Let’s Encrypt is a new Certificate Authority: It’s free, automated, and open
letsencrypt.org
letsencrypt.org
Previous HN discussion from their launch ~6months ago, are here: * Launching in 2015: A Certificate Authority to Encrypt the Entire Web https://news.ycombinator.com/item?id=8624160 * Let's Encrypt: How It Works https://news.ycombinator.com/item?id=8640756
In a more general sense, why have none of the larger players, who, I would have thought could easily do it, not ventured into this space?
Why are Google, Amazon, Microsoft, etc. not offering me free SSL certs based on their own existing ability to verify my identity in so many ways, far better than letsencrypt or anybody else, really? I'm really curious about what is the barrier here that makes this so hard that basically nobody is doing it? And if those barriers are so high, why is StartSSL able to do it?
Once everything is encrypted, the only things that can be known of a request are the origin IP and the destination IP.
[editing to add other sponsors]