Live data from Hacker News

Let’s Encrypt Receives the Levchin Prize for Real-World Cryptography

letsencrypt.org

31–37 of 37 posts

Re: Let’s Encrypt Receives the Levchin Prize for Real-World Cryptography

#31

"Let’s Encrypt is currently used by more than 280 million websites, issuing between two and three million certificates per day. I often think about how we got here, looking for some nugget of wisdom that might be useful to others." I guess it's keep trying. Keep patiently explaining, educating and building. I remember people saying "You'll never be able to topple the certs racket" - and here we are... in a age where…

Let's Encrypt was the reason I moved 8 websites to self-hosted nginx servers, because my old hoster wanted 10 Euros a month (!) per SSL certificate, despite charging a lot for that slow apache webspace already.

Even ignoring the money moving away from there was worth it. There is so much more control over my software on my own instances. I can do actual backups for free. Of course it is more work and needs more attention, but not a lot more

Re: Let’s Encrypt Receives the Levchin Prize for Real-World Cryptography

#33

I applaud the Let's Encrypt founders, past and current team for solving the automation problem that's plagued the SSL/TLS industry. The yang to that ying is a lack trust. I have zero trust in a site owner using LE certs. Domain vetting only means control of the domain ... everything inside that beautifully encrypted traffic can be insightful, helpful or script kiddies scamming the vulnerable. If one finds the scam, L…

TLS or SSL never meant that kind of safety in the first place. Even before LE, there was no guarantee that HTTPS means it's not a scam, and the PKI system has never been meant to guarantee that anyway! Let's Encrypt didn't change anything here, and they're doing exactly what they or any other CA is supposed to do.

Re: Let’s Encrypt Receives the Levchin Prize for Real-World Cryptography

#34
post #9

"Let’s Encrypt is currently used by more than 280 million websites, issuing between two and three million certificates per day. I often think about how we got here, looking for some nugget of wisdom that might be useful to others." I guess it's keep trying. Keep patiently explaining, educating and building. I remember people saying "You'll never be able to topple the certs racket" - and here we are... in a age where…

Some people care in the intelligence community ;) It's better to have LetsEncrypt and CloudFlare in the loop to protect national interests and fight against maliciouses actors.

I'm really pleased to see someone else framing this as a national security issue. It's a point of view rarely heard.

Re: Let’s Encrypt Receives the Levchin Prize for Real-World Cryptography

#35

So how the hell did Let's Encrypt convince the certificate cartel to let them in and undercut their products?

They got cross-signed by IdenTrust, which as I understand it were/are primarily selling EV certificates to financial institutions (which Let's Encrypt doesn't really compete with), rather than DV certificates (like most CAs out there do, including LE).

These days they are trusted directly by most browsers and OSes as the sibling comments mention, but the IdenTrust cross-signature was vital for bootstrapping and is still used for some older systems.

Re: Let’s Encrypt Receives the Levchin Prize for Real-World Cryptography

#36
post #29
post #28

Earlier quoted context omitted.

Wouldn't it be the opposite? If I had to rotate passwords frequently I'd want to use a password manager that could handle it for me.

There's no standard way for websites to rotate passwords through password managers.

Some password managers have automation to change passwords, but it's... janky. I think they've manually implemented stuff for some sites (and it works for some sites and managers, not all sites).

Re: Let’s Encrypt Receives the Levchin Prize for Real-World Cryptography

#37

"Let’s Encrypt is currently used by more than 280 million websites, issuing between two and three million certificates per day. I often think about how we got here, looking for some nugget of wisdom that might be useful to others." I guess it's keep trying. Keep patiently explaining, educating and building. I remember people saying "You'll never be able to topple the certs racket" - and here we are... in a age where…

What alternatives are there to get cheap easy SSL certificates? Let's Encrypt has no competition because Let's Encrypt needs no competition: it works, it's cheap, and competitors can't really provide any advantages for its target audience (mostly people who just want a cert).

> Let's Encrypt has no competition because Let's Encrypt needs no competition

I love Let's Encrypt! Truly good work for the benefit of humanity.

Still. Everything needs competition. Any single organization amassing too much influence is always a bad thing, no matter how benevolent the organization.

Post reply on HN