4 ms·
In all the excitement (I too think that they did massive strides in usability of https to the masses), nobody mentions of systems-level consequences of a single
by ay 4y ago
In all the excitement (I too think that they did massive strides in usability of https to the masses), nobody mentions of systems-level consequences of a single entity holding the keys to 300000000 servers on the internet. They’re now in a “don’t be evil” phase. But the people move on, change, etc. And the companies get sold, rogue, bankrupt…
I realize an org itself won’t fancy ponder its inevitable deviation from today’s course at some point in the future, but the netizens probably should…
(Sorry for sounding gloomy. :)
- wtetzner 4y agoJust curious what you think the consequences could be? Worst case scenario people would need to find a new CA the next time they need a certificate, right?
- acdha 4y agoI think the worst-case would be a mistake/malice issuing revocations for all of those certificates — that'd take out a ton of different sites and there'd be plenty of chaos around cleaning that up. For example, I note that stackoverflow.com, httpd.apache.org, and nginx.org all use LE certificates which would mean a fair number of people would struggle to install a replacement.
- Dylan16807 4y agoIn practice I think that gets a few through, then the mozilla and google servers that push revocation lists start to overload and the admins notice what's going on and shut things down.
- acdha 4y agoOh, sure but if we’re talking worst-case we’ll assume that the server infrastructure is bulletproof and the admins are all distracted by (maybe Musk just tweeted again).
- Dylan16807 4y agoIf we're assuming worst case about multiple separate companies then we might as well posit the power grid goes down.
- walrus01 4y agothey don't "hold the keys to the servers" - I believe you have a fundamental misunderstanding of how an X509 SSL PKI works. The people in possession of the private keys generate the cert signing request on their local machine. The CSR is then sent to Letsencrypt. The private keys never leave the system requesting the key signature. If you mean is it dangerous for one organization to have a root CA that if it went entirely rogue could theoretically be used to MITM peoples' traffic, that is definitely a concern, and why a process exists for removing a root CA from the mozilla, chrome, microsoft etc root CA trust stores.
- Dylan16807 4y agoCould you be more specific about "holding the keys"? Sure it's annoying to change to a different service, but they don't have access to any server secrets and all their certificates are logged.
- Moru 4y agoNot the GP but some guesses: If they disappear or change something, it will effectively shut down a lot of sites that does not have access to someone knowing how to update to a new cert after three months. Sure, the page will work but most browsers will block the users to get to it or require them to click things with scary messages on them. Holding the key also means they start your engine for you.