Let's Encrypt issues 35 certs every second
twitter.com
twitter.com
I just had a positive experience with adding a Let's Encrypt SSL cert at Fly.io[1] for hosting my new PWA on a custom domain[2]. It was literally a one-line command to run but no DNS challenge
[1] https://fly.io/docs/app-guides/custom-domains-with-fly/#addi...
This is just 3.5 Mbps, and we’re all “very impressed” that it’s being provided for free.
A Raspberry Pi could serve this.
Certificate Authorities have convinced everyone that their service is so onerously difficult to provide that they deserve billions of dollars… annually.
The reality is that they are pure rent-seekers, charging $50 for something that can be provided for free from a fanless hobby computer.
I just want everyone to have some perspective next time you go buy a wildcard certificate for a thousand dollars, which differs from a normal certificate by just four bytes.
Count the dollars per byte.
DigiCert for example is owned by private venture capitalists.
They expect as much rent-seeking as possible to get a return on their investment.
FreeFreeFreeCerts (https://bugzilla.mozilla.org/show_bug.cgi?id=233458) or Honest Achmed’s certificate authority (https://bugzilla.mozilla.org/show_bug.cgi?id=647959) won’t make it in today’s world, nor yesterday’s.
Let’s Encrypt’s financials are public and they aren’t running it off a singular Raspberry PI, nor anything like it - because they can’t; nor would it responsible to, at least on, say, a HSM or key seperation level.
Not to say, though, that traditional CAs aren’t rent seeking bloated greedy pieces of shit - because they absolutely are. I’m happy Let’s Encrypt found the funding and will (and the all important cross-sign) to take off and curb stomp the incumbent CAs around a bit. I still cringe every time I see an OV certificate in the wild.
I actually made one for myself in go that's been pretty fun. You can try it if you want (https://github.com/fsmv/daemon) but you should be able to set it up with apache or nginx as well.
Use it as a reverse proxy to your services
Before HTTPS was popular, I used to see ISPs inject tracking JavaScript or ads into arbitrary websites for their "customers".
So, in some sense yes, this preserves a legitimate version of your website for the requester.
This is largely because putting a huge red alert in front of plaintext HTTP pages would provoke a huge backlash from anti-HTTPS factions on the Internet.
HTTP pages should have a big red alert on them, and browsers are very slowly but surely moving in a direction of being HTTPS by default and HTTPS-only in the limited instances where it's possible. Arguably even in that world, a site claiming that the connection is secure and then offering a bad certificate is more worrying than a site that never claims the connection is secure in the first place. But ideally, eventually, we hope that the vast majority of the web is using certificates, and that visiting an HTTP-only page should be a rare event, possibly with some kind of warning in front of it.
Browsers have at the very least gotten rid of the SSL green padlock and have de-emphasized certificate origin in their presentation, and HTTP-only pages at least get labeled as insecure in modern browsers. That's a step in the right direction. But yeah, it's tough to treat HTTP-only pages the way they should be treated because a bunch of Internet users who dismiss MITM attacks will cry murder if browsers do so.
And of course absent a bunch of infrastructure and pinning capabilities and authentication mechanisms that don't exist for browsers, under current usage self-signed certificates don't really prove anything about the security of your connection.
This comment is the reason why browsers don't currently display giant warnings in front of HTTP pages even though they do arguably imply even less security than self-signed certificates. It has nothing to do with a browser conspiracy or narrative about "trusted" certs; browsers have largely been moving in a positive direction on that front.
Or are you just being snarky for the sake of being snarky?
Bad actors can get TLS certificates issued for their phishing sites just the same as you can for a regular website. Encryption is for everybody.
If your problem is that people treat certificates like they're some badge of authenticity, you're really complaining at the wrong company about that.