24 ms·
Let's Encrypt Has Issued a Billion Certificates
- rasengan 7y agoStats[1] indicate about 1.5-1.7 [2] websites exist. This would mean letsencrypt certificates make up more 2/3 of the internet! [1] https://www.websitehostingrating.com/internet-statistics-facts/ https://www.websitehostingrating.com/internet-statistics-fac... [2] https://www.internetlivestats.com/total-number-of-websites/ https://www.internetlivestats.com/total-number-of-websites/ Edit: Sounds like these include renewals from the thread, but it’s still over 10pct of the internet!
- icedchai 7y agoIt sounds like a billion certificates includes renewals, so not anywhere close to 2/3rds.
- jaas 7y agoThis is correct. We currently serve about 195 million websites, where website is defined as a unique Fully Qualified Domain Name.
- icedchai 7y agoThat's still awesome though!
- DonHopkins 7y agoNot only that, but you also made a profit of zero billion dollars!!! ;) Thanks for such a valuable public service. https://www.youtube.com/watch?v=cKKHSAE1gIs https://www.youtube.com/watch?v=cKKHSAE1gIs
- johnchristopher 7y agoI'd gladly pay a dollar a year to use the service (not a dollar a year per certificate).
- penagwin 7y agoThey do accept donations! https://letsencrypt.org/donate/ https://letsencrypt.org/donate/ Disclaimer : not affiliated but if you want to support a non-profit that's the best way to do it :)
- rasengan 7y agoThat’s over 10pct! It’s still very impressive! Great job, and thank you so much!
- misterti 7y agoWhy you make me think hard with pct? Why not just use a % sign?
- totaldude87 7y agoKeep doing what you are doing.. ;)
- giancarlostoro 7y agoWouldn't it have been something if every domain purchase went towards infrastructure and projects like this one. Even an email provider that provides free mail (and you can pay extra to get more email storage) service for your domain. I wonder if gmail would of ever grown the way it did.
- maxmcd 7y agoIt's worth reading the paper: https://jhalderm.com/pub/papers/letsencrypt-ccs19.pdf https://jhalderm.com/pub/papers/letsencrypt-ccs19.pdf I don't think this is just about having money and funding, it's a very careful and tactical approach. Agree it would be nice if we find and capitalize on opportunities like this, but (to me) it would be hard to run an email provider with the operational goals they list: - Minimal logic - Minimal data - Full automation - Functional isolation - Operational isolation - Continuous availability
- giancarlostoro 7y agoCan't that be achieved with POP3 email? It downloads emails to your system and then deletes them on the server.
- randomdude402 7y agoMost people don't want to have a desktop at home be the single source of truth for their email anymore, though.
- glofish 7y agoI shudder to think about what will happen if they go down for whatever reason. Or get compromised, or the renewal gets bugged etc. It is all cool and great, but is it sustainable long term, who guarantees that everything will work in 10 years? Monocultures are not desirable. A ray of hope - you can get a two-year certificate for 10 bucks - so right there, another major benefit of Let's Encrypt, they makes for better competition. (ok I know Apple will stop honoring these starting in the Fall, but I still got two years since the expiration will be for new certificates)
- Ajedi32 7y agoThe nice thing about ACME is that it's a standardized protocol, so its really easy to configure most clients to use a different provider. All we need is a few more CAs supporting the ACME protocol, and it'd be trivial to switch over to them if Let's Encrypt ever had a problem. (Come to think of it, automatic failover would be a pretty interesting feature to include in an ACME client.)
- JMTQp8lwXL 7y agoThese points could be stated for any major certificate issuer. They could encounter an availability issue, bugs, vulnerabilities, etc. The funding model doesn't change these risks.
- niks1101 7y agoAre any of the other providers this big? 10% of all websites and growing. If the NSA get hold of the keys then it's just like the old days, or am I missing something?
- deleted 7y ago[deleted]
- derefr 7y ago> If the NSA get hold of the keys In X.509, the CA never sees the private key associated with a certificate. So while a state actor could always manufacture a “legitimate CA-signed” replacement cert and MITM you with it, they can’t do anything about modern defense-in-depth security approaches like certificate pinning, since it’s the particular public key of the original cert being pinned, not the CA’s authority + CN.
- ddevault 7y agoSince LE has certificiate transparency, can we determine which cert was the billionth? I registered two certs with them today, here's hoping it was me ;)
- jaas 7y agoIt's surprisingly hard to tell which certificate was the billionth issued. You'd have to decide on a source of truth, and CT is probably not a good one for this purpose. Submissions to CT are not necessarily made and processed in issuance order. The goal is to get all certs into CT as quickly as possible, but ordering isn't particularly important (maybe one submission from our CA starts a second before another but the network request is delayed until after the second one). At the heart of things, our certificate signing infrastructure includes multiple HSMs, each one with multiple signing cores. This means that we're signing certificates in parallel all the time. The signed certificates are inserted into our internal database in a serialized order, but due to how we optimize our database it's not easy for us to just ask "what is the billionth one." That kind of query is usually not a very useful one for us to make.
- ddevault 7y agoSo, what you're saying is that my certificate was definitely the billionth.
- cjm42 7y agoNo, he's saying that he cannot deny that your certificate was the billionth.
- tehlike 7y agoCertificates have issuance date, no? Given ntp is a thing now, we might get close to finding the billiont.
- tialaramex 7y agoThe issuance date inside a certificate is not required to be accurate. Technical reasons for inaccuracy include a widespread choice to have stuff "Just work" if you install a brand new certificate even though it's not rare for end users to have clocks wrong by ~1 hour and historically a preference to put entropy (randomness) in the date-time fields because they're near the beginning of the certificate. The latter doesn't apply to Let's Encrypt (they're too new and this is no longer the Done Thing) but the former certainly does and there might be other technical reasons for small deviations. Inaccuracies in the timestamps are only forbidden if their purpose seems to be to defeat some other policy. For example during SHA-1 deprecation new certificates were forbidden because once you cease issuing there's no new risk from collision attacks. You can't travel back in time with knowledge of a collision and get certificates, so if a collision is found in 2017 but no certs were issued after 2016 then we're safe. To enforce the prohibition certificates using SHA-1 but dated after the prohibition weren't trusted. But a misbehaving CA (in this case WoSign) could back-date a SHA-1 certificate presumably for a hefty mark-up over their usual prices. This was against the rules, Gerv (who has since died) investigated and built up good evidence that's what happened though. Anyway, there are less than 100 000 seconds in a day and in that time Let's Encrypt issues typically over a million certificates. So there might be dozens of certificates issued in the same second as the billionth one no matter how you count.
- sarcasmatwork 7y agoCongrats and Thanks Let's Encrypt crew! Using your services for awhile now.
- vuln 7y agoHow many were issued to phishing/malvertising/malicious sites?
- privateSFacct 7y agoAnd the ICANN fees we pay covered none of this (when funding this sort of thing would be an obvious benefit vs what ICANN does spend money on).
- shp0ngle 7y agowe have the fun ceremony videos though
- est31 7y agoWhy does the number in the TOTAL row and TOTAL column contain 1.7 billion? https://crt.sh/?caid=16418 https://crt.sh/?caid=16418
- jaas 7y agoProbably because it includes pre-certificates. I have to run so I don't have time to explain, but basically at a certain point we started submitting each certificate twice, the first one being a "pre-cert." You can probably Google for more info.
- est31 7y agoThanks for answering my question as well as others in this thread! Let's Encrypt is awesome.
- cm2187 7y agoAnd that's where they realise they stored the serial number on an int32!
- knodi123 7y agoint32 is enough to store one cert per ipv4 address....
- STRML 7y agoWhich isn't really enough, considering SNI and subdomains.
- Dylan16807 7y agoSo a two month supply, since serial numbers don't get reused.
- GuyPostington 7y agoHere's the boulder CA function that generates serials https://github.com/letsencrypt/boulder/blob/master/ca/ca.go#L645-L666 https://github.com/letsencrypt/boulder/blob/master/ca/ca.go#...
- throwaway8941 7y agoStable URL for posterity. https://github.com/letsencrypt/boulder/blob/4184dc3fc997d51e3a71a6274a580fc7072ec536/ca/ca.go#L645-L666 https://github.com/letsencrypt/boulder/blob/4184dc3fc997d51e...
- nwsm 7y ago>In June of 2017 we were serving approximately 46M websites, and we did so with 11 full time staff and an annual budget of $2.61M. Today we serve nearly 192M websites with 13 full time staff and an annual budget of approximately $3.35M. That's awesome. Congrats
- oh_sigh 7y agoThose two extra staff are expensive, but worth it.
- aneutron 7y agoHonestly, I don't know anything about running a business. But if there's one thing I learned in engineering, it's the great if it ain't broke, don't fix it. (I know you're joking)But even if they're costly, if they keep the service running and bring in funds, why would anyone risk damaging their business and start cutting costs ?
- three_seagrass 7y agoIn grad school, my MBA-level technology course had a case on Zara and their POS software. The case problem was that the software was running on MS-DOS, had a janky text-based interface, but managed to work well for Zara's fast-fashion inventory. The 'right' solution for the case was to not change anything at all.
- meesles 7y agoJust curious how one would know if it was the 'right' solution without having tried other solutions? I find it hard to believe that any business would not benefit from moving from an ancient computer system to one with error validations and better tooling so that their boots on the ground can make less mistakes. Forget the cost of transitioning since at scale that's a whole executive job function, but purely from a day-to-day I don't understand how what you said can be true.
- hashhar 7y agoThanks for making it all so painless. It's so good I forget it's even there. Easily the best piece of infrastructure tech I've ever used. Also, to folks who wish to "pay" for the certs, you can do so at https://letsencrypt.org/donate/ https://letsencrypt.org/donate/. A yearly recurring donation for the avg price of an SSL cert is what I do.
- LoSboccacc 7y agowe still can't certify on an alternative port, DNS is not always an option and so there's people stuck with having to shut down servers while certbot does it's thing
- __float 7y agowhat practical situation do you encounter that DNS isn't an option? why are you shutting down servers to rotate certificates? a reload should be totally possible!
- closeparen 7y agoI think it refers to stopping the main service so that certbot can bind port 80 during the verification process.
- ohyeshedid 7y agoThe person you're responding to is asking about verification through dns, which is an option that avoids the need for http verification.
- tinus_hn 7y agocertbot can host the verification files on most webservers people would already be running (like Apache and nginx) so this isn’t necessary.
- ShakataGaNai 7y agoWell, if you're running something on a non-standard port then you could just use a tool (like certbot) on the standard ports and copy over the certificates when you're done?
- gramakri 7y agoOne of the best things to happen to the internet. We started working on our product a year before Let's Encrypt and in the early days onboarding new customers was a nightmare. This is because our product required a domain to work and we spent lot of time hand-holding customers to purchase a certificate and set it up. After Let's Encrypt, this has never been a problem.
- gramakri 7y agoWanted to add that after the dns-01 challenge went live, it has become even more awesome. Many customers saw opening up port 80 as a security concern for their firewall.
- dan15 7y agoDNS challenges are great for internal services too, where you want server-to-server communication to be encrypted but the servers aren't accessible over the public internet.
- upofadown 7y agoLet's Encrypt has caused a revolution in the world of public XMPP servers. Now they are pretty much all properly encrypted for both client to server and server to server. The list of servers shows a sea of Let's Encrypt: * https://list.jabber.at/ https://list.jabber.at/ I suspect that there are a lot of other non-web applications out there that have hugely benefited as well...
- mpoteat 7y agoIf so many services use Let's Encrypt, do you think there's a risk they become a target for sneaky surveillance activities?
- upofadown 7y agoIt is much better to target a small and obscure certificate authority if you are interested in conducting wide scale MITM attacks. The entire system is only as strong as the weakest link.
- Polylactic_acid 7y agoIsn't this what certificate transparency was meant to solve?
- cmrx64 7y agohttps://letsencrypt.org/docs/ct-logs/ https://letsencrypt.org/docs/ct-logs/ why target them when it's OSINT? :) [ed: compromise of their HSM would be bad and I didn't consider active attacks, only passive]
- Swtrz 7y agoAre there any documented cases of HSM breaches anywhere or involving a CA?
- Rebelgecko 7y ago
- zck 7y agoWhat was the billionth one issued? It's a long shot, but my website had its certificate renewed today, and it would be cool to find out if I had the billionth one.
- LoSboccacc 7y agowell yeah they expire like milk
- ck2 7y agoNow with domain prices being threatened to skyrocket, let's create/adopt a free alternative to ICANN with alternate roots supported by all modern browsers like OpenNIC Yeah I know there are billions of legacy devices that will never work on it but gotta start somewhere or adopt a current alternative asap so a decade from now it's common.
- simonblack 7y agoI converted my website from http to https last weekend. Many thanks to LetsEncrypt with CertBot for making it pretty much painless.
- anurag 7y agoLet's Encrypt isn't just making the web more secure; it's enabling a new generation of startups to exist and thrive. My company relies heavily on Let's Encrypt to offer SSL for all kinds of use cases including wildcard domains. We wouldn't be here without them and we're proud to be an official sponsor. If your company can afford it, do consider a corporate sponsorship: https://letsencrypt.org/become-a-sponsor/ https://letsencrypt.org/become-a-sponsor/
- lerie1982 7y agoThank you for your service
- musicale 7y ago...and only 90% of those certs went to https://login.yourbanknamehere.com.secure-password.asp.net.totally.legit.phishing-site.download.example https://login.yourbanknamehere.com.secure-password.asp.net.t...
- denkmoon 7y agoIf you're interested in running your own CA (eg. for .lan, and not having to deal with dozens of self signed certs) and want the benefits for ACME, smallstep (step-ca) makes this really easy. Unfortunately lots of user interfaces don't support setting a custom ACME directory (the clients mostly do, but both pfsense and proxmox require fiddling to add your custom CA working via the web UI), but it's getting better.
- stevespang 7y agoShout out to the nonprofit Internet Security Research Group (ISRG) ! I got Let's Encrypt https for my website now - - stopped getting hosed/trolled by GoDaddy for $89 a year for https, something that should be FREE.
- justlexi93 7y agoWould be interesting to know how many of those billion+ are flat out bad/malicious.
- saurabhnanda 7y agoNot to take away from this achievement, but no one else bothered about this massive centralisation of critical security infrastructure?
- panny 7y agoI'm concerned Mozilla will soon begin to use their intolerant leftist attitudes like a weapon against specific domains. They already fired their founder for being less than perfectly aligned with their radical leftist ideology. I can easily see them forming a policy against AbortionIsMurder.com or ThereAreOnlyTwoSexes.com. I don't use their service because I'm sure that day is coming.
- globular-toast 7y agoI've always been concerned about the centralised model of SSL. But interestingly whenever I mention that the model is broken and web of trust is the best thing we have I get downvoted and shouted at here on HN.
- doublerabbit 7y agoI get the same. Single point of failure and you don’t even get insurance if something does go tits up. Unlike you would with a normal paid SSL certificate . If ICANN can’t be trusted what makes me want to trust LetsEncrypt. I don’t trust it, I won’t use it. I don’t like it.
- burnJS 7y agoThank you!
- cloudking 7y agoThanks for saving us so much money and making the web more secure!
- tafsiralahlam 7y agocheck also this khwab ki tabeer https://tabeerinfo.com https://tabeerinfo.com
- nojvek 7y agoWhat made Let’s encrypt go through the roof is a whole bunch of providers effortlessly make your site https compatible. Like netlify (hosting a static site with build is super easy). Same with Cloudflare and a bunch of others. As a user it’s all abstracted at simply the push of a button.
- fyrefoxboy12 7y agoand chrome doesn't trust it
- coryfklein 7y agoAnd of course the first few pages (or 20%) of the comments are about Wikimedia budgets lol.