How does requiring HTTPS turn into no more personal websites? Let's Encrypt offers free certificates with automated renewal and minimal hassle, and if you don't like them there are several free alternatives.
How does requiring HTTPS turn into no more personal websites? Let's Encrypt offers free certificates with automated renewal and minimal hassle, and if you don't like them there are several free alternatives.
The second is more abstract but notice how literally everyone in this thread is recommending LetsEncrypt. That's great, and I love LE and I'm really glad they exist. But this is literally putting all our eggs in one basket. The increased centralization will inevitably lead to increased pressures, social, political, and otherwise on LE to censor, revoke permission, or otherwise cancel the accounts of law breaking websites. Like, say, a website for an abortion clinic that is now against the law in Texas. Switching to comodo when this happens won't fix it.
Web serving has always had moving parts, and there has always been some maintenance required to keep sites up. I agree that HTTPS increases the burden here, but not from zero.
> at some point that complex stack of software (who's complexity is hidden from the user) will break
Sort of? People definitely screw up their HTTPS configuration from time to time, or run into bugs. But the acme software is very reliable, so this is rare, and if it does happen blowing your existing configuration away and starting fresh will fix it.
> And not only does it make them more fragile but it makes setting up a website for the first time much more complex.
If you want to set up a website with minimal steps you generally get someone else to host, at which point they are dealing with HTTPS. If you want to do it all yourself HTTPS does add a step, but it is small compared to all of the other steps involved in setting up a server.
> The increased centralization will inevitably lead to increased pressures, social, political, and otherwise on LE to censor, revoke permission, or otherwise cancel the accounts of law breaking websites.
The US legal system cannot currently compel Let's Encrypt to refuse service to lawbreaking sites, and even if the law changed here you could get a certificate from a CA in another country.
And you do understand the reason why having browsers verify that they're actually talking to who they think they're talking to is important, right?
HTTP/3 would break this.
These are very different. If need to convince your audience to get and install some alternate client with an alternate protocol, now you audience it at best only a few techies who can do that for themselves.
Whereas sending anyone an URL they can click on with any client, even if it identified by an IP address instead of a hostname, is as easy at it gets.
Let's Encrypt is awesome, I use them for all my personal sites (web and non).
Threat modeling covers more than just authenticity and confidentiality. For instance, denial of service is also something to evaluate. So why does this matter?
Today if Let's Encrypt suddenly disappears or goes evil and no longer wants to issue me a certificate, I can simply re-enable plan HTTP on my site and my content remains available. Sure there are drawbacks but there are pros and cons to everything. As a static site I'm comfortable with the cons of hosting it via HTTP if the only alternative is not being able to host at all. Important things is I can make that choice.
In a world where normal people (i.e. non-techies who can't be expected to build their own browsers from source or whatever) can only have access to a client that enforces public CA issued certificates, it becomes easier than ever to drop unwelcome people effectively off the internet.