Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

They aren't the only no-cost distributor, their downtime doesn't really matter so long as it's less than a month long.

What exactly is the issue with centralization here?



How would Netlify feel about not being able to issue or renew any certs for any sites for a month? Plenty of platforms rely on LE exclusively for one-click/automatic HTTPS for their customers sites.


Let's Encrypt isn't the only provider supporting ACME either. Sectigo (under the ZeroSSL name) is a notable alternative.


The thing is that we're not talking downtime here, but rather something in the CA compromised, which would mean that pretty much ANY website could be impersonated, as the attacker could issue a Let's Encrypt CA valid certificate for it. That is mitigated by invalidating this CA, but that also invalidates all legit certificates previously issued by them. So they need to reissue them all


Let's Encrypt publishes Certificate Transparency logs: https://letsencrypt.org/docs/ct-logs/

You can both block certs that do not appear in the logs, and decide which certs not to trust ("everything after Friday the 13th at midnight is not trusted"), once you know the date/time of the intrusion.


Chrome already blocks certs not appearing in CT logs, at least if it was issued in 2018 or newer.


hmm, the logs are valid point. what scenario are we addressing here then?

but the issuance time isn't relevant, they can easily backdate the cert


> They aren't the only no-cost distributor

I couldn't name a second, which means they're probably not getting a huge %.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: