4 ms·
Agreed! What were we using before Let's Encrypt again? Maybe just plain HTTP
by Aardwolf 10mo ago
Agreed! What were we using before Let's Encrypt again? Maybe just plain HTTP
- bakies 10mo agoSelf signed certs. I wasn't paying.
- Thaxll 10mo agoSome of them were not expensive but it was not convenient at all.
- rew0rk 10mo agoeither you used http, self signed if you did not mind the warning, and i remember there being one company that did offer free certificates that validated, but cant remember the name of it
- deleted 10mo ago[deleted]
- asadotzler 10mo agoSSL/TLS via expensive and hard to work with providers and tooling. Let's Encrypt made it free and easy to maintain.
- ZeroConcerns 10mo agoMostly Verisign, which required faxing forms and eye-watering amounts of money. Then Thawte, which brought down prices to a more manageable US$500 per host or so. Which might seem excessive, but was really peanuts compared to the price of the 'SSL accelerator' SBus card that you also needed to serve more than, like, 2 concurrent HTTPS connections. And you try telling young people that ACME is a walk in the park, and they won't believe you...
- anamexis 10mo agoAnd then sketchy resellers for Verisign/Thawte, which were cheap but invariably had websites that ironically did not inspire confidence in typing in your credit card number.
- dylan604 10mo agoAs GP posited, because of this headache, lots of web traffic was plain ol' HTTP. Let's Encrypt is owed a lot of credit for drastically reducing plain ol' HTTP.
- SirMaster 10mo agoI was using StartCom StartSSL which was offering free 1 year certificates at least for my personal sites.
- 0x0 10mo agoThey were great in the beginning, and then when you issued a few more certs than they liked you were asked to pony up some $$$, and then when you did that and actually "verified" who you were on a personal international phone call, you got a grace, and then issued a few more, they decided they didn't like you so they would randomly reject your renewals close to the expiration date, and then they got bought out by some scummy foreign outfit which apparently caused the entire CA to be de-listed as untrustworthy in all major browsers. Quite the ride. Also, the only website I've ever encountered that actually used the HTML <keygen> tag.
- 1f60c 10mo agoThe pros were using client-side encryption :D