It's also quite odd that the article doesn't mention Let's Encrypt or the ISRG at all. I would have expected some sort of acknowledgement to their fantastic work over the years.
It's also quite odd that the article doesn't mention Let's Encrypt or the ISRG at all. I would have expected some sort of acknowledgement to their fantastic work over the years.
i think their platinum-level sponsorship of the ISRG is probably more meaningful than a shout-out in a blog post.
Side note: I'm actually so proud that my company, Datto, has also been sponsoring Let's Encrypt for many years, and that I was the one to suggest it. It's not platinum, but it's still $50k per year.
also, i get the sense that getting wider adoption for FIDO outside of LetsEncrypt is a bit of a goal, so having a third-party announce support for FIDO without referring to it as "the LetsEncrypt protocol" is kind of a win for the FIDO people.
for which there's no payment required as far as I can tell—just creating a Google Cloud account.
As the adage goes, if it's free you are the product, not the customer.
As well, post-paid providers rely on credit-card billing information to deduplicate/KYC users. Without this sort of information, an, er, "ingenious" user could just sign up for a million free-tier accounts and lash them together into a quota-evading resource-sucking behemoth.
And probably far less, actually. As many GCP users as there might be in the world, most of them are IT staff working for some-or-another enterprise; where that enterprise only has a single GCP billing-account administrator. Nobody else in the enterprise has their card on file. (And that billing-account administrator's card-on-file is just a corporate credit card, that tells you what the corporation buys, but tells you nothing about the individual. And their email is just a group/alias — billing@ or somesuch. Impossible to log into; impossible to browse the web as; no way to target ads at.)
You'd think the long tail of individual accounts could have more value, but those are the same users who GCP is least interested in recruiting to their platform, and the ones whose entered data is least trustworthy, because of all the spammers and crypto-miners attempting to use stolen credit cards to pay for service. You want to bind some poor random Joe's card-hubbed ad-profile to a spoke created by the person who stole their identity? That's negative average ad-targeting ROI!
Google is pretty famous for their nonexistent customer support, so I can't expect satisfaction there. And a chargeback would risk getting my entire account blocked.
Google cloud billing doesn't use google pay, so...nothing?
You gave them permission to bill for a reason. They decide the reason and amount and you pay. Seems risky without support.
Edot: Absolutely zero surprise this is getting voted to nowhere. CHEERS
The pattern you're referring to really doesn't apply to this business. If anything it's the opposite: Kurian's goal is to make Gcloud more like Oracle, and part of that involves making sure enterprise customers don't need to be skittish about the kinds of concerns you seem to be thinking of.
[1]: https://techcrunch.com/2022/02/02/with-a-22b-run-rate-does-i...
The fact that the current run rate is $22bn compared to the $13bn revenue in 2020 suggests that they're succeeding - that's some pretty significant growth.
It's a completely different business model from the consumer/ad side, and confusing the two is a mistake.
The counterfactual question one should be asking here is: Would gCloud exist if it were an independent company and not a bet?
Full disclosure: Xoogler here.
Independent companies like that are funded by investors for years, all the time. The cloud market is expected to hit close to a trillion dollars by 2026. Gcloud doesn't have to take away a single existing AWS customer to win big.
> Xoogler
So what's your take? You think Google might just decide to shut down a fast-growing business with $13-20bn revenues and huge upside potential as if it were a free product like Reader? Or you think they somehow aren't able to make it profitable so will just give up?
Neither of those are really how these things work.
All I'm saying is that this business isn't a monopoly like search or a near duopoly like ads. The competition is stiff. There are two players who are well ahead of them and the ones behind aren't sitting still. I don't expect any miracles with run of the mill management consulting leadership at the helm.
https://www.cnbc.com/2017/06/21/wal-mart-is-reportedly-telli...
So you can both do this (silently) and "not" do it (because it's impossible to detect), and it would thus be stupid to not actually do it because it's free data.
Zooming out I think this and the opposite view are equally possible. Just articulating what this perspective looks like.
That's a pretty huge data point though. It puts you into a very specific market segment.
They've changed free things to not free things many times in the past. Or started restricting features once it gets popular. Don't depend on it for anything you want to last a while.
LE is great, but their SLO is significantly below our customers’ expectations. For us, Google wouldn’t replace LE, it would supplement LE for higher reliability.
Seeing more providers conforming to ACME at a price point of “free” is great for the ecosystem.
The recommended renewal cycle gives you a 30 day lead on failure becoming a problem, plenty of time for multiple retries or recovery processes to use an alternate.
The only issues I've ran into, have stemmed from DNS for wildcard certs, where a client's DNS provider is... pretty crap about updating records despite low ttls being set.
On AWS, the equivalent is "We no longer recommend this, and it's not visible in the AWS console unless you are already using it or have asked support to enable it, but it will keep working indefinitely".
The traditional way a big tech company becomes the dominant provider is to embrace an open interoperable protocol to minimize the friction of switching from another provider. Later, when they have captured enough of the market, they extend the protocol to gradually reduce the de facto interoperability with other providers to increase the friction of switching to any other provider.
https://en.wikipedia.org/wiki/Embrace%2C_extend%2C_and_extin...
Even traditional host providers are raising their costs for the same mysterious reasons, although hardware costs are historically trending lower over time.
That's one way to put it.
Solving your customer's problems and making it more likely they will keep using your main offering is another way to put it.
Centralization with no accountability besides blaming things on AI is problematic.
This service has nothing to do with Let's Encrypt, you get certificates from GTS, so the connection would be that ISRG / Let's Encrypt was part of the work to develop ACME and so on. But that's increasingly ancient history. The goal of the work was that almost all CAs in the Web PKI would offer ACME (the people doing like a dozen issuances per month maybe not, but there's an open question about whether they should even exist) -- not just this one free service operated by a charity and here Google are following through.
I'd say that it's the same as if Zig announces each new compiler version or whatever and doesn't acknowledge that, yeah, Grace Hopper is in some sense responsible for the idea of compilers. [[ Hopper wrote the first "compiler" although today we would not consider her software to be a "compiler" but maybe a loader/linker. Anyway, the whole practice of having the machine do the boring job of writing machine code while a human just expresses what they wanted is down to Grace. Thinkers like Turing would have known this was possible in theory but Grace wasn't writing theory, she was doing engineering. ]]. Grace Hopper is important and worth celebrating, but it would be weird to insist on making a specific programming language that has nothing to do with Grace mention her every release.
I guess if you're an Oscar's speech writer going for that "I want to thank my parents, without whom I wouldn't be here today" vibe, then yeah. But otherwise it seems unnecessary.
For example they do managed TLS for their workloads like AWS but they operate their own CA rather than outsourcing to Digicert for certificate issuance which gives them a better SLA.
They have a global load balancer offering that enables TLS to terminate everywhere GCP is without having to manage a bunch of discrete load balancers, this also supports managed TLS.
They now support a very large number of certificates in the global load balancer product which allows SaaS products like hosting services to leverage the global load balancer rather than deploying a load balancer per 25 certificates (the limit per AWS LB).
And now let you enroll for certificates from the same CA they use even if you terminate TLS rather than having them do it for you. They do this via a standard API (ACME) which lets you have uniform and agile device compatibility regardless of how you deploy TLS. AWS doesn't let you do this at all.
(I should note I was the PM for most of these releases and am still the PM for Google Trust Services the CA used for this ACME release)
Which does raise an issue: I'm not sure why you'd use this, given Google's history of killing projects. What's the compelling reason to switch - especially since they feel content to release this under the `alpha` command set for the CLI tool.
I don't understand why anyone would go for this given LE is mature, stable, trusted, and well-supported.
Say one day it just stops issuing you new certs; now what? Call someone? Nope. Post in the forums? Not unless you want to get asked if you've cleared your Chrome cache.
1: https://letsencrypt.org/docs/challenge-types/#dns-01-challen...
2: https://eff-certbot.readthedocs.io/en/stable/using.html#dns-...
If I remember correctly, you don't need your server to be reachable from the internet, but you still need to be able to contact your DNS provider and the LE server, so you need internet access
So I don't recommend LE to my clients anymore. But it's a hassle to buy certificates the old way after having tasted ACME, so I'm always looking for an ACME-compatible alternative. ZeroSSL is backed by a more conservative Sectigo CA, but its ACME endpoints aren't very reliable. If this Google cert becomes widely available, I might just as well switch to it. :)
But their ACME support seems half-hearted at best. The endpoints often return errors for no reason, compatibility with clients is hit-and-miss, and they keep spamming you with renewal notices even if you renew the cert. For important domains these days I just get a cheap 1-year DV cert like the good ol' days.
https://support.google.com/chrome/thread/135844398/chrome-is...
So, yeah... I don't want to depend on a free Google Cloud account for SSL.
Google != Google Cloud Platform
.. the biggest advertising giant on the planet that sucks up as much data as they possibly can about their subjects.
> What's the compelling reason to switch
Google Cloud has been issuing certs for customer use off its own CA ( pki.goog ) for a while. It went GA April 27, 2020:
https://cloud.google.com/load-balancing/docs/release-notes#A...
You can see the documentation here:
https://cloud.google.com/load-balancing/docs/ssl-certificate...
GCP load balancers can automatically switch between pki.goog and letsencrypt.org if one goes down. Or you can restrict the load balancer to just get certs one of them by using a DNS CAA record.
Up till now, you could only use pki.goog with GCP load balancers. This new release allows pki.goog to be used with anything, because you actually control the private key.
Disclosure: I work in Google Cloud.
Awesome, glad to see other ACME clients using issuer fallback, like Caddy does!
Do you know if there are any plans to making the Google ACME CA usable without registration? Having to register for an account and using credentials is a huge barrier to entry for many less-technical users. Caddy is able to use LE and ZeroSSL because they both don't _require_ accounts (ZeroSSL recommends it, partially as an upsell, but it's not necessary).
The more no-registration CAs exist, the more resilient ACME clients can be.
I heard of someone who enrolls in a community college every winter, then goes skiing on a student discount, then drops out quickly and gets a refund. Not very ethical...
Sorry, this was completely unrelated to your point.
In 2026 only rich companies will be able to maintain sites with the way we're going folks.