5 ms·
I would say that the main problem is not the encryption itself but the certificate that must be issued. It’s sad we can’t just encrypt the communication by set
by anton96 5y ago
I would say that the main problem is not the encryption itself but the certificate that must be issued.
It’s sad we can’t just encrypt the communication by setting up something in the server and that would be it.
- sofixa 5y ago> It’s sad we can’t just encrypt the communication by setting up something in the server and that would be it. You can? With any of Let's Encrypt's clients ( certbot, lego) of web servers that come with an ACME integration ( Caddy, Traefik).
- squiggleblaz 5y agoI think the problem is if you use a self-signed certificate, the web browser tells you this is a grave concern. In order to avoid this issue, ACME requires your web server to communicate with an external service provider to sign the certificate. But now you're dependent on Lets Encrypt being able to access your server! I'm not sure that this is an avoidable problem. If your web browser would accept an unsigned certificate, then it's not really encrypted content. The router could intercept the relevant HTTPS request, connect to the self-signed server on its own accord and pass the data back to the client. All we're achieving there is the use of a few more CPU cycles. Lets Encrypt gives you proof that at some point in the last 90 days, Lets Encrypt's routes, which you trust to be more secure than your own routes, were able to access this server (modulo pedantry). If this information is interesting to you, you need to distinguish between the occasions when you have some alternative means of trust from the majority case. Browser warning pages are an in-your-face but reasonable approach. As a person who has a vague understanding of how PKI works and a relative ability to distinguish "I want to access this site now" from "I have a means of proving that I trust this key", I would appreciate it if I could say I trust this signer or do something like trivially set up an acme signer for my home network.[*] The browser's "permanently stop caring about trust for this site" isn't really one that I enjoy using (even the old fashioned option to "add a temporary exception" was better!), and a lot of software is becoming harder to use without TLS. [*] ed to add: I mean I can, but it's matter of time and energy. I think Windows makes it relatively easy to add a new root key, and on Linux I guess it's a matter of doing all the stuff you do whenever you configure stuff. On Android I have no idea if it's possible or if I just have to trust exactly whoever it is that OnePlus trusts. I've seen tutorials for how to deal with some of this stuff, and I always filed it into the box of things to deal with when I got a round tuit. It's not so much the ability to deal with it, as the fact that it's a fair amount of work, needs to be repeated for several devices, needs to be repeated for new devices, may not be doable for all devices, and it's done so rarely that it's completely impossible to memorise and even if you could something has probably changed in the interim. In short, it's possible, but using HTTP is way easier despite the fact that sometimes you have to override defaults.
- rad_gruchalski 5y ago> I think the problem is if you use a self-signed certificate, the web browser tells you this is a grave concern. In order to avoid this issue, ACME requires your web server to communicate with an external service provider to sign the certificate. But now you're dependent on Lets Encrypt being able to access your server! Not necessarily, you can use lego client with dns01 challenge. This is how I issue certificates for local services running with dnsmasq or hosts file.
- Saris 5y ago>In order to avoid this issue, ACME requires your web server to communicate with an external service provider to sign the certificate. But now you're dependent on Lets Encrypt being able to access your server! Only if you're using the HTTP challenge, the DNS challenge is (IMO at least) much simpler, easier, doesn't require any services open to the internet so can work in a LAN, and can issue wildcard certs too. If you use a webserver like Caddy as well, then your SSL certs are done automatically without you needing to do much of anything at all.
- gravypod 5y agoSuper agree with this comment. Been using Caddy with DNS and it's been amazing.
- squiggleblaz 5y agoThat's true, and instead of verifying that Lets Encrypt can contact your server, they verify that you can control the DNS. It isn't compatible with least privilege though, is it? Either every box that wants to use SSL has to be capable of changing DNS settings, or you need a central box that generates secrets and securely transmits them to the servers. I have domain names which I am authorised to serve content on, but not authorised to manipulate DNS for (but they're all exposed to the internet, so not relevant to the limitation - but probably the reason I overlooked the blindingly obvious solution)