Live data from Hacker News

10 Years of Let's Encrypt

letsencrypt.org

321–330 of 361 posts

Re: 10 Years of Let's Encrypt

#321

It’s easy to forget how awful TLS was before Let’s Encrypt: you’d pay per-hostname, file tickets, manually validate domains, and then babysit a 1-year cert renewal calendar. Today it’s basically “install an ACME client once and forget it” and the web quietly shifted from The impressive bit isn’t just the crypto, it’s that they attacked the operational problem: automation (ACME), good client ecosystem, and a nonprofit…

> It’s easy to forget how awful TLS was before Let’s Encrypt: you’d pay per-hostname, file tickets, manually validate domains, and then babysit a 1-year cert renewal calendar.

I remember getting a 10(I think?) year wildcard cert in ~2009. I get why that changed and, while it's not great for my personal usage, I see the value for the majority of the web, but the story definitely looked more like "we decided to make TLS so difficult you have no choice but to automate" when it came time to finally replace it.

If there were two things which would make me happier with it all it'd be 10x rate limits on Let's Encrypt (so you don't have to even think of it when you screw something up/test different things for a week) and some more extension/standardisation of ACME on an internal facing service talking with an external DNS server to do the DNS challenge more easily in this scenario.

Re: 10 Years of Let's Encrypt

#322

Earlier quoted context omitted.

American IT Mafia? That provides free certificates? You'd think setting up renewal would be less of a hassle than dealing and paying CAs even if it's once every 3 years, so that would be a rather benevolent mafia. Which of those CAs went out of business by the way? Do you think Let's encrypt is less popular outside the US?

StartSSL, WoSign were the ones I've used. Very convenient services, much more convenient, compared to this certbot insanity. I think that the rest of the world does not have much choice, because US uses their IT superiority to force political decisions to the rest of the world. I experienced that first-hand. When my country wanted to implement MITM to improve Internet usability for their citizens, US companies blackl…

In what way do MITM certificates "improve Internet usability for their citizens"?

Re: 10 Years of Let's Encrypt

#323

I still remember the original announcement around LE and thought "Great idea, no idea if they'll be able to get buy-in from browsers/etc", now I use it on all my self-hosted sites and will probably be transitioning my employer over to it when we switch to automated renewal sometime next year. LE has been an amazing resource and every time I setup a new website and get a LE cert I smile. Especially after having lived/…

We actually spent some time making sure that we weren't going to run into problems with browsers. However, as the OP points out, because LE had a cross-signature from an existing CA, browsers didn't have to any positive action to make LE certificates work. This was absolutely essential to getting things off the ground.

Re: 10 Years of Let's Encrypt

#324
post #171

Earlier quoted context omitted.

What's the alternative, showing the company's unique registration ID? CAs invented EVs because the wanted to sell something which could make them more money than DVs. The fact that company names aren't unique means that the whole concept was fundamentally flawed from the start: there is no identifier which is both human-readable and guaranteed to uniquely identify an entity. They wanted to sell something which can't…

The alternative would have been to have the CA use human judgement when approving EV certificates and reject applications from organizations whose names shadowed better-known firms, or to only accept applications from a select set of organizations (like, say, banks). But either of those possibilities would have increased the cost of the program and limited the pool of applicants, so CAs chose the cheap, easy path whi…

How many CAs do you think there are? How many countries do you think they operate in?

Maybe we could augment the old EV cert indicator with a flag icon, but now there's yet another thing that users have to pay attention to. Maybe the CA/Browser Forum could run a clearinghouse for company names, but apart from trivial examples, there might very well be legitimate cases of two companies with the same name in the same country, just in different industries. Now do we augment the indicator with an industry icon too? Then the company changes its name, or forms a subsidiary relationship, or what have you. Now do we need to put "Meta (formerly Facebook)" or "Facebook (division of Meta)" etc. in the name?

There's just so many problems with the EV cert approach at Internet scale and they're largely beyond solvable with current infrastructure and end-user expectations.

Re: 10 Years of Let's Encrypt

#325

Seems longer than 10 years ago? But hey... Let's Encrypt absolutely changed the game... TLS and certificates were a huuuuuge PITA and expensive... we only used them when money was moving around online and they were slow most times. It was also a process to add one, update one, etc. I remember not trusting it at first because it was so easy lol. THANK YOU Let's Encrypt... you made us all more sane, saved time, and sec…

Thats what I thought when I read this too, I feel like they have been around forever.

Guess a lot has happened in 10 years.

Re: 10 Years of Let's Encrypt

#326
post #91

Earlier quoted context omitted.

Yeah, I hate how it made housing things locally without a proper domain name very difficult. My router _shouldn't_ have a globally recognized certificate, because it's not on a publicly visible host. There's certainly advantages to easily available certificates, but that has enabled browsers and others to push too far; to be sure, though, that's not really a fault of Let's Encrypt, just the people who assume it's som…

A related issue is that most consumer devices (both iPhone and current Android) make it impossible or extremely difficult to trust your own root CA for signing such certs.

A long time ago when I was playing with rolling my own PKI, each of Android, iOS, Chrome, Firefox, and even Internet Explorer allowed me to install a root CA by opening the .crt file. From what I remember, iOS popped up some warnings and added the cert as part of a profile, but it did work.

I know things like MDM/Intune/Group Policy/etc and such can A) faciliate doing this on a large number of devices and B) prevent users from doing this on their own.

Does this not work anymore?

Re: 10 Years of Let's Encrypt

#328

Earlier quoted context omitted.

I think you've left out the ecosystem of semi-scam, without that the decisions look less logical.. If you go and add a private rootCA to all your servers there are risks. You can convince yourself the risks are covered, you can convince a highly qualified security analyst. Can you convince a business intern with a checklist hired by a certification firm that underbid the one with specialists? 30K to engage with no on…

I'm not sure the alternative is sef-created RootCA. (But perhaps I don't understand the underlying case.) To me, the alternative is just a LE cert. Can do wildcards via DNS challenge.

I was replying in the context of what you were replying to where they either could spend 30k or make a private root. I'm not sure they were actually using EV but for it to cost $30k and given the topic of the thread it seems plausible they were using some technicality on EV or similar to reduce public domain validation requirements.

Re: 10 Years of Let's Encrypt

#329
I probably downloaded terabytes of data from the internet unnecessarily because https everywhere makes makes it prohibitively complicated to setup local caching proxy.

No to mention time lost waiting for downloads to finish.

I'll never understand why caching proxy is not a default part of every OS.

Re: 10 Years of Let's Encrypt

#330

Earlier quoted context omitted.

Many countries has official register of companies with at least post box address. Requiring to answer a physical letter sent to an address from the central register will be much more reliable.

Sure, and then someone just registers a company with the exact same name in another jurisdiction and EV is thwarted anyway

IMO it would make sense to tie into the trademark system. Allowing companies to build a brand reputation and protect it from impersonators is literally the whole point of that part of our legal system.

Imagine if only the owner of the McDonald's trademark could issue a certificate which displays the McDonald's name and logo, for example.

Post reply on HN