Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

BTW, who really is Let's Encrypt, why should I trust them, why should I trust they won't disappear once plain HTTP is no longer supported by cargo-cult-security-conscious browsers?

It seems to me like providing certificates isn't exactly free, in itself.



Say they disappear, so what? You're left in the exact same situation as before they've appeared, except with some money saved in the meantime.


You must have missed

once plain HTTP is no longer supported by cargo-cult-security-conscious browsers

There already are people talking about such possibility and some even appear to believe it would be a good idea.

Of course what happens then is that without Let's Encrypt you are stuck paying other CAs to have anything published on the Web at all.

<tinfoil hat on>LE is a conspiracy of CAs to phase out unencrypted HTTP and ensure them infinite money stream.

<tinfoil hat off>Even if it isn't, LE will disappear five months after their mission is done because what the heck, why bother.

I just wonder if there is any reason to believe that users of LE are any smarter than kids accepting free candy from pedos? Maybe there are reasons but I just haven't heard them yet.


Ah, I think I'm missing an assumption you're making: that LE is indispensable (or almost) for browsers to deprecate HTTP.

Personally, I think the deprecation (as in, the warning bells and reduced priority, not full blocking) was going to happen anyway, and LE was mostly inconsequential, even if it makes the transition easier.

As for LE being a CA conspiracy, I don't think that makes much sense considering their funders (eg. Mozilla, Google) and those funders relationships with existing CAs (see WoSign, Symantec). But anything's possible.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: