they'll bear. EVs are not a scam per-se, but they also don't add any value. 80% of the world already figured that out, do by definition if you are asking you are in the bottom 20%. Now I get you were in the process of migration, but that's an edge case. In a normal case if you go around a…
Re: 10 Years of Let's Encrypt
#266Earlier quoted context omitted.
Android is pretty easy, you just add it to the keystore and that's it. I've had my own CA long before Let's Encrypt, but now mostly only use it for non-public devices that can't easily use Let's Encrypt (printers, switches, etc).
You can add it to your user CA store, but no app will trust it since it's treated differently from the system CA store, which you can't modify without root or building your own ROM. In effect it is out of reach for most normal users, as well as people using security focused ROMs like Graphene, when ironically it can improve security in transit in many cases.
Re: 10 Years of Let's Encrypt
#267Re: 10 Years of Let's Encrypt
#268Let's Encrypt was _huge_ in making it's absurd to not have TLS and now we (I, at least) take it for granted because it's just the baseline for any website I build. Incredible, free service that helped make the web a more secure place. What a wonderful service - thank you to the entire team. The CEO at my last company (2022) refused to use Let's Encrypt because "it looked cheap to customers". That is absurd to me beca…
I once notified Porsche that one of their websites had an expired certificate, they fixed it within a couple of hours by using Let's Encrypt. It surprised me. Let's Encrypt is to the internet what SSDs are to the PC. A level up.
Re: 10 Years of Let's Encrypt
#269Earlier quoted context omitted.
There are literally thousands of web hosts out there. If your web host is doing something shitty like that, it's trivial to find a new one.
I'd be happy to hear about a traditional hosting company that allows clients to install lets Encrypt certs if you can name any... Most of my clients don't have budgets big enough for cloud hosting.
Not only do they just allow you to import any certificate you want, but they literally have a button on the panel to get one from Let's Encrypt for free.