Earlier quoted context omitted.
I stopped donating to Wikipedia after the size of their cash reserves were revealed. I get that's designed to protect themselves for the long term and it sounds like they've made it so they don't need my money for now, at least not at the expense of other projects that don't have such cash reserves like Let's Encrypt.
> stopped donating to Wikipedia after the size of their cash reserves were revealed. After I read your comment, I thought they had 10x annual expenses or something but really they have 18 months of runway. That's not that long IMO. https://www.washingtonpost.com/news/the-intersect/wp/2015/12...
A Year-End Letter from our Executive Director
81–90 of 155 posts
Re: A Year-End Letter from our Executive Director
#82I don't understand why Let's Encrypt is OK but DANE isn't. They both use DNS to authenticate certificates, why not cut out the middleman?
The other big reason DANE isn't deployed, even as a trial balloon in browsers for the rare cases where DANE records actually exist, is that the Internet is full of middleboxes (caches and rando routers) that block DNSSEC, or really any atypical DNS response at all. The browsers tried rolling out DANE, and it caused reliability problems. DANE advocates tried to work around this with stapled DANE records as a TLS extension, which failed due to security concerns, and is now a dead letter.
(There is an obvious chicken-egg thing happening between these first two reasons that strongly suggests this will remain a stable equilibrium.)
The best reason DANE isn't deployed is that it vests keying authority with organizations that can't be revoked. World governments control most of the most important TLDs, and most of those have demonstrated repeatedly that they will alter the DNS for their own policy goals. Google can dis-trust CAs that act up, and in fact they did that a few years ago for one of the largest CAs in the world. Google can't dis-trust .COM. Mozilla can realistically threaten to dis-trust any CA that doesn't implement Certificate Transparency, but nobody can threaten a TLD owner if they don't enroll in a (fictitious) DANE Transparency program --- part of the reason there is no such program.
Re: A Year-End Letter from our Executive Director
#83Earlier quoted context omitted.
As someone that supports Let's Encrypt's efforts and playing devil's advocate, I imagine a downside is that the bar is lowered and nefarious websites can easily get SSL-equipped channels compared to the high paywall of prior.
What is the downside of this?
Re: A Year-End Letter from our Executive Director
#84Earlier quoted context omitted.
An Ex-facebook ml engineer who doesn't know what ssl is and takes pride in not having to learn it? Not sure it's a downside/upside thing. It might shed light on the types of people who get hired at facebook.
It's perfectly reasonable for someone to be into programming and not want to have to care about the details of setting up a networking stack.
Re: A Year-End Letter from our Executive Director
#85Earlier quoted context omitted.
I stopped donating to Wikipedia after the size of their cash reserves were revealed. I get that's designed to protect themselves for the long term and it sounds like they've made it so they don't need my money for now, at least not at the expense of other projects that don't have such cash reserves like Let's Encrypt.
> stopped donating to Wikipedia after the size of their cash reserves were revealed. After I read your comment, I thought they had 10x annual expenses or something but really they have 18 months of runway. That's not that long IMO. https://www.washingtonpost.com/news/the-intersect/wp/2015/12...
Re: A Year-End Letter from our Executive Director
#86Earlier quoted context omitted.
Quoted post unavailable.
So for one, if you're looking for an actual answer, dial it down a few notches. Your post is 18 minutes old as of me writing and you're already boasting about a lack of replies. Two, you're likely misunderstanding the purpose of SSL and Let's Encrypt. It's not to protect you against the site you're talking to, it's to prevent man in the middle attacks on the way. It ensures you can't walk into a starbucks for an hour…
But should they? I never had any issues running an internet site before this was required. A blog doesn't need SSL. Why are ISP's not more scrutinized to ensure that MITM doesn't happen? Why is it put upon the admin? My blog from 2005 was never hit with MITM.
> If you're a microsoft, that can mean thousands if not millions of users hitting this wall they expect not to have, leading to huge costs for customer support and occassionally deeper issues updating certificates. Exactly the same reason Bank of America doesn't use godaddy.com for their domain name.
So your saying LE is only worth for small-class sites such as "blogs", which than I above said, Why does a blog need SSL? The only reasoning I had which was valid was that "ISP's inject" and if that's the case why are ISP's allowed to get away with injection?
> Your post is 18 minutes old as of me writing and you're already boasting about a lack of replies.
Folks like to down-vote and never reply. I'm sure I might be "flagged" soon too.
> Two, you're likely misunderstanding the purpose of SSL and Let's Encrypt.
Not at all, SSL is the communications protocol. A encrypted-tunnel example made by HTTPS. Verified by a Certificate if we apply laymans terms. LetsEncrypt issues that certification based on the trusted root installed on your computer and if all valid, the brower throws a green badge. I can easily remove the LE root certificate and any LE encrypted site would be invalid.
Re: A Year-End Letter from our Executive Director
#87In all the excitement (I too think that they did massive strides in usability of https to the masses), nobody mentions of systems-level consequences of a single entity holding the keys to 300000000 servers on the internet. They’re now in a “don’t be evil” phase. But the people move on, change, etc. And the companies get sold, rogue, bankrupt… I realize an org itself won’t fancy ponder its inevitable deviation from to…
If you mean is it dangerous for one organization to have a root CA that if it went entirely rogue could theoretically be used to MITM peoples' traffic, that is definitely a concern, and why a process exists for removing a root CA from the mozilla, chrome, microsoft etc root CA trust stores.
Re: A Year-End Letter from our Executive Director
#88Let's Encrypt has had such a positive impact, I think I'll start donating to them instead of Wikipedia. They're a lot more subtle with their calls to donate, but they seem to deliver a lot of good things to a lot of users, with a much smaller budget. I'm just really grateful for the service, and glad to see the Prossimo work continuing as well. (On a tangential note, I suspect the way Let's Encrypt makes me feel is t…
Re: A Year-End Letter from our Executive Director
#89I don't understand why Let's Encrypt is OK but DANE isn't. They both use DNS to authenticate certificates, why not cut out the middleman?
There are a lot of reasons. The real reason DANE isn't deployed is that DNSSEC isn't deployed, and DNSSEC isn't deployed because (1) it's not an operational security win for most companies, and (2) it has an earned reputation for causing nightmare outages. That's why nothing uses DANE: because there are no DANE records to look up, and the most important (high-traffic, whatever) sites on the Internet disproportionatel…
Speaking of TLDs, there are still some TLDs that don't support DNSSEC at all, meaning that some that do want to use DNSSEC/DANE (usually for certificate pinning for MX systems) have migrated to TLDs that do. Also IIRC DANE can be used in a "verify that this is the key but also checked if it's signed by a trustworthy CA", but at this point why bother?
Re: A Year-End Letter from our Executive Director
#90Before Letsencrypt, SSL signing was cumbersome and downright scary sometimes. With cPanel + letsencrypt (or whatever their default Auto SSL provider is [0]), it's a few clicks and done. If there's a downside, I have never seen nor heard of it. Side note: I was expecting this CEO letter to end with layoffs. [0] https://docs.cpanel.net/whm/ssl-tls/manage-autossl/