Live data from Hacker News

A Year-End Letter from our Executive Director

letsencrypt.org

91–100 of 155 posts

Re: A Year-End Letter from our Executive Director

#91

I am glad it looks like the IETF ACME specification only addresses the HTTP-01 challenge. I really would like to see improvements made to the DNS-01 challenge before it's ratified, namely, let us publish a public key to a TXT record and use the private key to sign the renewal request. Then I can revoke certbot's access to my DNS records and stop hacking the `.well-known` path.

Sorry, can you clarify what you mean by this? The ACME spec (RFC 8555: https://www.rfc-editor.org/rfc/rfc8555.html) fully specified both the HTTP-01 (Section 8.3) and the DNS-01 (Section 8.4) challenges nearly four years ago. The TLS-ALPN-01 challenge was fully specified in RFC 8737 (https://www.rfc-editor.org/rfc/rfc8737) about a year later.

In addition, the new work mentioned in this letter is ARI, or ACME Renewal Info, which is not directly tied to any of the aforementioned renewal methods.

Re: A Year-End Letter from our Executive Director

#92
post #78
post #45

Earlier quoted context omitted.

I stopped donating to Wikipedia after the size of their cash reserves were revealed. I get that's designed to protect themselves for the long term and it sounds like they've made it so they don't need my money for now, at least not at the expense of other projects that don't have such cash reserves like Let's Encrypt.

> stopped donating to Wikipedia after the size of their cash reserves were revealed. After I read your comment, I thought they had 10x annual expenses or something but really they have 18 months of runway. That's not that long IMO. https://www.washingtonpost.com/news/the-intersect/wp/2015/12...

18 months runway is included all expenses including wages, awards (that Mozilla gives out, for example to political initiatives), travel, social events and so on.

If we only looked at costs related to hosting the website they have almost 100 years. They got total assets of 191 millions, and the website hosting costs are 2.4 millions each year. 55 millions each year goes to wages (up from 46 millions previous year).

https://wikimediafoundation.org/about/annualreport/2020-annu...

Re: A Year-End Letter from our Executive Director

#93
Can somebody from LE explain why "Rust in the kernel" is a story for LE, rather than for Linux itself? Did LE e.g. do the coding? or help? is this a cross-product activity? LE is a system for bootstrapping CA certification, Rust in the kernel is a generalized memory/systems security & safety coding activity.

Not that it isn't good, but "why talk about it in a letsencrypt end of year message" -is this the wider "we" at play, or was there something specific I missed?

Re: A Year-End Letter from our Executive Director

#94
post #82

I don't understand why Let's Encrypt is OK but DANE isn't. They both use DNS to authenticate certificates, why not cut out the middleman?

There are a lot of reasons. The real reason DANE isn't deployed is that DNSSEC isn't deployed, and DNSSEC isn't deployed because (1) it's not an operational security win for most companies, and (2) it has an earned reputation for causing nightmare outages. That's why nothing uses DANE: because there are no DANE records to look up, and the most important (high-traffic, whatever) sites on the Internet disproportionatel…

All of the problems you listed around trusting TLDs applies to Let's Encrypt/ACME DNS-01 validation though...

Re: A Year-End Letter from our Executive Director

#96
post #68

In all the excitement (I too think that they did massive strides in usability of https to the masses), nobody mentions of systems-level consequences of a single entity holding the keys to 300000000 servers on the internet. They’re now in a “don’t be evil” phase. But the people move on, change, etc. And the companies get sold, rogue, bankrupt… I realize an org itself won’t fancy ponder its inevitable deviation from to…

Could you be more specific about "holding the keys"?

Sure it's annoying to change to a different service, but they don't have access to any server secrets and all their certificates are logged.

Re: A Year-End Letter from our Executive Director

#97
post #78

Earlier quoted context omitted.

> stopped donating to Wikipedia after the size of their cash reserves were revealed. After I read your comment, I thought they had 10x annual expenses or something but really they have 18 months of runway. That's not that long IMO. https://www.washingtonpost.com/news/the-intersect/wp/2015/12...

Based on what the parent said only 3% of that $77m is to run the site. The rest is spent on frivolous things I imagine if that's all it takes and they're still soliciting donations.

> 3% of that $77m is to run the site

And that are outdated numbers from 2015.

2021 report:

$153m dollars in donations spent on $67m in salaries, $10m in grants (surprisingly low, in 2020 it was $20m), $2m in hosting and like $10-20m in other professional expenses.

Net assets at the end of 2021 now at $231 mio.

https://upload.wikimedia.org/wikipedia/foundation/1/1e/Wikim...

Re: A Year-End Letter from our Executive Director

#98
post #73
post #49

Earlier quoted context omitted.

If these devices have internet access they can auto renew. If they don't, they don't need a cert signed by a public CA.

I partly agree with you, however it's possible for devices to have limited access to the internet, or even no direct access but still be accessible to devices that are on the internet. If I have a smart device at home I may put it on a network that has no outgoing access to the internet, but it would still be nice to be able to connect to it with a web browser without getting angry expired certificate warnings. It's…

A company extranet locked by a whitelist of IP addresses comes to mind. You still want a SSL installed for security.

Re: A Year-End Letter from our Executive Director

#99
post #66

Earlier quoted context omitted.

I should hope HN hashes our passwords, instead of encrypting them. And for encrypted data I would expect them to use symmetric key encryption, rather than certificates with RSA or another form of public key cryptography. Your post contains some very basic misconceptions. This is going to sound harsh, but I would recommend not putting too much stock in your own opinions on security, and instead to trust the experts.

Not harsh at all. I understand I am no security expert, bores the heck out of me. Sadly, you shouldn't trust the "experts" to be if that's LetsEncrypt. No one can be trusted apart from yourself when implementing security. If LE is ran with the following companies, "Electronic Frontier Foundation; Mozilla Foundation; University of Michigan; Akamai Technologies; Cisco Systems" What makes them all trade worthy, especial…

HN: Pretty sure their relationship with DigiCert predates LE, why change if the current relationship is functional.

Google: Browser Maintainer that runs entire TLDs, doesn't need a third party, it could just decide to trust itself and 60+% of the market follows.

Amazon: Runs a massive chunk of the internet, it's already MitM'd itself and most other things, doesn't really need a third party for Certs but still uses DigiCert which predates LE and they clearly have a working relationship.

Netflix: See Amazon, HN.

You: Barely exist to the infrastructure of the web as people experience it. Maybe you have a static site you don't care to protect from MitM (could add some malicious scripts or whatever but who cares). Maybe you're a tiny service that offers some 50 users something, their plaintext auth probably shouldn't be readable to just anyone along the network path, but they're not paying you for services so you might not wanna spend much money on that service. Use LE.

Also, if you think LE as a company has the ability to take sites with it if it goes down, you don't really understand Web PKI. At most likely within a year to 3 months you'd need to find a new place if their signatures expire. At worst someone could pretend to be you, but still not read that traffic protected by the old cert.

Why so salty about LE? Especially from a "seasoned" SysEng? Didn't it just make your job easier and safer for those with slightly less experience?

Re: A Year-End Letter from our Executive Director

#100

Earlier quoted context omitted.

So for one, if you're looking for an actual answer, dial it down a few notches. Your post is 18 minutes old as of me writing and you're already boasting about a lack of replies. Two, you're likely misunderstanding the purpose of SSL and Let's Encrypt. It's not to protect you against the site you're talking to, it's to prevent man in the middle attacks on the way. It ensures you can't walk into a starbucks for an hour…

> Before Let's Encrypt, certs cost money from certificate authorities, so not many smaller companies would bother. Now it's streamlined enough that browsers throw scary warnings if you don't have it, which is a massive improvement for everyone using the web. But should they? I never had any issues running an internet site before this was required. A blog doesn't need SSL. Why are ISP's not more scrutinized to ensure…

> I'm sure I might be "flagged" soon too.

Yes if you're going to deliberately flamebait I will flag you.

That's not you winning. You made things worse for everyone.

Post reply on HN