10 ms·
A Year-End Letter from our Executive Director
- personjerry 4y agoI love them. I'm not really sure how SSL works or what it is (and frankly I don't care to know the details) but with 2 commands I can get that magical lock on any website. I'm glad they're doing well. Thank you!
- kache_ 4y agoI'm not sure that's a good thing
- barbazoo 4y agoWhat's a downside of that?
- otachack 4y agoAs someone that supports Let's Encrypt's efforts and playing devil's advocate, I imagine a downside is that the bar is lowered and nefarious websites can easily get SSL-equipped channels compared to the high paywall of prior.
- the_optimist 4y agoWhat is the downside of this?
- progmetaldev 4y agoMy guess is a misunderstanding of how easy it is to get a credit card to make a payment. This hasn't gotten any easier, so there truly is no downside at this point, unless people automatically think a SSL means a site is trustworthy. I think that's just education, and is likely to come into public consciousness the longer secure sites are pushed as the default.
- CodesInChaos 4y agoA plain domain validated certificate cost like $10 for a year or two. So roughly the same cost as the domain name. Hardly a "high paywall".
- HideousKojima 4y agoIt meant a paper trail via CC payments (though fraudsters were likely to use stolen CCs, and they probably needed a CC to buy the domain name in the first place). But yeah it's basically not fundamentally different.
- kelnos 4y agoDon't most domains cost $5 or less? I think it's pretty outrageous to have to spend 2x (or more) of the domain name cost to secure connections to it.
- manuelmoreale 4y agoNot sure where you found that figure but most domains definitely don’t cost 5 or less. Most domains are 10+ in my experience.
- lxgr 4y agoCommercial CAs verify exactly two things: Administrative control over a domain name and a working credit card number. Let’s Encrypt only gets rid of the latter, and given that fraudsters able to spoof the former can probably spare the $10 for the latter, I‘d argue that this is a good thing.
- marcosdumay 4y agoBefore Let's Encrypt there were all kinds of bullshit CAs that would distribute secure sites "seals", and lie all over the internet on how those meant anything. All of that noise is gone now. That makes the internet much safer.
- ipaddr 4y agoAn Ex-facebook ml engineer who doesn't know what ssl is and takes pride in not having to learn it? Not sure it's a downside/upside thing. It might shed light on the types of people who get hired at facebook.
- kevinh 4y agoIt's perfectly reasonable for someone to be into programming and not want to have to care about the details of setting up a networking stack.
- bogwog 4y agoOk I get not wanting to pick on the guy, but is that really reasonable? Engineering is about solving problems by designing/implementing systems. The more you know about the system(s) you're working with, the better the solutions you can build. Even if you're "just" working at a high level and maximally specialized to a single niche, not knowing how the underlying parts work will really limit you. Pick the brain of any accomplished engineer, and you'll quickly see that the technical knowledge they use to write code on a day to day basis is only the tip of the iceberg. It's not reasonable to expect everyone to know everything all the time, but I don't agree people should be aspiring to just know the bare minimum either. Mediocrity is like gravity: if you don't (at least occasionally) aim higher, your trajectory will be lower than you want.
- TillE 4y agoRight obviously very few people will be deep experts on the nitty gritty details of any particular thing, but it's weird to work with computers and not have a broad high-level understanding of something as crucial as TLS and PKI.
- ipaddr 4y agoNot understanding something is to be expected but being proud you don't have to goes against the core of what a programmer is.. curious.
- pedja 4y agoDownside existed before Let's Encrypt, it just got amplified with it. General public does not differentiate between the SSL certificate validation level. Let's Encrypt provides domain validation certificates, which only validates that one owns the domain in question. There is another level - Organization Validation SSL certificates, which involves manual checking that this is the legal entity it claims to be. I would expect the financial institutions to use this kind of certificates to avoid phishing, but sadly I've seen some of them use Let's Encrypt.
- Thiez 4y agoBrowsers don't differentiate between the SSL certificate validation level. Because it has been shown that the higher validation levels aren't actually significantly more secure, so the distinction is pointless.
- maxpro 4y agoI don't think this is an issue with LE or the implementation. Maybe we need different policies for such organizations, but this is for sure not a LE issue
- NavinF 4y agoOV certs are pointless and that's why nobody uses them. Anyone can pay $30 to register a business with the same name in a different state.
- personjerry 4y agoIt saves me from the implementation details, this way I don't need to wear another engineer/sysadmin hat. I think the website content is more important than the SSL implementation!
- ethbr0 4y agoIndeed! It's how security should work, and should be the default dual-goal of any piece of security software: provide as much security as possible to as many people as possible.
- doublerabbit 4y ago
- Thiez 4y agoI should hope HN hashes our passwords, instead of encrypting them. And for encrypted data I would expect them to use symmetric key encryption, rather than certificates with RSA or another form of public key cryptography. Your post contains some very basic misconceptions. This is going to sound harsh, but I would recommend not putting too much stock in your own opinions on security, and instead to trust the experts.
- doublerabbit 4y agoNot harsh at all. I understand I am no security expert, bores the heck out of me. Sadly, you shouldn't trust the "experts" to be if that's LetsEncrypt. No one can be trusted apart from yourself when implementing security. If LE is ran with the following companies, "Electronic Frontier Foundation; Mozilla Foundation; University of Michigan; Akamai Technologies; Cisco Systems" What makes them all trade worthy, especially when they're all American? Especially after the whole Richard Stallman. Mozilla, maybe because they were netscape. I have more than enough experience working within security to know that. I've seen SysOps leak DB's, Passwords in plaintext.. and I've seen it from the age of where such didn't exist to where companies are now installing X security appliances to safe guard there networks. I'm not newb, from 2004 to now, counted 15 years of System and Network engineer experience. Fair from experienced but well seasoned. Why isn't HackerNews using LetsEncrypt, Google, Netflix, Amazon, if promoted as a great thing. Is what I want to know.
- loloquwowndueo 4y agoWow remind me what your web site is so I never get anywhere near it.
- vbezhenar 4y ago
- jjulius 4y ago>Why letsencrypt director writes about nvme driver? Why people can't focus on one specific thing. It's literally a director's job to focus on more than one specific thing.
- mikeyouse 4y agoAnd Josh is the ED of the Internet Security Research Group, of which Lets Encrypt is just one product/service. As mentioned in his letter, they also run and support Prossimo (https://www.memorysafety.org https://www.memorysafety.org) -- so the Rust drivers and memory safe kernel are directly in their area of interest and are something they're investing in and supporting.
- jiggawatts 4y ago> some shady websites What are you talking about? A clever design aspect of Let’s Encrypt is the deliberately short expiry. That forces administrators to automate the issuance and renewal process. Not to mention that you’re not supposed to “download” the private key! The whole idea of PKI is to generate the private key locally and then have a CA sign only the public part. If you’re doing anything else you’ve undermined the entire purpose of the thing. I mean you are literally -- not figuratively -- handing your secrets over to Russian hackers and complaining about the people politely showing you how to make your systems safe. Learn about the ACME protocol and certificate automation: https://letsencrypt.org/docs/client-options/ https://letsencrypt.org/docs/client-options/
- vbezhenar 4y agoI know better what am I supposed to do. Type "download letsencrypt certificate online" in the Google and you'll find out what I'm talking about. You can think of forcing administrators all the day while Internet is full of expired letsencrypt websites that I regularly stumble upon. The world does not work like that. Letsencrypt should serve its users, not force them onto anything. If I think that I should generate key online, provide me this service with sane implementation on a safe website. If you won't, I'll download it from the "Russian hackers". ACME is awesome, but it's not always suitable, sometimes I want to get certificate manually and that's OK. I remember chinese websites issuing 3-year certificates. Wosign or something like that. That was the best experience I've ever had.
- andirk 4y agoBefore Letsencrypt, SSL signing was cumbersome and downright scary sometimes. With cPanel + letsencrypt (or whatever their default Auto SSL provider is [0]), it's a few clicks and done. If there's a downside, I have never seen nor heard of it. Side note: I was expecting this CEO letter to end with layoffs. [0] https://docs.cpanel.net/whm/ssl-tls/manage-autossl/ https://docs.cpanel.net/whm/ssl-tls/manage-autossl/
- jmathai 4y agoI used to configure all of this manually on Apache following crappy instructions from online certificate providers. Copying .pem, .key, .csr files PRAYING Apache would start without complaining. I'm still old school but can set this up all using the letsencrypt command line utilities that configure everything for me. Oh, and whatever the hell GoDaddy's intermediate chain certificate was.
- wankle 4y agoI always had issues with GoDaddy and had to get on a call with their support but at least they played cool old jazz in the wait queue. LE works great.
- andirk 4y agoThose instructions were always so clunky as was the process. Re: Godaddy, I was using their "EV" (Extended Validation) cert which added a company name indicator in the address bar. I then learned that it's unwise to bring up security when someone isn't thinking about it because it puts them on undue alert. A couple years ago the browsers have done away with that EV badge altogether.
- mynameisvlad 4y agoBrowsers did away with it because it says nothing about the actual security status of a page compared to any other SSL page. All it means is that the organization was verified. Customers were seeing the prominent green text and assuming a heightened level of security and trust. Legal names are also not unique, and this loophole could be used for phishing. Instead, what browsers did was promote SSL as a default (regardless of certificate type) and point out HTTP connections as insecure.
- candiddevmike 4y agoI don't understand why Let's Encrypt is OK but DANE isn't. They both use DNS to authenticate certificates, why not cut out the middleman?
- bawolff 4y agoThey use DNS in very different ways. I don't think they are directly comparable. Sometimes some things catch on and others don't.
- NavinF 4y agoNot much has changed since "Why not DANE in browsers (17 Jan 2015)": https://www.imperialviolet.org/2015/01/17/notdane.html https://www.imperialviolet.org/2015/01/17/notdane.html
- rakoo 4y agoLet's encryt is a protocol, ACME, that can be implemented by any number of independent actors. Yes, it takes time, energy and money, but it is doable. And if it is possible to switch away from a bad actor, there is more incentive to not being a bad actor. DANE relies on the DNS being end-to-end secure, which all boils down to the root being secure. It's extremely centralized in a way that is just diammetrally opposed to how the Internet is designed.
- tptacek 4y agoThere are a lot of reasons. The real reason DANE isn't deployed is that DNSSEC isn't deployed, and DNSSEC isn't deployed because (1) it's not an operational security win for most companies, and (2) it has an earned reputation for causing nightmare outages. That's why nothing uses DANE: because there are no DANE records to look up, and the most important (high-traffic, whatever) sites on the Internet disproportionately eschew DNSSEC. The other big reason DANE isn't deployed, even as a trial balloon in browsers for the rare cases where DANE records actually exist, is that the Internet is full of middleboxes (caches and rando routers) that block DNSSEC, or really any atypical DNS response at all. The browsers tried rolling out DANE, and it caused reliability problems. DANE advocates tried to work around this with stapled DANE records as a TLS extension, which failed due to security concerns, and is now a dead letter. (There is an obvious chicken-egg thing happening between these first two reasons that strongly suggests this will remain a stable equilibrium.) The best reason DANE isn't deployed is that it vests keying authority with organizations that can't be revoked. World governments control most of the most important TLDs, and most of those have demonstrated repeatedly that they will alter the DNS for their own policy goals. Google can dis-trust CAs that act up, and in fact they did that a few years ago for one of the largest CAs in the world. Google can't dis-trust .COM. Mozilla can realistically threaten to dis-trust any CA that doesn't implement Certificate Transparency, but nobody can threaten a TLD owner if they don't enroll in a (fictitious) DANE Transparency program --- part of the reason there is no such program.
- nektro 4y agoLet's Encrypt is behind that annoying memorysafety.org website? how unfortunate. otherwise great news that LE is still doing well as an org
- tux3 4y agoLet's Encrypt has had such a positive impact, I think I'll start donating to them instead of Wikipedia. They're a lot more subtle with their calls to donate, but they seem to deliver a lot of good things to a lot of users, with a much smaller budget. I'm just really grateful for the service, and glad to see the Prossimo work continuing as well. (On a tangential note, I suspect the way Let's Encrypt makes me feel is the thing that people wish Mozilla still had whenever there is a Firefox thread that turns bitter. Like a breathe of fresh air on a cynical internet.)
- Gigachad 4y agoThey seem a whole lot less bloated than Wikipedia as well. Given that something around 3% of donations to Wikipedia actually go to the website, they'll be fine with less donations despite what their nag popups suggest.
- cube00 4y agoI stopped donating to Wikipedia after the size of their cash reserves were revealed. I get that's designed to protect themselves for the long term and it sounds like they've made it so they don't need my money for now, at least not at the expense of other projects that don't have such cash reserves like Let's Encrypt.
- 0goel0 4y ago> stopped donating to Wikipedia after the size of their cash reserves were revealed. After I read your comment, I thought they had 10x annual expenses or something but really they have 18 months of runway. That's not that long IMO. https://www.washingtonpost.com/news/the-intersect/wp/2015/12/02/wikipedia-has-a-ton-of-money-so-why-is-it-begging-you-to-donate-yours/ https://www.washingtonpost.com/news/the-intersect/wp/2015/12...
- Dylan16807 4y agoPersonally, I care about the ratio of cash reserves to what it costs to run wikipedia and directly related sites, and that's well over 10x.
- iuafhiuah 4y agoI am glad it looks like the IETF ACME specification only addresses the HTTP-01 challenge. I really would like to see improvements made to the DNS-01 challenge before it's ratified, namely, let us publish a public key to a TXT record and use the private key to sign the renewal request. Then I can revoke certbot's access to my DNS records and stop hacking the `.well-known` path.
- rainsford 4y agoI'll admit I haven't spent a ton of time thinking through all the implications, but that proposal seems like it comes with some significant security tradeoffs. In particular, you'd lose the ability to prove you control the domain name at the time of certificate renewal. Instead, the key pair approach shows you controlled the DNS records for the domain at some point and your entry has yet to be deleted. From the certificate issuing standpoint, that seems like a much weaker security guarantee. Certbot's access to your DNS records does mean you have to protect those credentials, but the overall requirement seems like a feature rather than a bug.
- comex 4y agoTo be fair, “you controlled the DNS records for the domain at some point and your entry has yet to be deleted” could also describe the HTTP-01 challenge. Admittedly, having the A/AAAA record point to the wrong place is much more likely to be noticed than having a stray TXT record lying around. Perhaps more worrying is the possibility of having a keypair that is legitimately being used to sign certificate requests, but which an attacker also stole a copy of at some point. (Assume that the server owner doesn’t know they were compromised and hence didn’t rotate the key, but the attacker subsequently lost access for some reason.) Such an attacker would likely have also stolen the TLS private key, but that only stays valid for 90 days, whereas for this keypair approach to be useful, the keypair would have to stay valid for a long time or indefinitely…
- kelnos 4y agoDoes it? Under the approach of storing a public key in DNS, certs can be issued long after the person asking for one has lost access to the website, if the pubkey record hasn't been deleted. With http-01, ownership has to be proven every time a new cert is issued. > Such an attacker would likely have also stolen the TLS private key, but that only stays valid for 90 days That doesn't have to be the case; the private key can be valid for as long as someone wants it to be, unrelated to the validation period of the cert that is issued. Yes, it does look like certbot generates a new keypair for every renewal, but in a world where we were putting a pubkey in a DNS record, the private key would certainly have a much longer validity, as otherwise there'd be no point to doing it this way in the first place.
- anderspitman 4y agoWe need someone to pull a Let's Encrypt in the identity space. A nonprofit that provides the convenience of single-click social login without the tracking. All it would need to do is provide a domain that verifies you control an email address, then let's services do OIDC flows to that domain to log you in.
- NavinF 4y agoAren't there too many free services that already do that? LE won on cost, automation, and no upselling
- bugfix-66 4y ago
- orthecreedence 4y agoBonus points if it doesn't use blockchain...
- ay 4y agoIn all the excitement (I too think that they did massive strides in usability of https to the masses), nobody mentions of systems-level consequences of a single entity holding the keys to 300000000 servers on the internet. They’re now in a “don’t be evil” phase. But the people move on, change, etc. And the companies get sold, rogue, bankrupt… I realize an org itself won’t fancy ponder its inevitable deviation from today’s course at some point in the future, but the netizens probably should… (Sorry for sounding gloomy. :)
- wtetzner 4y agoJust curious what you think the consequences could be? Worst case scenario people would need to find a new CA the next time they need a certificate, right?
- acdha 4y agoI think the worst-case would be a mistake/malice issuing revocations for all of those certificates — that'd take out a ton of different sites and there'd be plenty of chaos around cleaning that up. For example, I note that stackoverflow.com, httpd.apache.org, and nginx.org all use LE certificates which would mean a fair number of people would struggle to install a replacement.
- Dylan16807 4y agoIn practice I think that gets a few through, then the mozilla and google servers that push revocation lists start to overload and the admins notice what's going on and shut things down.
- acdha 4y agoOh, sure but if we’re talking worst-case we’ll assume that the server infrastructure is bulletproof and the admins are all distracted by (maybe Musk just tweeted again).
- 4y ago
- ggm 4y agoCan somebody from LE explain why "Rust in the kernel" is a story for LE, rather than for Linux itself? Did LE e.g. do the coding? or help? is this a cross-product activity? LE is a system for bootstrapping CA certification, Rust in the kernel is a generalized memory/systems security & safety coding activity. Not that it isn't good, but "why talk about it in a letsencrypt end of year message" -is this the wider "we" at play, or was there something specific I missed?
- phasmantistes 4y agoIt's because it's not just a Let's Encrypt end-of-year message: it's an ISRG (Internet Security Research Group) end-of-year message. ISRG runs multiple projects, including both Let's Encrypt and Prossimo. Prossimo is all about using memory-safe languages to replace critical memory-unsafe code, and Prossimo funded a significant chunk of the work to get Rust into the Linux kernel.
- ggm 4y agoThanks! good explanation.
- rdl 4y agoOne of the many great things Peter Eckersley started. The Internet is a lot better because of Let's Encrypt.