6 ms·
Acme, a brief history of one of the protocols which has changed the Internet
- gorgoiler 10mo agoThank you Let’s Encrypt, you changed the world and made it better. Sorry to everyone else who was listening in on the wire. Come back with a warrant, I guess?!
- kuil009 10mo agoThank you for your service
- gerdesj 10mo agoI remember deploying SSL on NetWare in the late 1990s and being given ... something that the US allowed to be exported as a munition! I don't recall the exact details but it was basically buggered - short key length. Long enough to challenge a 80386 Beowulf cluster but no match for whatever was humming away in a very well funded machine room. You could still play with all the other exciting dials and knobs, SANs and so on but in the end it was pretty worthless.
- tiagod 10mo agoA few years ago a client of mine gave me a big-ish APC UPS. I recently got new batteries for it after the outage here in Portugal, and to turn on SSH I had to agree that I was not a terrorist organisation's nor in a country where encryption can not be exported to.
- stavros 10mo agoI'm glad it had that. If you were, say, a member of ISIS and used the UPS, they'd be able to successfully sue you for breach.
- GJim 10mo ago> I had to agree that I was not a terrorist organisation's nor in a country where encryption can not be exported to. Don't forget when flying to the USA, ticking the box to say you won't try to overthrow the government. I'm sure that clause has stopped many an invading army in their tracks.
- kragen 10mo agoRight, 40-bit export-grade SSL.
- wakawaka28 10mo agoHas anyone considered the possibility that a CA such as Let's Encrypt could be compromised or even run entirely by intelligence operatives? Of course, there are many other CAs that could be compromised and making money off of customers on top of that. But who knows... What could defend against this possibility? Multiple signatures on a certificate?
- dbt00 10mo agoA signature on a certificate doesn't allow CA to snoop. They need access to the private key for that, which ACME (and other certificate signing protocols in general) doesn't share with the CA.
- wakawaka28 10mo agoI know that. But presumably, Let's Encrypt could participate in a MITM attack since they can sign another key, so that even the visitor who knows that you use them as a CA can't tell there is a MITM. Checking multiple signatures on the same key could raise the bar for a MITM attack, requiring multiple CA's to participate. I can't be the first person to think of this. I'm not even a web security guy. It might be interesting for ACME to be updated to support signing the same key with multiple CA's. Three sounds like a good number. You ought to be able to trust CA's enough to believe that there won't be 3 of them conspiring against you, but you never really know.
- ryandv 10mo agoThe signing keys used by the Certificate Authority to assert that the client (leaf) certificate is authentic through cryptographic signing differ from the private keys used to secure communication with the host(s) referenced in the x509 CN/SAN fields.
- wakawaka28 10mo agoI know that. At issue is the fact that the signing keys can be used to sign a MITM key. If there were multiple signatures on the original key, it would (or could) be a lot harder to MITM (presumably). Do you trust any CA enough to never be involved in this kind of scandal? Certainly government CA's and corporate CA's MITM people all the time. Edit: I'm gonna be rate limited, but let me just say now that Certificate Transparency sounds interesting. I need to look into that more, but it amounts to a 3rd party certificate verification service. Now, we have to figure out how to connect to that service securely lol... Thanks, you've given me something to go read about.
- stavros 10mo agoLet's Encrypt did more for privacy than any other organization. Before Let's Encrypt, we'd usually deploy TLS certificates, but as somewhat of an afterthought, and leaving HTTP accessible. They were a pain to (very manually) rotate once a year, too. It's hard to overstate just how much LE changed things. They made TLS the default, so much that you didn't have to keep unencrypted HTTP around any more. Kudos.
- kragen 10mo agoI think it was Snowden who made TLS the default. Let's Encrypt did great work, but basically having the NSA's spying made common knowledge (including revealing some things that were worse than we expected, like stealing the traffic between Google's data centers) created a consensus that unencrypted HTTP had to go, despite the objections of people like Roy Fielding.
- Lammy 10mo agoIronically, the inability to cache TLS on the edge of my network makes the Internet more surveillable since everything has to pass through the Room 641As of the world and subjects us all to more network behavior analysis. The TLS-everything world leaks so much more metadata. It's more secure but less private.
- kragen 10mo agoYes, that's a real problem. Probably moving to a content-centric networking or named-data networking system would help with it, while also creating difficulties for censorship, and IPFS and Filecoin seem to be deploying such a thing in real life as an overlay network over the internet.
- globular-toast 10mo agoYou can do it if you're happy to deploy your CA to your network, can't you? Deploying CA certs sucks, though. I wish it was easier.
- 10mo ago
- throw0101a 10mo agoThere are several other certificate provisioning protocols: * https://en.wikipedia.org/wiki/Simple_Certificate_Enrollment_Protocol#See_also https://en.wikipedia.org/wiki/Simple_Certificate_Enrollment_...
- tialaramex 10mo agoSo, the crucial thing ACME has that the other protocols do not is a hole (and some example ways to fill that hole for your purpose, though others are documented in newer RFCs) for the Proof of Control. See, SCEP assumes that Bob trusts Alice to make certificates. Alice uses the SCEP server provided by Bob, but she can make any certificate that Bob allows. If she wants to make a certificate claiming she's the US Department of Education, or Hacker News, or Tesco supermarkets, she can do that. For your private Intranet that's probably fine, Alice is head of Cyber Security, she issues certificate according to local rules, OK. But for the public web we have rules about who we should issue certificates to, and these ultimately boil down to we want to issue certificates only to the people who actually control the name they're getting a certificate for. Historically this had once been extremely hard core (in the mid-1990s when SSL was new) but a race to the bottom ensued and it had become basically "Do you have working email for that domain?" and sometimes not even that. So in parallel with Let's Encrypt, work happened to drag all the trusted certificate issuers to new rules called the "Ten Blessed Methods" which listed (initially ten) ways you could be sure that this subscriber is allowed a certificate for news.ycombinator.com and so if you want to do so you're allowed to issue that certificate. Several ACME kinds of Proof of Control are actually directly reflected in the Ten Blessed Methods, and gradually the manual options have been deprecated and more stuff moves to ACME. e.g. "3.2.2.4.19 Agreed‑Upon Change to Website ‑ ACME" is a specific method which is how your cheesiest "Let's Encrypt in a box" type software tends to work, where we prove we control www.some.example by literally just changing a page on www.some.example in a specific way when requested and that's part of the ACME specification so it can be done automatically without a human in the loop.
- abhashanand1501 10mo agoCan someone explain why letsencrypt certificates have to be 90 days expiry? I know there is automation available, but what is the rationale for 90 days?
- pastel8739 10mo agoI’ve heard one rationale that it is short enough to force you to set up the automation, but don’t know if this was actually a consideration or not
- cortesoft 10mo agoYou can just read their explanation: https://letsencrypt.org/2015/11/09/why-90-days https://letsencrypt.org/2015/11/09/why-90-days Tl;dr is to limit damage from leaked certs and to encourage automation.
- ChrisArchitect 10mo agoRelated recently: Decreasing Certificate Lifetimes to 45 Days https://news.ycombinator.com/item?id=46117126 https://news.ycombinator.com/item?id=46117126
- Lammy 10mo agoIt's so annoying. Eventually we will get to the point that every connection will have its own unique certificate, and so any compromised CA will be able to be “tapped” for a particular target without anybody else being able to compare certs and figure it out.
- figmert 10mo agoOthers have already given your answer, but heads up, LE is lowering the certificate lifetime to 45 days[0]. - [0] https://letsencrypt.org/2025/12/02/from-90-to-45 https://letsencrypt.org/2025/12/02/from-90-to-45
- eimrine 10mo agoThe best computer possible on the Earth today can crack it for 91 days in the best case for him.
- donpdonp 10mo agoit seems like all this infrastructure could be replaced by a DNS TXT record with a public key that browsers could use to check the cert sent from the web server. A web server would load a self-signed cert (or whatever cert they wanted), and put the cert's public key into a DNS record for that hostname. Every visit to a website would need two lookups, one for address and one for key. It puts control back into the hands of the domain owners and eliminates the need for letsencrypt.
- akovaski 10mo agoI'm not sure what that would solve. You would still need some central entity to sign the DNS TXT record, to ensure that the HTTPS client does not use a tampered DNS TXT record.
- tzs 10mo agoIf someone can tamper with your DNS TXT records now they can get a certificate for your domain.
- franga2000 10mo agoNot tamper with the record directly, but MitM it on the way to a target.
- crote 10mo agoThat's what DNSSEC is for.
- franga2000 10mo agoYes, but that's just PKI again, which is what the OP was trying to avoid.
- ishouldbework 10mo agoThat should be prevented by dnssec no?
- eduction 10mo agoI’m sorry, who the heck wrote this and why should I trust them? Very poorly written, also. It’s bizarre. There is a photo at the top, no name, no site title. No about page. Extremely untrustworthy.
- ThomasMidgley 10mo agoNo! It's not bizarre. Scroll down to the footer--> click on "Homepage" Then you will get to his homepage: https://www.brocas.org/ https://www.brocas.org/
- eduction 10mo agoteeny tiny link at the bottom, oy. A site almost totally free of context. No date on the post, even. In the context of how history/journalism of this sort is normally delivered, it is absolutely bizarre. Ironic that someone specializing in security doesn't understand how to make their information trustworthy. But I suppose it's easier and more fun to try and understand machines than other human beings.
- RagnarD 10mo agoIt certainly affected Wile E Coyote.
- a96 10mo agoAnd plan9 users worldwide! (There's dozens of us!)
- dust42 10mo agoTo play the devils advocate: TLS on websites where you are not logged in is the greatest security hogwash of all times. For example the cookies of the NYT: - Store and/or access information on a device 178 vendors - Use limited data to select advertising 111 vendors - Create profiles for personalised advertising 135 vendors - Use profiles to select personalised advertising - Understand audiences through statistics or combinations of data from different sources 92 vendors There is no way to escape any of this unless you spend several hours per week to click through these dialogs and to adjust adblockers. And even if you block all cookies, ever-cookies and fingerprinting, then there are still cloudflare, amazon, gcp and azure who know your cross-site visits. The NSA is no longer listening because there is TLS everywhere? Sure, and the earth is flat.
- Y_Y 10mo agoTLS is cool for stopping your ISP from MiTMing your traffic (usually to insert shitty banner ads or something). Otherwise I find it a scourge, particularly when I want to run https over a private network, but browsers have a shitfit because I didn't publicly announce my internal hosts. There's plenty of traffic that has no need to be encrypted, and where not much privacy is added since the DNS queries are already leaked (as well as what the site operator and their many "partners" can gather). I'm glad you can get free certs from Let's Encrypt, but I hate that https has become mandatory.
- woodruffw 10mo agoThis has nothing to do with TLS’s security model. You still have to trust the site you’re connecting to.
- 1vuio0pswjnm7 10mo ago"There is no way to escape any of this unless you spend several hours per week to click through these dialogs and to adjust adblockers." I read NYT with no cookies, no Javascript and no images. Only the Host, User Agent (googlebot) and Connection headers are sent. TLS forward proxy sends requests over internet, not browser. No SNI. No meaningful "fingerprint" for advertising This only requires accessing a single IP address used by NYT. No "vendors" TLS is monitored on the network I own. By me I inspect all TLS traffic. Otherwise connection fails
- dorianniemiec 10mo agoThis protocol definitely made securing the web easier. Thanks to it, I don't need to renew certificates manually (it's now done automatically), which can be tedious...
- 1vuio0pswjnm7 10mo ago"The challenge is based on device attestation and what’s new in this case is the arrival of a third party, the attestation server."