Live data from Hacker News

Let's Encrypt is Trusted

letsencrypt.org

291–300 of 318 posts

Re: Let's Encrypt is Trusted

#291

Earlier quoted context omitted.

Let's Encrypt isn't the first to offer free TLS certificates. I've attempted to maintain a list of all the providers that do (in one way or another), and it's currently 4: * CloudFlare https://www.cloudflare.com/ssl * StartSSL https://startssl.com * WoSign https://buy.wosign.com/free * Let's Encrypt https://letsencrypt.org For people reading this comment dozens of months in the future, a maintained list will be kept…

They are not quite the same thing: * CloudFlare doesn't give you a certificate. It terminates your TLS connection at their endpoint with a certificate they own the private key to. * StartSSL free tier is for non-commerical use only. * Haven't used WoSign so no idea what it is, but clicking on the link took was so laggy it didn't give me much confidence. (I personally wouldn't work with a company in China jurisdiction…

I use WoSign. Free 3 year certificates although I'm not using it for security just to enable SPDY.

Re: Let's Encrypt is Trusted

#292

Earlier quoted context omitted.

They are not quite the same thing: * CloudFlare doesn't give you a certificate. It terminates your TLS connection at their endpoint with a certificate they own the private key to. * StartSSL free tier is for non-commerical use only. * Haven't used WoSign so no idea what it is, but clicking on the link took was so laggy it didn't give me much confidence. (I personally wouldn't work with a company in China jurisdiction…

What would be the difference in using WoSign vs any other? If you use a CSR and not let them generate the private key I would think their certificates are identical to any other providers.

It doesn't matter much for TLS certificates (the slowness might though) except if they choose to issue another certificate under your name with their private key to MITM your connections, it'd look more legitimate if your real certificate is issued by the same CA, but admittedly, the real issue here is on the client side: browsers trusting way too many CAs that directly include many governments.

Re: Let's Encrypt is Trusted

#293
post #214

Being told that you now trust someone with your secrets via a news website is a pleasingly succinct display of everything that's wrong with the CA model.

Well. The CA model is community trust. I am told all the time, often by news websites, that my government now trusts or distrusts some other government, that my employer now trusts or distrusts or is even part of some other company, etc. I don't know if I personally think that the embargoes on Cuba should be lifted, or my company's new vice president is qualified for the role, or (if I worked for VMware) Dell is a go…

CAs are CAs because they established themself. Personally I don't trust them because they are susceptible to MitM attacks & government intervention attacks.

Some Mesh Networks & protocols like the Tor Browser use an IP derived from a public key.. so you're absolutely sure that who you're talking to is who they say they are.

Why can't we have our cake (long distance electronic communications) and eat it too? (encryption & assuredness of identity)

Celebrating "trustedness" of LetsEncrypt only perpetuates the belief that CA is working fine.

EDIT: See below discussion by other posters

Re: Let's Encrypt is Trusted

#294

Being told that you now trust someone with your secrets via a news website is a pleasingly succinct display of everything that's wrong with the CA model.

We’re pleased to announce that we’ve received cross-signatures from IdenTrust This is what is wrong with the CA, model, not their method of announcing it to a community anxiously awaiting the arrival of their product. What is absurd is that identrust has a shitty non-responsive 90's looking website and wants $299 for an SSL certificate, which is something that should be free. I will say though, they really did sell m…

link: https://www.identrust.com/

Re: Let's Encrypt is Trusted

#295

Being told that you now trust someone with your secrets via a news website is a pleasingly succinct display of everything that's wrong with the CA model.

You would like to buy a knitted scarf from a yak herder in Ecuador. How do you propose that establish trust between you and the yak guy without an intermediary?

Crypto currency with escrow, receipt of goods validated by a robot camera sending a picture to an anonymous network of validators who say "yep that's the scarf they ordered, trigger the payment"

Re: Let's Encrypt is Trusted

#296
post #167

Earlier quoted context omitted.

> Is there still value to buying an expensive cert from another vendor? If you are running a commercial, high-traffic website, then yes, there is. For example, EV (extended validation) certificates is currently the only way to quickly build and maintain a "reputation" with 3rd party website ranking systems such as Microsoft's SmartScreen and, based on anecdotal evidence, with Symantec SafeWeb and Google SafeBrowsing…

Do you have any recommendations on which CA is good for EV certs (that work in Chrome)?

We use DigiCert.

They are generally good. There was one case when they started pulling a Comodo thing on us - the lawyer's signature was unintelligible, go and redo the paper - for some secondary document. But each email includes a note to email their support head if something's off, which is what we did and he had the cert issued in an hour after that. So the tops do care about their service levels and there's an easy way to escalate issues.

Re: Let's Encrypt is Trusted

#297

Earlier quoted context omitted.

You would like to buy a knitted scarf from a yak herder in Ecuador. How do you propose that establish trust between you and the yak guy without an intermediary?

Crypto currency with escrow, receipt of goods validated by a robot camera sending a picture to an anonymous network of validators who say "yep that's the scarf they ordered, trigger the payment"

That system still appears to include intermediaries. They're just stuck in a Rube Goldberg machine rather than dealing directly with the two parties.

Re: Let's Encrypt is Trusted

#298
post #148

Earlier quoted context omitted.

"EV certs are going to be the only ones that get the 'green' chrome in browsers anymore." Are there any facts to back up this claim? Edit: This is what HN looks like in Firefox 38.0.5: http://img4.imagetitan.com/img4/RsbN6Rsn61k2IMN/12/12_l.png Sure, the background color is white, but there's still a padlock icon.

Image not found

I don’t know what happened there. Try https://i.imgur.com/cY0Kx6x.png

Re: Let's Encrypt is Trusted

#299
post #278

Earlier quoted context omitted.

I'm sure they're not opposed to it. It's a work in progress!

It's up and running now -- J. C. Jones gave a reference to search the log via a web interface. https://crt.sh/?caid=7395 If you want to dive in more, you can get this data in other formats too.

So does this make the existence of my https site public, even if I'm not linked to from anywhere?

Re: Let's Encrypt is Trusted

#300
post #283

Earlier quoted context omitted.

To be clear, I am massively excited to use Let's Encrypt and plan on setting up SSL for the first time ever when it launches. I am legit broke so I can't afford to pay a lot of money for someone to have an automated process of: gpg --gen-key I was responding to parent, that announcing trust is a werid quirk of the CA model. TBH, that is correct, but I find it more bizarre Let's Encrypt has to be "trusted" by an unkno…

Although I loved your sarcastic remarks about the cool pictures, I do want to point out that there are two issues with your argument: a) There is something else that you know about IdenTrust, and that is that your browser vendor trusts them. This is the whole point of this CA thing: in the end you trust whom your browser vendor trusts (with the option of removing CAs for which you disagree). This is far from perfect…

You raise some good points, and I totally agree. The thing is, when the drduh Yosemite guide came out (around the time Google dropped CNNIC) I looked into it a bit. I dropped a ton of certs, mostly international ones (about 40) and the only site that broke was Bing.

> you trust who your browser trusts

Exactly, and my OS. But I run Mac and I am sure Windows users can relate, there are over 200 CAs and I have no idea what heuristics can be used to determine whether they are trustworthy. It wouldn't be a big deal except a compromise at ANY means they could fake ANY website.

Now, on a serious note. If you were running node and you had a super clean react front end with a picture of Jamie lee Miller from hackers super imposed over the ghostbusters symbol (responsive using html5 flex boxes) for sure I would trust you with the security for every website I visit.

I just meant the comment more as idem trust looks like a random rent collector who hasn't updated their business model since 1995. As a broker of trust, I find it disconcerting I know fuck all about them and even if I did, there are hundreds more like that. If you have the money, I don't because I am broke, for sure it would be worth $100 for a padlock when a user hits your site. With nothing more to go on than their site though, it looks like they have been on autopilot for 10 years and I can't wait for Lets encrypt to go live.

Post reply on HN