3 ms·
The older I get the more skeptical I get to free services that run on others servers. They have a bunch of expenses and you are getting it for free. You are not
by o_m 1y ago
The older I get the more skeptical I get to free services that run on others servers. They have a bunch of expenses and you are getting it for free. You are not the customer. I rather pay for a service than gamble on some free service that might be shut down at any time, or that might have malicious intents.
- jraph 1y agoWith you in general, but in this specific case, the whole thing seems healthy: - Many companies (including competitors) are sponsoring LE, so the funding should be quite robust - These companies are probably winning from the web being more secure, so the incentives are aligned with you (contrary to say, a company that offers something free but want to sink you under ads) - the vendor lock-in is very weak. The day LE goes awry, you can move to another CA pretty painlessly There are CAs supporting ACME that provide paid services as well.
- trenchpilgrim 1y agoThere are paid ACME services - basically LE with paid support.
- znpy 1y agoYeah, one of those is https://zerossl.com/ https://zerossl.com/
- aitchnyu 1y agoWhats a LetsEncrypt competitor which has convenient automated renewal?
- trenchpilgrim 1y agoAny that support ACME. Most of the big SSL companies do nowadays.
- patrakov 1y agoZeroSSL - they provide Sectigo certificates under the hood. Works well with Dehydrated.
- cpach 1y agoGoogle Cloud
- PhilippGille 1y agoLet's Encrypt is run by a nonprofit organization [1], funded by corporate and individual sponsors (like Google and AWS, but also the EFF and Mozilla) [2]. That doesn't guarantee they don't have malicious intents, but it's different from a for-profit company that tries to make money with you. [1] https://www.abetterinternet.org/about/ https://www.abetterinternet.org/about/ [2] https://www.abetterinternet.org/sponsors/ https://www.abetterinternet.org/sponsors/
- IcePic 1y agoI think for certs, you are not better of paying $5 for the cert, than paying nothing to get an LE cert. It is already "subsidized" into cheapness, and the $5 company will bug you with ads for EV certs and whatnot in order to make a profit off you somehow since you are now a customer. What I think LE did was to gather the required bag of money that any cert issuer needs to pony up to get the infra up and validated, and then skipped the $5 part and just run on donations. So while LE might stop tomorrow, you don't have any good guarantees that the $5 cert company will last longer if their sidebusiness goes under, and if you go to a $100 cert company, you are just getting scammed from some company who soon will realize that most certs are being given away and that they can't prove why their $100 certs are "better" in any meaningful way so they will also be at risk of going under. In all these cases, you get to use your cert for whatever validity period you had, and then rush over to the next issuer, whoever that is left when the pay-for-certs business tanks. As opposed to cars or whatever, you can't really put more "quality math" into the certs so they last longer, the CAs have limits on how long they are allowed to last, so no more 10-year certs for public services anyhow. You might aswell get the cheapest of the ones that are still valid and useful (ie, exists in browser CA lists) and LE is one of those. Might be more (zerossl?) but same argument would hold for those. The CA list is curated by the browser teams lots better than me or you shopping around websites that make weird claims on why their certs are worth paying $100 for.