4 ms·
I agree that free LE certs disrupt the TLS certificate market pricing and a lot of CAs are probably going to be out of business for that matter.
by devy 9y ago
I agree that free LE certs disrupt the TLS certificate market pricing and a lot of CAs are probably going to be out of business for that matter.
- snakeanus 9y agoAnd this is a great thing.
- ivanr 9y agoActually, it's not necessarily a great thing. Issuing certificates cost money and has to be paid one way or another. Having one very dominant CA -- even if it's free -- is not healthy long term. We need competition in this space.
- DaiPlusPlus 9y agoThe cost of issuing domain-validated certificates is negligible - there's no reason they couldn't be done for free and paid through advertising or other long-tail revenue sources (or in LetsEncrypt's case: donations and endowment).
- snakeanus 9y agoI believe that it would be better if all CAs disappeared and a new system such as public-keys-as-urls/hashes-as-urls (like tor/i2p/gnunet/etc) or a web-of-trust based solution was adopted. > Issuing certificates cost money Making a post on HN probably costs more money than issuing certificates.
- Karunamon 9y agoEven if you're not using a proper PKI, you still have to trust someone at the end of the day to not be lying to you. That's ostensibly the point behind CAs and auditing and trust roots. LE's probably the best we're going to get for a long time. Mozilla's one of the few groups I'd go so far as to say is completely benevolent, and LE is being operated as a public service.
- Kadin 9y ago> Issuing certificates cost money and has to be paid one way or another. It's not clear that the prices being charged by commercial CAs are anywhere close or even related to the underlying costs. I think LE is beginning to demonstrate that the costs of operating a CA are not actually that high, at the same time that the lax behavior by certain commercial CAs has demonstrated that the "validation" they provide is of very little value.
- Karunamon 9y agoMost of the cost tied up in being a CA is being audited and reaudited by a third party that charges hundreds of thousands of dollars (and given the Symantec/Startcom shenanigans, is completely worthless). The actual technical infrastructure required, while intricate, isn't that hard to set up.
- walrus01 9y agoI think the market for TLS CA will segment into basically two things: a) free letsencrypt certificates for everything that only needs to be domain-validated (DV SSL). b) $95/year EV certificates for companies that want the big friendly green banner on their ecommerce/credit card checkout pages, which is reassuring to the average non techincal user. In the last 4 years I have seen the price for EV SSL certs fall from $400/year to $95/year from several vendors. My main concern is that EV SSL issuers need to be held to a very high standard of actually verifying corporate identity. If they start getting lax about it and known EV certs go out to not-fully-vetted organizations, that would be a bad thing for the whole idea behind EV.