4 ms·
Is there an actual issue with widespread cert theft? That seems like the primary valid reason to do this, not forcing automation.
by _bin_ 1y ago
Is there an actual issue with widespread cert theft? That seems like the primary valid reason to do this, not forcing automation.
- trothamel 1y agoI suspect it's to limit how long a malicious or compromised CA can impact security.
- rat9988 1y agoI think op is asking has there been many real case scenarios in practice that pushed for this change?
- hedora 1y agoEquivalently, it also maximizes the number of sites impacted when a CA is compromised. It also lowers the amount of time it’d take for a top-down change to compromise all outstanding certificates. (Which would seen paranoid if this wasn’t 2025.)
- lokar 1y agoMostly this. Today of a big CA is caught breaking the rules, actually enforcing repairs (eg prompt revocation ) is a hard pill to swallow.
- chromanoid 1y agoI guess the main reason behind this move is platform capitalism. It's an easy way to cut off grassroots internet.
- gjsman-1000 1y agoIf that were true, we would not have Let's Encrypt and tools which can give us certificates in 30 seconds flat once we prove ownership. The real reason was Snowden. The jump in HTTPS adoption after the Snowden leaks was a virtual explosion; and set HTTPS as the standard for all new services. From there, it was just the rollout. (https://www.eff.org/deeplinks/2023/05/10-years-after-snowden-some-things-are-better-some-were-still-fighting https://www.eff.org/deeplinks/2023/05/10-years-after-snowden...) (Edit because I'm posting too fast, for the reply): > How do you enjoy being dependent on a 3rd party (even a well intentioned one) for being on the internet? Everyone is reliant on a 3rd party for the internet. It's called your ISP. They also take complaints and will shut you down if they don't like what you're doing. If you are using an online VPS, you have a second 3rd party, which also takes complaints, can see everything you do, and will also shut you down if they don't like what you're doing; and they have to, because they have an ISP to keep happy themselves. Networks integrating with 3rd party networks is literally the definition of the internet.
- nottorp 1y agoHow do you enjoy being dependent on a 3rd party (even a well intentioned one) for being on the internet? Let's Encrypt... Cloudflare... useful services right? Or just another barrier to entry because you need to set up and maintain them?
- icedchai 1y agoYou are always dependent on a 3rd party to some extent: DNS registration, upstream ISP(s), cloud / hosting providers, etc.
- chromanoid 1y agoI dunno. Self-hosting w/o automation was feasible. Now you have to automate. It will lead to a huge amount of link rot or at least something very similar. There will be solutions but setting up a page e2e gets more and more complicated. In the end you want a service provider who takes care of it. Maybe not the worst thing, but what kind of security issues are we talking about? There is still certificate revocation...
- icedchai 1y agoHave you tried caddy? Each TLS protected site winds up being literally a couple lines in a config file. Renewals are automatic. Unless you have a network / DNS problem, it is set and forget. It is far simpler than dealing with manual cert renewals, downloading the certificates, restarting your web server (or forgetting to...)
- jack0813 1y agoThere are very convenient tools to do https easily these days, e.g. Caddy. You can use it to reverse proxy any http server and it will do the cert stuff for you automatically.
- chromanoid 1y agoOfc, but you have to be quite techsavy to know this and to set this up. It's also cumbersome in many low-tech situations. There is certificate revocation, I would really like to see the threat model here. I am not even sure if automation helps or just shifts the threat vector to certificate issuing.
- bshacklett 1y agoHow does this cut off the grassroots internet?
- chromanoid 1y agoIt makes end to end responsibility more cumbersome. There were days people just stored MS Frontpage output on their home server.
- icedchai 1y agoMany folks switched to Lets Encrypt ages ago. Certificates are way easier to acquire now than they were in "Frontpage' days. I remember paying 100's of dollars and sending a fax for "verification."
- chromanoid 1y agoI agree, but I think the pendulum just went too far on the tradeoff scale.
- whs 1y agoDo they offer any long term commitment for the API though. I remembered that they were blocking old cert manager clients that were hammering their server. You can't automate that (as it could be unsafe, like Solarwinds) and they didn't give one year window to do it manually either.
- icedchai 1y agoYou do have a point. I still feel that upgrading your client is less work than manual cert renewals.
- ezfe 1y agoI've done the work to set up, by hand, a self-hosted Linux server that uses an auto-renewing Let's Encrypt cert and it was totally fine. Just read some documentation.
- cryptonym 1y agoLet's Encrypt dropped support for OCSP. CRL doesn't scale well. Short lived certificate probably are a way to avoid certificate revocation quirks.
- Ajedi32 1y agoIt's a real shame. OCSP with Must-Staple seemed like the perfect solution to this, it just never got widespread support. I suppose technically you can get approximately the same thing with 24-hour certificate expiry times. Maybe that's where this is ultimately heading. But there are issues with that design too. For example, it seems a little at odds with the idea of Certificate Transparency logs having a 24-hour merge delay.
- lokar 1y agoThe log is not really for real time use. It’s to catch CA non-compliance.
- NoahZuniga 1y agoAlso certificate transparency is moving to a new standard (sunlight CT) that has immediate merges. Google requires maximum merge delay to be 1 minute or less, but they've said on google groups that they expect merges to be way faster.
- dboreham 1y agoI think it's more about revocation not working in practice. So the only solution is a short TTL.