4 ms·
Cool. But what do the HSMs, auditing, etc, etc, etc that the BRs (https://cabforum.org/wp-content/uploads/CA-Browser-Forum-BR-v2.0.0.pdf https://cabforum.org/wp
by ehPReth 3y ago
Cool. But what do the HSMs, auditing, etc, etc, etc that the BRs (https://cabforum.org/wp-content/uploads/CA-Browser-Forum-BR-v2.0.0.pdf https://cabforum.org/wp-content/uploads/CA-Browser-Forum-BR-...) and root store policies require cost on top of “just some bytes”?
FreeFreeFreeCerts (https://bugzilla.mozilla.org/show_bug.cgi?id=233458 https://bugzilla.mozilla.org/show_bug.cgi?id=233458) or Honest Achmed’s certificate authority (https://bugzilla.mozilla.org/show_bug.cgi?id=647959 https://bugzilla.mozilla.org/show_bug.cgi?id=647959) won’t make it in today’s world, nor yesterday’s.
Let’s Encrypt’s financials are public and they aren’t running it off a singular Raspberry PI, nor anything like it - because they can’t; nor would it responsible to, at least on, say, a HSM or key seperation level.
Not to say, though, that traditional CAs aren’t rent seeking bloated greedy pieces of shit - because they absolutely are. I’m happy Let’s Encrypt found the funding and will (and the all important cross-sign) to take off and curb stomp the incumbent CAs around a bit. I still cringe every time I see an OV certificate in the wild.