I hope everyone realises that Let's Encrypt is by now an essential part of the Internet, somewhat like DNS is, just massively centralised.
I hope everyone realises that Let's Encrypt is by now an essential part of the Internet, somewhat like DNS is, just massively centralised.
You can start reading more info here: https://developer.mozilla.org/en-US/docs/Web/Security/Certif...
(HPKP is considered obsolete, if by cert pinning you meant that. If you're confusing HSTS with HPKP, just know that HSTS makes it much harder to mistakenly access the site via http, while HPKP [now deprecated] is the practice of ensuring some hashes is found in the cert that the server sends to mitigate some attacks)
Oh, that’s a neat one and would be very valuable for me. We have poor internet access at home and would be cool to reduce traffic going out to the net.
Thanks for the reply, appreciate it!
https://community.letsencrypt.org/t/certificate-failure-due-...
Pinning has uses, but if I'm running an app, I'm not doing pinning unless I have to.
Pinning to the issuing or root is much safer from an availability standpoint.
https://docs.aws.amazon.com/enclaves/latest/user/nitro-encla...
Of course, the other failure points didn't completely go away yet. But I do expect their number to reduce a lot in the future.
In an emergency.
It would take quite some coordination but I suspect the current pandemic might provide some models and examples as to the way to do things at scale with JiT decision making from wonks who normally drag feet by default.
What exactly is the issue with centralization here?
I couldn't name a second, which means they're probably not getting a huge %.
You can both block certs that do not appear in the logs, and decide which certs not to trust ("everything after Friday the 13th at midnight is not trusted"), once you know the date/time of the intrusion.
but the issuance time isn't relevant, they can easily backdate the cert
I'd love to see, say, another charitable CA set up in a different jurisdiction[0] that can hold a similar reputation to the ISRG.
[0] Probably somewhere in Europe, whether that's in the EU or elsewhere like Switzerland or the UK. What matters most is that it's somewhere with strong commitment to the Rule of Law and not beholden to the US.