Live data from Hacker News

10 Years of Let's Encrypt

letsencrypt.org

291–300 of 361 posts

Re: 10 Years of Let's Encrypt

#291
post #280
post #274

Earlier quoted context omitted.

Modern browsers are going out of their way to hide every bit of information about the website (including even the URL) — so I don't know how these customers would actually even find out what CA issued the certificate. In Safari, I don't even know how to find that information anymore. When I want to check expiration dates for my own sites, I start Firefox.

It’s the symbol to the left of the URL > Show Certificate. They even make it available on iOS Safari (Page Info > Connection Security Details), but if it’s expired, you’ll know by the big red warning page.

I don't have that :-) — what I see when I click the thingamajig on the left side of the URL is a menu with "Hide Distracting Items", "Zoom", "Find" and "Website settings".

Re: 10 Years of Let's Encrypt

#292
post #159

Earlier quoted context omitted.

The problem is that people wrongly believe that company names are unique. In reality you're just some paperwork and a token registration fee away from a name clash. If anything, it's a disadvantage . People are going to be less cautious about things like the website's domain name if they see a familiar-sounding company name in that green bar. "stripe-payment.com" instead of "stripe.com"? Well, the EV says "Stripe, In…

In many countries, company names are unique to that country. And combined with country TLDs controlled by the nation-state itself, it'd be possible for at least barclays.co.uk to be provably owned by the UK bank itself when a EV cert is presented by the domain. In the US though, every state has it's own registry, and names overlap without the power of trademark protection applying to markets your company is not in.

Are company names even unique within the UK? Sure, there can be only one bank named Barclays because of trademark laws, but can't there be a company in a different sector with the same name? Like Apple the computer business vs Apple the record company?

Or don't you have small local businesses (restaurants, pubs, stores) with duplicate names as long as they're in different locations? I know here in Flanders we have, for example, tens if not more places called "Café Onder den toren" (roughly translated as "Pub beneath the tower"). Do all local businesses in the UK have different names?

Re: 10 Years of Let's Encrypt

#293
post #37

Earlier quoted context omitted.

I once notified Porsche that one of their websites had an expired certificate, they fixed it within a couple of hours by using Let's Encrypt. It surprised me. Let's Encrypt is to the internet what SSDs are to the PC. A level up.

An apt metaphor, … until I read recently on HN that storage on SSDs only last 1 year when unplugged. https://news.ycombinator.com/item?id=46038099

Let's Encrypt certificates last even only 90 days when unplugged.

Re: 10 Years of Let's Encrypt

#294
post #291
post #280

Earlier quoted context omitted.

It’s the symbol to the left of the URL > Show Certificate. They even make it available on iOS Safari (Page Info > Connection Security Details), but if it’s expired, you’ll know by the big red warning page.

I don't have that :-) — what I see when I click the thingamajig on the left side of the URL is a menu with "Hide Distracting Items", "Zoom", "Find" and "Website settings".

For me it’s hidden behind a kebab menu in that thingamajig you described.

Re: 10 Years of Let's Encrypt

#295

Earlier quoted context omitted.

GP: At least on business plans this is incorrect, it defaults to (last time I checked) accepting any SSL certificate including self signed from edge to origin and it’s a low friction option to enforce either valid or provided CA/PubKey certs for the same path. Parent: those innocuous cat photos are fine in the current political climate… “First they came for the cat pic viewers, but I did not speak up…”

Wrong metaphor though? How does SSL on a -ing public site protect you from being arrested by miniluv? It’s public, you want everyone to see the cat photos, that’s why you set up the site. On the contrary, SSL certs mean another party through which miniluv can track you. They prove or are supposed to prove identity not hide it.

Sorry that wasn’t particularly clear, I was taking more about the general advantageous nature of normalising encryption.

WRT to another party to track you, one of the benefits of LE is that you only need to provide proof of domain ownership (eg dns txt) so the only tie back to you is whatever information you give to the registrar that you have to provide anyway.

Re: 10 Years of Let's Encrypt

#296
post #291

Earlier quoted context omitted.

I don't have that :-) — what I see when I click the thingamajig on the left side of the URL is a menu with "Hide Distracting Items", "Zoom", "Find" and "Website settings".

For me it’s hidden behind a kebab menu in that thingamajig you described.

Well, either it isn't there in my Safari (macOS 15.7.2) or I can't find it.

I have found "Connection Security Details…" in the "Safari" menu, though. But my point still stands: average users won't see any certificate information without serious effort.

Re: 10 Years of Let's Encrypt

#297
post #5

Let's Encrypt was _huge_ in making it's absurd to not have TLS and now we (I, at least) take it for granted because it's just the baseline for any website I build. Incredible, free service that helped make the web a more secure place. What a wonderful service - thank you to the entire team. The CEO at my last company (2022) refused to use Let's Encrypt because "it looked cheap to customers". That is absurd to me beca…

has anyone actually commented to you in a negative way about using Let's Encrypt? I couldn't imagine, but curious on others' experiences.

One thing I heard recently which might be a valid point - that LE is based in US, which makes it a subject to US laws. Read from that what you will though.

Re: 10 Years of Let's Encrypt

#298
post #5

Let's Encrypt was _huge_ in making it's absurd to not have TLS and now we (I, at least) take it for granted because it's just the baseline for any website I build. Incredible, free service that helped make the web a more secure place. What a wonderful service - thank you to the entire team. The CEO at my last company (2022) refused to use Let's Encrypt because "it looked cheap to customers". That is absurd to me beca…

has anyone actually commented to you in a negative way about using Let's Encrypt? I couldn't imagine, but curious on others' experiences. One thing I heard recently which might be a valid point - that LE is based in US, which makes it a subject to US laws. Read from that what you will though.

Why is that problematic? They don't have your private keys and their "level of access" is equivalent to any other certificate authority that your browser trusts.

Re: 10 Years of Let's Encrypt

#299
post #5

Let's Encrypt was _huge_ in making it's absurd to not have TLS and now we (I, at least) take it for granted because it's just the baseline for any website I build. Incredible, free service that helped make the web a more secure place. What a wonderful service - thank you to the entire team. The CEO at my last company (2022) refused to use Let's Encrypt because "it looked cheap to customers". That is absurd to me beca…

has anyone actually commented to you in a negative way about using Let's Encrypt? I couldn't imagine, but curious on others' experiences. One thing I heard recently which might be a valid point - that LE is based in US, which makes it a subject to US laws. Read from that what you will though.

No matter where they were based they would be subject to US laws since they offer services to US peoples. (similar to how everyone here always points out that US companies are subject to EU laws if they offer services in the EU).

Re: 10 Years of Let's Encrypt

#300
post #5

Let's Encrypt was _huge_ in making it's absurd to not have TLS and now we (I, at least) take it for granted because it's just the baseline for any website I build. Incredible, free service that helped make the web a more secure place. What a wonderful service - thank you to the entire team. The CEO at my last company (2022) refused to use Let's Encrypt because "it looked cheap to customers". That is absurd to me beca…

> Let's Encrypt was _huge_ in making it's absurd to not have TLS

I still find it too much of pain in the ass to deal with to justify for my personal stuff. Easier to just click through the warning every time.

Post reply on HN