5 ms·
How do these services make money? edit: thanks for the replies!
by lambda_obrien 6y ago
How do these services make money?
edit: thanks for the replies!
- dewey 6y agohttps://letsencrypt.org/sponsors/ https://letsencrypt.org/sponsors/
- toomuchtodo 6y agoLet’s Encrypt is a non profit funded by donors, other vendors sell value add services (the free SSL cert is marketing/a loss leader). More options are good, Let’s Encrypt is mandatory to ensure good (or non predatory or oligopoly) behavior by other cert providers. It’s a check on their power.
- brunoluiz 6y agoLet's encrypt is not run for profit, and is sponsored by many companies. https://letsencrypt.org/about/ https://letsencrypt.org/about/ https://www.abetterinternet.org/ https://www.abetterinternet.org/
- Spivak 6y agoBut a more direct answer to the parents question is that they "make money" by providing a service that by virtue of its existence saves the sponsoring companies money and headache. I'm surprised this model isn't more common as an alternative to licensing.
- anonunivgrad 6y agoCollective action problem. You don’t have to sponsor to reap the benefits. You can pull it off for this or that cause celebre, but it’s not a workable model in general.
- 0df8dkdf 6y agowell when you are service that has to rely on them to renew your site every 90 days, the data alone from different site is worth money. “ The world’s most valuable resource is no longer oil, but data.” ~The Economist, May 6, 2017
- dewey 6y agoExcept that they (At least in LE's case) are funded by a lot of companies and donors and are not in it for the money. https://letsencrypt.org/privacy/#we-do-not-sell-your-data-or-information https://letsencrypt.org/privacy/#we-do-not-sell-your-data-or...
- hedora 6y agoWhat information can they (theoretically) gather beyond certificate renewal times (which can be inferred by any web scraper)?
- 0df8dkdf 6y agoWell you don't have to scrap it. And a centralised CA authority seems dangerous. I'm not saying LE is bad it one of good thing that came along. However, whenever we trust to one authority it alway gets dangerous. So yes I personally welcome another CA. However, don't think your data is or will not be used for something. Organization change, and people who runs the organization change.
- TheDong 6y ago> Well you don't have to scrape it Certificate logs from the certificate transparency project [0] are already public knowledge and shared freely. The only thing lets encrypt gets in addition to what's in those logs and publicly discoverable is what challenge you chose (dns or tls), and what email you're using. > So yes I personally welcome another CA More CAs generally means more chance that one CA loses a private key or has a vulnerability. Tragically, since browsers trust all CAs for all websites, if the new CA has an issue, people can forge TLS certs for my website even though I have no intention of ever using that new CA. In a very real way, having an excess of CAs is bad for the security of the entire internet. Letting anyone become a trusted CA would be an unequivocal disaster, so clearly more CAs isn't always good. I do think there's a balance, where we should have several viable CAs that we trust to be secure, but not 100s of them, just 10s. We already trust a ton more roots than that, so right now I see a new CA as being detrimental to security overall. That all being said, I'm pretty sure this CA is using an existing trusted root and processes, so since it doesn't require cross-signing in a new root, it's less big of a deal. [0]: http://www.certificate-transparency.org/how-ct-works http://www.certificate-transparency.org/how-ct-works
- abcleb 6y agoDo they sell the private keys to the NSA? Maybe not. It is an effort by many companies and groups to make the web more secure.
- hu3 6y agoLet's imagine they do sell private keys to state actors (which I highly doubt). Would that allow transparent sniffing of traffic encrypted with these certs?
- AgentME 6y agoMost HTTPS connections today negotiate ephemeral keys at the start of the connection, so even if an attacker has the server's private key (which the CA never sees and couldn't sell!), the attacker can't do passive listening attacks on connections using it. The attacker would have to do an active man-in-the-middle attack that rewrites the connection and swaps out the ephemeral keys with keys known to the attacker, which risks detection. If an attacker has the CA's private key, then the attacker can mint new HTTPS certificates. They wouldn't be able to do passive listening attacks on connections, but they could use an active man-in-the-middle attack to swap out the server's certificate in the connection. However, this attack could be detected through Certificate Transparency, and the CA's leaked keys would become untrusted by browsers.
- blibble 6y agothey couldn't sell your private keys to the NSA as they don't have them as they're generated locally on your machine and never leave it they could sell their keys, but impersonations would likely be spotted thanks to certificate transparency
- huhtenberg 6y agoThey don't see the private keys.
- cocoa19 6y agoThey can't sell the keys since they don't have them. NSA could still mount an attack by asking the CA to register NSA's certs as valid, and tamper the victim's network connection. What makes certs secure is our trust in certificate authorities.