Launching Our Crowdfunding Campaign
letsencrypt.org
letsencrypt.org
- Take the amount you paid for certificates last year
- Divide by any number, let's say 10
- Donate that amount to LetsEncrypt, and continue to get free certificates all year!
I agree with some commenters that it would be great to see LetsEncrypt bolster their revenue with reasonably-priced offerings such as wildcards and EVs. But you can't argue with the progress they've made so far. If there is enough community demand, I'm sure they'll get there.Though their stats page[0] appears to be broken, last I heard they had surpassed 5 million certificates. To meet their current funding goal of $200k for a month, that equates to $0.04 per certificate per month, or $0.48 per certificate per year!
EDIT: Their stats page is back. Looks like they have reached 10 million certificates. So halve the above numbers!
You can't really compare the number of free things you're using to the number of things you'd use if they weren't free.
I'd also like to point out that even if you never get a certificate from us yourself we're still helping to protect you when you browse any of the millions of sites we help to secure.
The startup I perviously worked at paid around USD 2000 for 5 wild card certs from GoDaddy.
if Let's Encrypt charged even 10% of that, it's about $40/cert. Based on your estimate of 10 million certificates issued (and assuming that 90% of the users leave because it's not free)...that's ~1 mil certificates @ $40/cert => $40 mil.
Am I calculating this wrong somehow? (or how it this possible?)
(Also, Let's Encrypt doesn't issue wildcard certificates at all.)
Is this truly needed to cover operations? In other words, when this falls short, are they in danger of going insolvent at some point?
I'd much rather they go some different path to cover the shortfall. Perhaps reasonably priced wildcard and/or EV certs, while leaving regular certs at the "free" price level?
"We decided to run a crowdfunding campaign for a couple of reasons. First, there is a gap between the funds we’ve raised and what we need for next year. Second, we believe individual supporters from our community can come to represent a significant diversification of our annual revenue sources, in addition to corporate sponsorship and grants"
IDK, wildcard certs encourage really bad practices, and I don't see the LE team liking the idea of issuing them.
EV certs means a significant increase in costs to actually go through the processes required (audits, etc) so that browsers will accept them, and then the increased costs of doing due diligence when issuing certs. Unless they want to grow in that direction, it seems like a poor business choice.
Yes, it means they run the risk of going insolvent; despite the fanfare, and the pace at which they have moved themselves into a critical niche on the web, they are still an open source project, and are supported by sponsorships and donations.
I expect that there are some significant players that would invest to keep them around, but it can be hard to continue to making an impact when you subsist off of crumbs.
Anyone who's career depends on FOSS should at least read https://files.puzzling.org/wayback/pay-for-foss/
If I'm running a web application, and want to provide an interface where separate teams sign up and access their version of the app at team-name.your-app.com, what's the alternative? Or is it that this is considered unwise, and I should just put team-name in the URL path instead?
- https://checkout.example.com/
- https://forums.example.com/
Your wildcard certificate for * .example.com covers both domains, and can be shared between both servers. Nice! You've saved a bundle of money on certificates. But there's now a security risk: Say an attacker manages to compromise forums.example.com through some vulnerability in the forum software, and steals the private key for * .example.com. They can now set up their own server hosting checkout.example.com, successfully execute a Man in the Middle attack, and steal sensitive customer data without the end user being any the wiser.Issuing separate certificates prevents this scenario by enforcing a separation of responsibilities. If each server has its own set of keys, then a security compromise on forums.example.com does not spill over to checkout.example.com, because the key used on one server is useless to impersonate the other. Obviously a key compromise at all is a bad situation, but you want to architecture your environment so that a compromise has the least potential to do damage, and that's the basic argument against wildcard certificates.
In other words, a web app with custom subdomains is probably a reasonable use case for wildcart certs, for now.
Any chance LE can make some official statement regarding their operating budget/burn? My strong preference would be to use them but I can't recommend transitioning to someone trying to make up single months of Opex by begging for donations.
Sep 20, 2016
https://letsencrypt.org/2016/09/20/what-it-costs-to-run-lets...
The bulk of our support comes from corporate sponsorship, another component is grants, and the third is individual donations. Individual donations are likely always going to be our smallest source of revenue but it's still an important source to develop.
We'll be around. Go ahead with your rollout, I hope it goes smoothly and that it inspires you to contribute back what you can.
And thats how they get 0.50$ every month(it is a small private, non profit site, otherwise it would be more).
It costs $3m/year to run it (someone already posted this link).
Take a look at the sponsor cost: https://letsencrypt.org/become-a-sponsor/
And their sponsors: https://letsencrypt.org/sponsors/
They already have at least $2.4m from the 10 platinum and gold sponsors. And at least $270k from the 27 silver sponsors. That's the minimum total, and we're already close to the $3m.
Plus it's part of ISRG, which is backed by Akamai, Cisco, Mozilla, EFF, and a few others.
It sounds very unlikely they'll fail to raise the $3m they need any time soon. I think they'll need some kind of other event to occur first before that happens -- like a security breach, or getting removed from the browsers.
Their staff cost about $200k/person, and their total budget for 2017 is 2.9M!
Any useful service costs money to build and keep running. Perhaps easier renewals have led us to forget that efforts to make the internet more secure require a lot of hard work and resources (money). LetsEncrypt doesn't generate income by selling ads. Users ought to consider donating.
Due to technical bug my domain got black listed for a week, and I had to buy a new domain due to the deadline. I couldn't have used QA cert server.
Letsencrypt are one of the good guys. They are fighting the good fight. With the admirable goal of trying to get the web moved entirely over to SSL. It's an uphill battle because we have decades of SSL being a pain in the ass to deploy and maintain. "But certificates are not hard to generate and deploy!" Over 50% of the web disagrees with you.
People have got to start taking this stuff seriously. Everyone should be donating monthly to OpenBSD for OpenSSH which everyone and their grandmother uses in their infrastructure but they take it for granted and don't donate. Which I personally find appalling that it's so widely used and yet supported so very little for such a vital part of everyones infrastructure.
SSL is the same way, it's a vital part of everyones infrastructure and both the OpenBSD folks and lets encrypt should be bankrolled by the tens of millions each year from both individuals and the corporations who use this software on a massive scale. Seriously, Cisco, Juniper, Oracle (yeah I know it was a waste of bits to type that name here), every corporation using SSH should be pouring millions into the OpenBSD foundation and you should all be ashamed and publicly called out for not doing so!
Yes, LE are the good guys, and everyone should be donating mountains of money to them, and the bsd-folks. But that doesn't negate the fact that $200K a month is a crazy amount.
There are literally thousands of people working at SSL companies. 1100 at Comodo alone.
Which is why it is disheartening to me to hear anyone gasp at this request from LE. As you said there are many many companies using SSL that are spending truckloads a month on employee salaries, sending a 10,000 dollar check to LE each month for them should be in their own interest.
We are not holding corporations making millions off fundamental pieces of infrastructure like LE and OpenSSH accountable. These corps should really be ashamed and called out publicly for not donating healthy sums each month to these projects. IMO.
https://en.wikipedia.org/wiki/List_of_highest_funded_crowdfu...
Edit it and remove the /web/20160506180535/ and /web/20160506180535im_/ from the PayPal form at the bottom.
Open it and click the PayPal donate button. (I would just paste the HTML code in this post, but I suspect giving people a PayPal hosted_button_id in an editable HN post would feel kind of sketchy, as opposed to getting it from the Internet Archive.)
I'll also ask to have the PayPal button put back somewhere during the crowdfunding campaign, which would be a lot easier.
Not to mention that currency conversion is a complete ripoff. I avoid PayPal like the plague.
They lock accounts on a whim and require extensive, unnecessary documentation to get your own money back. They recently settled a class-action suit because of this: https://www.accountholdsettlement.com/
They nearly always side with purchasers and reverse charges despite ample evidence supporting the seller.
Also take a page from buffer and release your expenses and revenues.
I'm willing to donate any time I get a cert from you guys and I'm sitting on all this free PayPal money to give you, but can't via indygogo
-A LetsCrypt certificate is ultimately free
BUT
-You must pay X amount of dollars to get one (a fair and low amount)\
-After 30 days, you can cancel/refund your payment
-BUT you still get to keep your certificate...
Probably in something like this, a fairly high percent of people will not bother to pay / are happy to continue to pay. LetsEncrypt certificates are still always free but at least this way human laziness means that LE important work can be sustainable into the future.
Wouldn't it also break the whole automatic side of things?
I get it when it comes to crowd funded products - actually getting the product - but do you really need the overheads of making and shipping (and in some cases handling returns) on physical rewards? Anyone in the know - How much does this eat into the raised funds?
Another comment here mentioned they're likely after corporate donations - I'm guessing they get processed outside of indiegogo?
Plus, some people just won't give without getting. Which is why PBS continues to do donation drives where they give away Rick Steves books (or whatever it is these days).
It's nice to have some sort of recognition to people who give you money, it seems perfectly reasonable to me.
https://www.comodo.com/home/email-security/free-email-certif...
EDIT: A quick google showed me that there are also others that offer S/MIME for free
Also, I'd probably sign up for a small recurring donation if it was possible. Recurring donations could become a significant and reliable source of funding.
Edit: I am not suggesting they start spamming everyone and ask for money. An opt-in email list for topics not strictly related to service would be good.
If you provide an email address to Let’s Encrypt when
you create your account, we’ll automatically send you
expiry notices when your certificate is coming up for
renewal. We send the first notice at 20 days before
your certificate expires, and more notices at 10 days
and 1 day before it expires.P.S. Let's Encrypt rocks! I just donated.
But your CA server won't be able to sign any certificates that will be recognized by Mozilla, Google, Microsoft, etc. It takes time, energy, and expertise to be a CA authority that is trusted by those organizations.
I think that trying to scrimp and save is not worth the relatively small amount of money saved for something like this. We've seen over and over again that so-called "critical" open source projects cannot afford to operate that way.
1) Our software is already open source. That doesn't mean we get the development work that we need when we need it for free. We are constantly working on various features and fixes that need to be deployed weekly if not more often, and usually based on a close working relationship with our operations team. Security fixes need to be produced in hours or less, not when a volunteer contributor gets around to it. Our engineers also spend a lot of time every day digging through hundreds of GB of logs to find or verify service issues.
Keep in mind that our software is deployed by very few people other than us, because in order for our software to be useful you need to have done a massive amount of other (expensive) work to set up the legal, compliance, and technical context.
2) I'm not sure where you get 60k requests per day as a representation of our system load. Between ACME API interactions and OCSP it's many millions.
3) The CA needs to be monitored 24/7. Our infrastructure is necessarily more complicated than your average web API or application, and it's constantly being maintained and improved. Open sourcing doesn't address the issue of having highly qualified and trained staff building and monitoring secure systems.
4) There is a huge amount of tedious compliance and legal work that has to be done in order for us to continue to operate.
5) We operate in a compliance environment (WebTrust/BRs/root program rules). We have a lot of obligations, mostly for good reasons, that make what we're doing very different from "write some code, throw it on GitHub, deploy on a cloud service and be done with it."
2) I thought i saw around 60k certificate requests in statistics on your site.
It is.
> And let other people work on it and just cover 3 people managing this + architecture costs.
Um, Lets Encrypt, in the course of the last year has inadvertently become one of the largest issuers, and has become critical infrastructure for many of it's users who would suddenly have to pay for certificates, assuming they configured LE certs and Strict Transport Security. If LE was only 3 "managers" + cloud infrastructure, it wouldn't be reliable.
> You don't need 2.9 mil per year to process 60k certificate requests a day with system that is practically finished. What else is there to do which open source community could not do it itself?
The service isn't "practically finished", they need to continue to improve the service to reduce costs, improve the operations capabilities of the service as it grows, From LE: Staffing is our dominant cost. We currently have eight full time employees, plus two full time staff that are employed by other entities (Mozilla and EFF). This includes five operations/sysadmin staff, three software developers, one communications and fundraising person, and an executive director.
>Thousands of companies and developers use letsencrypt, a lot of potential man power to help if you ask me. You could easily cut costs 5-6 times. Or am i missing something here?
You are missing alot... this is not an open source project that anyone other than an existing CA can consume and hit the ground running. If any other major CA decided to consume Boulder, and offer it as a service, they could eat LE for lunch, but for anyone else, they need a massive investment in the logistics of becoming a CA.
Over and above that, LE is a team run on a shoestring, and yet they are building out infrastructure that is likely to be highly targeted by a broad range of attackers. Wether it's DoS, folks trying to get mis-issued certs, or a number of other objectives, that they are running and keeping the service up with that few people and that little money is an impressive feat.