|
|
Log in / Subscribe / Register

Let's Encrypt

Let's Encrypt

Posted Mar 8, 2016 7:04 UTC (Tue) by jezuch (subscriber, #52988)
In reply to: Let's Encrypt by tialaramex
Parent article: TLS certificate management on Android

> Turns out if you constantly screw up it's way easier to just not tell anybody than to investigate why you keep screwing up. Huh.

Huh indeed. There are some industries where safety is so critical that they voluntarily adopted disclusure policies stating that if you disclose your failures, nobody wll blame you for them. Aviation industry is one of those, I think. Turns out that this makes everyone safer and, notably, it does *not* reduce public trust in the industry. Quite the contrary in fact. Will the CAs see the light eventually? Who knows?...


to post comments

Let's Encrypt

Posted Mar 9, 2016 16:20 UTC (Wed) by tialaramex (subscriber, #21167) [Link]

For the CAs the situation with web browsers is a bit weird. I wrote a long thing here originally but here's the short version:

CAs existed before the World Wide Web, and when SSL was invented and they were given a role on the Web they probably expected to outlive it. So CA roots aren't, as we might think of them today, the root of a hierarchy filled entirely with stuff about web sites. Instead along with the millions of web sites are VISA payment terminals, Exchange mail servers, Government tax IDs, Pay-per-view movie systems for Cable TV, and so on. Today it seems crazy to put all this stuff in one hierarchy, but that situation sneaked up on them and so far we're stuck with it, mostly with negative consequences.

I think we're at a turning point right about now, for a number of reasons which I'll list below, which means we might see some hard choices actually made and stop kicking some of the security cans down the road.

* The trust / don't trust / kinda-sorta-trust metrics (and less importantly UI) in browsers have become more sophisticated, offering a middle ground where you can threaten to mark a CA's certificates as less trusted than its competitors without causing a tidal wave of user dissatisfaction. Google have already done this for EV for example. If your CA doesn't obey Google's extra rules for EV your EV certs still work as SSL certs, but they don't give the EV "green bar" effect in Chrome.

* Sunlight. CA/Browser forum was originally a darkened room affair. Almost all business now (since mid-2012) takes place in public, and anything which is done privately has to be ratified in public, giving anybody who'd rather it hadn't happened in the dark an opportunity to up-end the can of worms and force it to be re-examined in the light.

* Let's Encrypt. Previously the for-profit CAs made up such an overwhelming majority of all certificates issued that if they stood together the browser vendors had no option but to put up with whatever they offered. But since late-2015 there's a non-profit that could take up a lot of the slack overnight. Abolishing for-profit CAs isn't on the roadmap, but for-profit CAs can no longer just insist it's their way or the highway.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds