Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Half the web didn't rely on Symantec for free certificates. They do rely on LE.


If LE is distrusted, we all stop using TLS and go back to letting the NSA read everything. LE is the only reason HTTPS is now ubiquitous.


Isn't that a really, really juicy target though?


LetsEncrypt doesn't see your private key when you obtain the certificate. So no, it's not _really_ a juicy target.


On the other hand, who's gong to notice a LE issued cert that they did not request in the certificate transparency logs?


The ones who monitor their domains in the CT log.

(Mom-and-pop-stores probably won’t. Other orgs might.)


Why not just stop using Chrome and start using any of the Chrome-based alternatives in instead?


Are you talking about as a user or a website operator?


Neither, I meant if enough people panic and stop using chrome, website operators need not worry much. Safari is default on macs, and Edge is default on windows, both can render any website that can't be accessed in Chrome, so it'll make Chrome the browser that can't open half of the websites, instead of half of the websites out there suddenly being incompatible with chrome. The power of numbers is on LE's side.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: