What if Letsencrypt gets bought by Google / Microsoft and the free lunch is over? The end of the free web as we know it... ?
What if Letsencrypt gets bought by Google / Microsoft and the free lunch is over? The end of the free web as we know it... ?
After all the CA system is effectively decentralized.
A $0 incentive, to be specific.
Even for Let's Encrypt it took 3 years before they were comfortable to abandon the IdenTrust cross signed certificate, and they won't even do it until July 2020, so a whole 5 years.
That's from a very popular NPO supported by many corporation.
And the protocol to talk to LetEncrypt is open, if LetEncrypt turned evil, you could go to other providers without updating your overall process.
https://en.m.wikipedia.org/wiki/Automated_Certificate_Manage...
Anyway I'm not arguing that it would be impossible to create an LE2 but it would not be that simple. Especially if the buyer is someone already in the certificates business that wants to destroy the "free-for-all" concept.
If LE is compromised a few times and some fraudulent facebook.com or google.com certs leak out, how long before Firefox/Chrome/Edge blacklist their root cert like they did with Symantec[1], and end up breaking half the internet?
I understand that ACME is an open standard, but can someone point me to an alternative ACME provider that isn't "please call us for a quote" enterprise-grade?
[1]: https://blog.mozilla.org/security/2018/03/12/distrust-symant...
> There’s an inherent flaw in how Public Key Infrastructure (PKI) operates today: any CA is able to issue certificates for any name without having to seek approval from the domain name owner. It seems incredible that this system, which has been in use for about 20 years now, essentially relies on everyone—hundreds of entities and thousands of people—doing the right thing.
My hope is that in time we will move to something like DANE[1].
[1]: <https://en.wikipedia.org/wiki/DNS-based_Authentication_of_Na...
Why wouldn’t they continue to pay? Hint: Presumably the sponsors feel that they get something more than only goodwill for their donations.
7x Platinum $350k/y = 2,450M
2x Gold $150k/y = 300k
73x Silver $40k/y (vary depending on # of employees) = 2,920M
In total, LE receives over $5.5M a year. I think they are covered
In 2019 we spent $3.35M in cash (we came in a little under our projected budget of $3.6M). We raised $3.82M in cash between sponsors, grants, and individual giving.
The philanthropy-based funding model, coupled with the fact that this is now load-bearing Internet infrastructure, still makes me quite nervous, but I'm glad that you're able to sock away ~$500k for a rainy day.
Fast forward a few years, ICANN v2.0
But setting up a new CA, while expensive and time consuming, is very doable. If Let's Encrypt somehow became as corrupt as ICANN, there'd be incentive for some organization to create an alternative.
In the meantime, it would be nice for letsencrypt to pledge not to take big donations from corporates.
Certificates are pain in the arse and it depresses me that we still don't have a way to deal with compromised private keys.
You mean the people who actually benefit financially from the service? Look, I get the sentiment but this is a case where the incentives are remarkably aligned. Companies that derive real business value from the service foot the bill while the rest of the world gets free certs.