4 ms·
While HTTPS is being burned into the architecture of the Web, I have a humble question to ask: what is the dear HN community's next-best-option in a scenario if
by sdrinf 9y ago
While HTTPS is being burned into the architecture of the Web, I have a humble question to ask: what is the dear HN community's next-best-option in a scenario if letsencrypt dies/gets sued/goes under/servers not accessible anymore?
I ponder on this question seeing how Google is planning to increasingly depreciate HTTP. While in general, I welcome the security upgrade, the lack of next-best-free-options makes me vary of this config change locking us into a $$$paid-only web publishing system.
- kemitche 9y agoACME is a protocol - I imagine most of us are hoping that, should LE fade off, one or more others take the reins and implement it.
- badrabbit 9y agoWith PKI,a good protocol isn't the problem but rather making the cost of infrastructure keep-up worthwhile. Anyways, non-pki protocols are in the works.
- sdrinf 9y ago> non-pki protocols are in the works. Could you kindly link to relevant threads / RFCs / orgs / undertakings currently working on that, please?
- aeden 9y agoDANE might provide a solution. See specifically the section https://tools.ietf.org/html/rfc6698#section-2.1.1 https://tools.ietf.org/html/rfc6698#section-2.1.1, certificate usage 3: 3 -- Certificate usage 3 is used to specify a certificate, or the public key of such a certificate, that MUST match the end entity certificate given by the server in TLS. This certificate usage is sometimes referred to as "domain-issued certificate" because it allows for a domain name administrator to issue certificates for a domain without involving a third-party CA.
- tscs37 9y agoThis would need DNS to be secured though and DNSSEC is still a bit of a mess last I checked and not enabled for a majority of DNS traffic.
- aeden 9y agoDNSSEC support is increasing each year, but that's just one issue. DANE would also need to be implemented by browsers for full adoption, not just as a plugin to specific browsers. Then again, I was responding to the question about an RFC or other standard, not whether it was feasible today. ;-)
- tscs37 9y agoIt would be feasible if DNSSEC wasn't a total mess, tbh. The support for it is still abysmal and a lot of resolvers (including the one in my router) can't handle DNSSEC responses at all. I think using DNS over HTTPS in conjunction with signing the response is going to be more viable since you don't have 200 ways a middle box will break it.
- tptacek 9y agoIf you want to sign over the security of the Web PKI to the United States Government, DANE is a pretty effective way to accomplish that. It is, essentially, an Internet key escrow scheme.
- badrabbit 9y agoThis is one I personally have grown fond of: https://github.com/DeDiS/cothority https://github.com/DeDiS/cothority I've heard of blockchain based ideas as well but I'll leave that to your google-fu
- dorfsmay 9y agoBut it would have to be somebody who already have their public root keys in all the browsers.
- cm2187 9y agoBut Let's encrypt is not just the ACME protocol, it is ACME + free certificates.
- fulafel 9y agoWith Lets's Encrypt, consensus hopefully strengthens that the cert system is not a good situation. This may eventually web browsers to support TLS PKI methods other than X.509.
- deleted 9y ago[deleted]
- icebraining 9y agoFree is certainly nice, and I'd probably go back to self-signed for a few private subdomains, but you can get a paid cert for under $3/year. The only people really screwed would be those running a non-profit project that used many (sub)domains.
- discreditable 9y agoWhere are these $3/year certs? Cheapest I've found is about $9.
- nacs 9y agoFrom a quick search, looks like Comodo's PositiveSSL is being resold for $3.88 for 1 year and $2.88/yr for 2 years.
- icebraining 9y agossls.com (Namecheap). They're on sale, but even the regular price is only $7 (if you buy two years).
- piracykills 9y agoThe thing about certificate authorities is the whole system is as insecure as the worst of them, so you may as well go find the cheapest. I've even managed to get wildcards for $30/year from an alphassl reseller.
- nickjj 9y agoMy automation tools are slowly migrating towards a proper PKI set up that supports ACME, self signed certs and external certs (vendor signed certs from anywhere). I first saw this strategy used in the DebOps project's PKI Ansible role at https://docs.debops.org/en/latest/ansible/roles/debops.pki/ https://docs.debops.org/en/latest/ansible/roles/debops.pki/. Basically if LE goes down, all I have to do is make 1 line of YAML changes, run an Ansible script and my servers are secured by a different provider's certificate.