edit: thanks for the replies!
edit: thanks for the replies!
More options are good, Let’s Encrypt is mandatory to ensure good (or non predatory or oligopoly) behavior by other cert providers. It’s a check on their power.
https://letsencrypt.org/about/ https://www.abetterinternet.org/
I'm surprised this model isn't more common as an alternative to licensing.
Would that allow transparent sniffing of traffic encrypted with these certs?
If an attacker has the CA's private key, then the attacker can mint new HTTPS certificates. They wouldn't be able to do passive listening attacks on connections, but they could use an active man-in-the-middle attack to swap out the server's certificate in the connection. However, this attack could be detected through Certificate Transparency, and the CA's leaked keys would become untrusted by browsers.
they could sell their keys, but impersonations would likely be spotted thanks to certificate transparency
NSA could still mount an attack by asking the CA to register NSA's certs as valid, and tamper the victim's network connection. What makes certs secure is our trust in certificate authorities.
“ The world’s most valuable resource is no longer oil, but data.” ~The Economist, May 6, 2017
https://letsencrypt.org/privacy/#we-do-not-sell-your-data-or...
Certificate logs from the certificate transparency project [0] are already public knowledge and shared freely.
The only thing lets encrypt gets in addition to what's in those logs and publicly discoverable is what challenge you chose (dns or tls), and what email you're using.
> So yes I personally welcome another CA
More CAs generally means more chance that one CA loses a private key or has a vulnerability. Tragically, since browsers trust all CAs for all websites, if the new CA has an issue, people can forge TLS certs for my website even though I have no intention of ever using that new CA.
In a very real way, having an excess of CAs is bad for the security of the entire internet. Letting anyone become a trusted CA would be an unequivocal disaster, so clearly more CAs isn't always good.
I do think there's a balance, where we should have several viable CAs that we trust to be secure, but not 100s of them, just 10s. We already trust a ton more roots than that, so right now I see a new CA as being detrimental to security overall.
That all being said, I'm pretty sure this CA is using an existing trusted root and processes, so since it doesn't require cross-signing in a new root, it's less big of a deal.
I acknowledge your points with the risk of intelligence leaking. However most DNS is benign / not a state secret in general.