[HN Gopher] 10 Years of Let's Encrypt
       ___________________________________________________________________
        
       10 Years of Let's Encrypt
        
       Author : SGran
       Score  : 372 points
       Date   : 2025-12-09 18:54 UTC (4 hours ago)
        
 (HTM) web link (letsencrypt.org)
 (TXT) w3m dump (letsencrypt.org)
        
       | victorbjorklund wrote:
       | Wow. Feels like Let's encrypt been around for longer.
        
         | Aardwolf wrote:
         | Agreed! What were we using before Let's Encrypt again? Maybe
         | just plain HTTP
        
           | bakies wrote:
           | Self signed certs. I wasn't paying.
        
             | Thaxll wrote:
             | Some of them were not expensive but it was not convenient
             | at all.
        
           | rew0rk wrote:
           | either you used http, self signed if you did not mind the
           | warning, and i remember there being one company that did
           | offer free certificates that validated, but cant remember the
           | name of it
        
             | tomklein wrote:
             | I believe it was StartSSL and/or WoSign back then
        
             | SahAssar wrote:
             | > i remember there being one company that did offer free
             | certificates that validated, but cant remember the name of
             | it
             | 
             | You're probably thinking of StartSSL, and it was a bit of a
             | pain to get it done.
        
           | asadotzler wrote:
           | SSL/TLS via expensive and hard to work with providers and
           | tooling. Let's Encrypt made it free and easy to maintain.
        
           | ZeroConcerns wrote:
           | Mostly Verisign, which required faxing forms and eye-watering
           | amounts of money. Then Thawte, which brought down prices to a
           | more manageable US$500 per host or so. Which might seem
           | excessive, but was really peanuts compared to the price of
           | the 'SSL accelerator' SBus card that you also needed to serve
           | more than, like, 2 concurrent HTTPS connections.
           | 
           | And you try telling young people that ACME is a walk in the
           | park, and they won't believe you...
        
             | anamexis wrote:
             | And then sketchy resellers for Verisign/Thawte, which were
             | cheap but invariably had websites that ironically did not
             | inspire confidence in typing in your credit card number.
        
             | dylan604 wrote:
             | As GP posited, because of this headache, lots of web
             | traffic was plain ol' HTTP. Let's Encrypt is owed a lot of
             | credit for drastically reducing plain ol' HTTP.
        
           | SirMaster wrote:
           | I was using StartCom StartSSL which was offering free 1 year
           | certificates at least for my personal sites.
        
             | 0x0 wrote:
             | They were great in the beginning, and then when you issued
             | a few more certs than they liked you were asked to pony up
             | some $$$, and then when you did that and actually
             | "verified" who you were on a personal international phone
             | call, you got a grace, and then issued a few more, they
             | decided they didn't like you so they would randomly reject
             | your renewals close to the expiration date, and then they
             | got bought out by some scummy foreign outfit which
             | apparently caused the entire CA to be de-listed as
             | untrustworthy in all major browsers. Quite the ride.
             | 
             | Also, the only website I've ever encountered that actually
             | used the HTML <keygen> tag.
        
           | 1f60c wrote:
           | The pros were using client-side encryption :D
        
         | quesera wrote:
         | I was going to say the opposite. LE still feels like the "new"
         | way, to me. :)
        
       | jjice wrote:
       | Let's Encrypt was _huge_ in making it's absurd to not have TLS
       | and now we (I, at least) take it for granted because it's just
       | the baseline for any website I build. Incredible, free service
       | that helped make the web a more secure place. What a wonderful
       | service - thank you to the entire team.
       | 
       | The CEO at my last company (2022) refused to use Let's Encrypt
       | because "it looked cheap to customers". That is absurd to me
       | because 1), it's (and was at the time) the largest certificate
       | authority in the world, and 2) I've never seen someone care about
       | who issued your cert on a sales call. It coming from GoDaddy is
       | not a selling point...
       | 
       | So my question: has anyone actually commented to you in a
       | negative way about using Let's Encrypt? I couldn't imagine, but
       | curious on others' experiences.
        
         | rokkamokka wrote:
         | No! Let's encrypt is easily the best thing that's happened for
         | a secure internet the last 10 years.
        
         | johnebgd wrote:
         | There are extended certificates that did matter in our sales
         | process for some hosted solutions back about 15 years ago if I
         | recall right... no one has ever cared since...
        
         | giancarlostoro wrote:
         | > It coming from GoDaddy is not a selling point...
         | 
         | I just people who use GoDaddy. They were the one company
         | supporting SOPA when the entire rest of the internet was
         | opposed to SOPA. It's very obvious GoDaddy is run by "business-
         | bros" and not hackers or tech bros.
        
           | dylan604 wrote:
           | This is my feeling as well. Finding out someone uses GoDaddy
           | is a bit of a shibboleth.
        
         | Analemma_ wrote:
         | I've seen people complain that Let's Encrypt is so easy that
         | it's enabling the forced phaseout of long-lived certificates
         | and unencrypted HTTP.
         | 
         | I sort of understand this, although it does feel like going
         | "bcrypt is so easy to use it's enabling standards agencies to
         | force me to use something newer than MD5". Like, yeah, once the
         | secure way is sufficiently easy to use, we can then push
         | everyone off the insecure way; that's how it's _supposed_ to
         | work.
        
           | mschuster91 wrote:
           | > Like, yeah, once the secure way is sufficiently easy to
           | use, we can then push everyone off the insecure way; that's
           | how it's supposed to work.
           | 
           | The problem is that this requires work and validation, which
           | no beancounter ever plans for. And the underlings have to do
           | the work, but don't get extra time, so it has to be crammed
           | in, condensing the workday even more. For hobbyist projects
           | it's even worse.
           | 
           | That is why people are so pissed, there is absolutely zero
           | control over what the large browser manufacturers decide on a
           | whim. It's one thing if banks or Facebook or other truly
           | large entities get to do work... but personal blogs and the
           | likes?
        
             | nottorp wrote:
             | > but personal blogs and the likes?
             | 
             | Yep, the result of the current security hysteria/theater is
             | it makes it increasingly difficult to maintain an
             | independent web presence.
             | 
             | Yes, I know, you can just use Cloudflare and depend on
             | it...
        
               | eastbound wrote:
               | Cloudflare uses HTTP to connect to your website before
               | caching the content. I've always found it highly
               | insecure. You could have HTTPS with Letsencrypt, but you
               | need to deactivate Cloudflare when you want to renew (or
               | use the other validation that is complex enough that I
               | didn't succeed to do it).
        
               | nottorp wrote:
               | Don't pick on this particular SSL requirement, pick on
               | the deluge of requirements that only make sense for a
               | site that sells something or handles personal data (i.e.
               | has accounts). They get extended to $RANDOM_SITE that
               | only serves static text and the occasional cat photo for
               | no good reason except "your cats will be more secure!".
        
               | Ferret7446 wrote:
               | TLS only takes a few minutes to add to a self hosted
               | solution, just plop caddy in front of your server
        
           | foresto wrote:
           | I can understand this in in certain contexts, such as a site
           | that exists solely to post public information of no value to
           | an attacker.
           | 
           | A local volunteer group that posts their event schedule to
           | the web were compelled to take on the burden of https just to
           | keep their site from being labeled as a potential threat.
           | They don't have an IT department. They aren't tech people.
           | The change multiplied the hassles of maintaining their site.
           | To them, it is all additional cost with practically no
           | benefit over what they had before.
        
             | charcircuit wrote:
             | This is why more and more organizations get away with only
             | having social media pages where they don't have to worry
             | about security or other technical issues.
        
               | foresto wrote:
               | Unfortunately, placing the information on a social media
               | page burdens the people seeking it with either submitting
               | to the social media site's policies and practices, or
               | else not having access to it. This is not a good
               | substitute.
               | 
               | It also contributes to the centralization of the web,
               | placing more information under the control of large
               | gatekeepers, and as a side effect, giving those
               | gatekeepers even more influence.
        
           | mook wrote:
           | Yeah, I hate how it made housing things locally without a
           | proper domain name very difficult. My router _shouldn't_ have
           | a globally recognized certificate, because it's not on a
           | publicly visible host.
           | 
           | There's certainly advantages to easily available
           | certificates, but that has enabled browsers and others to
           | push too far; to be sure, though, that's not really a fault
           | of Let's Encrypt, just the people who assume it's somehow
           | globally applicable.
        
           | rplnt wrote:
           | Random anecdote: I have a device in which the http client
           | can't handle https. Runs out of memory and crashes. Wasn't
           | able to find a free host with a public http to host a proxy.
        
         | UltraSane wrote:
         | I have worked at companies that refused to use LetsEncrypt for
         | the same reason.
        
         | quesera wrote:
         | There was a time when EV certificates were considered more
         | trustworthy than DV certs. Browsers used to show an indication
         | for EV certs.
         | 
         | Those days are long gone, and I'm not completely sure how I
         | feel about it. I hated the EV renewal/rotation process, so
         | definitely a win on the day-to-day scale, but I still feel like
         | something was lost in the transition.
        
           | trueismywork wrote:
           | What about OV?
        
             | ekr____ wrote:
             | It's never been clear to me what the rationale for OV was,
             | as the UI wasn't even different like EV was.
        
             | quesera wrote:
             | I've never seen (noticed) an OV cert in real life, and no
             | business I've ever been responsible for pushed for OV over
             | DV. It was always EV or "huh?"
        
               | Sesse__ wrote:
               | Before LE, we did lots of OV (which you generally could
               | get a couple of for free from somewhere). We had to dig
               | up stuff like a heating bill, because evidently that is
               | proof of organizational control to some people.
        
               | bostik wrote:
               | I think I've seen one or two, and only because I noticed
               | them as a weird callout in a $LARGE_FINANCE_INSTITUTION
               | infosec bingo sheet. Of course I _had_ to check that they
               | really were running with OV certs.
               | 
               | Some of the outfits in that space will be heavily hit by
               | the shortening certificate max-lifetimes, and I do hope
               | that the insurance companies at some point also stop
               | demanding a cert rotation before 90 days to expiry. It's
               | a weird feeling to redline a corporate insurance policy
               | when their standard requirements are 15 years out of
               | date.
        
               | quesera wrote:
               | > _when their standard requirements are 15 years out of
               | date_
               | 
               | I swear half of my "compensating control" responses are
               | just extended versions of "policy requirement is outdated
               | or was always bad".
        
         | traceroute66 wrote:
         | > has anyone actually commented to you in a negative way about
         | using Let's Encrypt?
         | 
         | A friend of mine has had a negative experience insofar as they
         | are working for a small company, using maybe only 15-20 certs
         | and one day they started getting hounded by Let's Encrypt
         | multiple times on the email address they used for ACME
         | registration.
         | 
         | Let's Encrcypt were chasing donations and were promptly told
         | where to stick it with their unsolicited communications. Let's
         | Encrypt also did zero research about who they were targetting,
         | i.e. trying to get a small company to shell out $50k as a
         | "donation".
         | 
         | My friend was of the opinion is that if you're going to charge,
         | then charge, but don't offer it for free and then go looking
         | for payment via the backdoor.
         | 
         | In a business environment getting a donation approved is almost
         | always an entirely different process, involving completely
         | different people in the company, than getting a product or
         | service purchase approved. Even more so if, like Let's Encrypt,
         | you are turning up on the doorstep asking for $50k a pop.
        
           | jfindper wrote:
           | > _one day they started getting hounded by Let 's Encrypt
           | multiple times_
           | 
           | > _trying to get a small company to shell out $50k as a
           | "donation"._
           | 
           | > _Even more so if, like Let 's Encrypt, you are turning up
           | on the doorstep asking for $50k a pop._
           | 
           | Does your friend have anything to corroborate this claim?
           | Perhaps the email with identifying details censored?
           | 
           | I have a received an occasional email mentioning donations.
           | They are extremely infrequent and never ask me for a specific
           | amount. I would be incredibly surprised to see evidence of "
           | _hounding_ " and requests for $50,000.
        
             | traceroute66 wrote:
             | All the usual phishing checks were done if that's what
             | you're thinking.
             | 
             | In terms of the actual mail with identifying details
             | removed, I'd have to go back and ask.
             | 
             | I did look before posting here as I thought they had
             | already forwarded it to me, but it was last year, so I have
             | almost certainly cleaned up my Inbox since. I'm not an
             | Inbox hoarder.
        
           | cjaybo wrote:
           | "They sent a few emails soliciting donations" isn't exactly a
           | horror story in my experience. Seems hardly worth mentioning!
        
             | dylan604 wrote:
             | It's not something to stop using them over, but unsolicited
             | solicitation emails are annoying at the least. It's
             | definitely worth mentioning letting other people know they
             | have warts too
        
             | traceroute66 wrote:
             | To be clear, I was merely answering the question posed _"
             | has anyone actually commented to you in a negative way
             | about using Let's Encrypt?"_
             | 
             | Well, yes, someone actually commented to me in a negative
             | way about using Let's Encrypt ....
             | 
             | Don't shoot the messenger, as they say.
        
         | btown wrote:
         | To be fair, for a CEO in 2022, EV certificates had only lost
         | their special visualizations since September/October 2019 with
         | Chrome 77 and Firefox 70 - and with all that would happen in
         | the following months, one could be forgiven for not adapting to
         | new browser best practices!
         | 
         | https://www.troyhunt.com/extended-validation-certificates-ar...
        
           | yabones wrote:
           | Call me old-school, but I _really_ liked how EV certs looked
           | in the browser. Same with the big green lock icon Firefox
           | used to have. I know it 's all theatrics at best and a scam
           | at worst, but I really feel like it's a bit of a downgrade.
        
             | wnevets wrote:
             | > Call me old-school, but I really liked how EV certs
             | looked in the browser.
             | 
             | I agree, making EV Certs visually more important makes
             | sense to people who know what it means and what it doesn't.
             | Too bad they never made it an optional setting.
        
               | arccy wrote:
               | i think the point was that EV didn't actually mean
               | anything because the checks were too loose. it's a feel
               | good false sense of security
        
               | RonanSoleste wrote:
               | When you request an EV. They call you by the phone number
               | that you give to ask if you requested a certificate. That
               | was the complete extend of the validation. I could be a
               | scammer with a specificity designed domain name and they
               | would just accept it, no questions asked.
        
               | Uvix wrote:
               | Depends on the registrar. Globalsign required the phone
               | number to be one publicly listed for the company in some
               | business registry (I forget exactly which one), so it had
               | to be someone in our main corporate office who'd deal
               | with them on the phone.
        
               | bangaladore wrote:
               | For an online business in a dubious (but legal) domain,
               | my co-owner spent a few hundred bucks registering a
               | business in New Mexico with a registered agent to get an
               | EV cert.
               | 
               | So, a barrier to entry, but not much of one.
        
               | wnevets wrote:
               | > In addition to all of the authentication steps CAs take
               | for DV and OV certificates, EV certificates require
               | vetting of the business organization's operational
               | existence, physical address and a telephone call to
               | verify the employment status of the requestor. [1]
               | 
               | [1] https://www.digicert.com/difference-between-dv-ov-
               | and-ev-ssl...
               | 
               | Tying a phone number to a physical address and company is
               | a lot more useful than just proof of control over a
               | domain. Of course its not 100% fool proof and depends on
               | the quality of the CA but still very useful.
        
               | matrss wrote:
               | > Tying a phone number to a physical address and company
               | is a lot more useful than just proof of control over a
               | domain.
               | 
               | It might be useful in some cases, but it is never any
               | more secure than domain validation. Which is why browsers
               | don't treat it in a special way anymore, but if you want
               | you can still get EV certificates.
        
               | monerozcash wrote:
               | It was easy to provide the information for an existing
               | business you're completely unrelated to. Reliably
               | verifying that a person actually represents a company
               | isn't possible in most of the world.
        
               | fpoling wrote:
               | Many countries has official register of companies with at
               | least post box address. Requiring to answer a physical
               | letter sent to an address from the central register will
               | be much more reliable.
        
               | realityking wrote:
               | EV certs also showed the legal name of the company that
               | requested the certificate - that was an advantage.
        
               | duskwuff wrote:
               | Which would have made sense if company names were unique
               | - which they aren't. See e.g. https://groups.google.com/g
               | /mozilla.dev.security.policy/c/Nj... for an example of
               | how this was abused.
        
               | brians wrote:
               | Having run an EV issuing practice... they were required
               | to contact you at a D&B listed number or address.
        
               | AlbinoDrought wrote:
               | I'd love a referral to your certificate authority and rep
               | - we go through a big kerfluffle each renewal period,
               | only eventually receiving the certificate after a long
               | exchange of government docs and CPA letters. For us, only
               | the last step is the phonecall like you say.
        
               | wnevets wrote:
               | The replies to my original comment make it obvious who
               | has gotten an EV cert from a quality CA before and who
               | hasn't.
        
             | woleium wrote:
             | it's okay, the scam continues with BIMI
        
           | unethical_ban wrote:
           | EV validated not only that a domain was under control of the
           | server requesting the cert, but that the domain was under
           | control of the entity claiming it.
           | 
           | I kind of wish they still had it, and I kind of wish browsers
           | indicated that a cert was signed by a global CA (real cert
           | store trusted by the browsers) or an aftermarket CA, so
           | people can see that their stuff is being decrypted by their
           | company.
        
             | arccy wrote:
             | you can find quite of few examples online that the entity
             | check wasn't all that strict...
        
             | tadfisher wrote:
             | Problem is, I can easily set up a company and get an EV
             | cert for "FooBar Technologies, LLC" and phish customers
             | looking for "FooBar Incorporated" or "International FooBar
             | Corp.". Approximately zero users know the actual entity
             | name of the real FooBar.
        
               | matrss wrote:
               | Even if the users knew exactly what the name of the
               | entity whose website they wanted to visit was: that name
               | is not unique, as is shown by the "Stripe, Inc" example
               | in the parents linked blog post.
        
           | charlesbarbier wrote:
           | It was a red herring the entire time. At Shopify we made
           | experiment regarding conversion between regular certs and EV
           | before they stop being displayed and there was no significant
           | difference. The users don't notice the absence of the fancier
           | green lock.
        
           | smurda wrote:
           | I loved the visualization of EV certs in browsers, but in
           | 2014 vendors like GoDaddy charged $100/yr for them. https://w
           | eb.archive.org/web/20131023033903/http://www.godadd...
           | 
           | I'm glad LE, browsers, and others like Cloudflare brought
           | this cost to $0. Eliminating this unnecessary cost is good
           | for the internet.
        
         | qwertox wrote:
         | I once notified Porsche that one of their websites had an
         | expired certificate, they fixed it within a couple of hours by
         | using Let's Encrypt. It surprised me.
         | 
         | Let's Encrypt is to the internet what SSDs are to the PC. A
         | level up.
        
         | xxmarkuski wrote:
         | I have heard, but do not aggree, that Let's Encrypt is risky,
         | because phishing sites use it. It's implied that other CAs do
         | checks against it.
        
           | anonymars wrote:
           | I will say, I have never before this season seen so many
           | seemingly-legit fake web stores. All with their little lock
           | icons in the address bar. I assume LLMs helped kick it into
           | overdrive too
        
       | npodbielski wrote:
       | I am glad to be one of the users using that for around 7 years. I
       | can't think of how much better is life of people just doing blogs
       | or some silly websites with free https certs. Would I pay 50$
       | bucks a year for ability to self host nextcloud? Probably not.
       | But security enhancement is so enormous with that service. Thanks
       | to everyone involved for making world a little bit better.
        
       | greyface- wrote:
       | New baseline expectation that web traffic will be encrypted on
       | the wire: very good!
       | 
       | New de-facto requirement that you need to receive the blessing of
       | a CA to make use of basic web platform features... not so good.
        
         | jovial_cavalier wrote:
         | That's not new, LetsEncrypt just didn't solve it. And if you
         | think this is the only single point of failure in the stack, I
         | have news for you.
        
           | greyface- wrote:
           | It's absolutely new. No HTML5 features were restricted to
           | secure origins only pre-LE. Today, many are. Google was able
           | to push these requirements in large part due to Let's
           | Encrypt's success making secure origins ubiquitous.
        
             | ekr____ wrote:
             | The order of events is a bit more complicated than this.
             | 
             | Google initially proposed restricting powerful features to
             | secure origins back in February of 2015 (https://web.archiv
             | e.org/web/20150125103531/https://www.chrom...) and Mozilla
             | proposed requiring secure origins for all new features in
             | April of 2015
             | (https://blog.mozilla.org/security/2015/04/30/deprecating-
             | non...). Let's Encrypt issued its first certificate in
             | September of 2015.
             | 
             | This isn't to say that these two things are unrelated:
             | Mozilla obviously knew about Let's Encrypt and we
             | considered it an important complement for this kind of
             | policy, and at least some people at Chrome knew about LE,
             | though I'm not sure how it played into their thinking.
             | However, it's not as simple as "LE happened and then people
             | started pushing for secure origins for new features".
        
         | ekr____ wrote:
         | Can you elaborate a bit about what you mean by "the blessing of
         | a CA"?
         | 
         | I agree that it's true that you need a certificate to do TLS,
         | but importantly Let's Encrypt isn't interested in what you do
         | with your certificate, just that you actually control the
         | domain name. See: https://letsencrypt.org/2015/10/29/phishing-
         | and-malware.html
        
           | greyface- wrote:
           | Their policy today is to grant certificates liberally. There
           | is no technical guarantee that this remains the case
           | indefinitely, only a political one. I don't doubt the
           | sincerity of this guarantee, but I wish I didn't have to rely
           | on it.
        
             | ekr____ wrote:
             | I agree that technical guarantees are better than policy
             | guarantees.
        
         | unethical_ban wrote:
         | Kinda hear you, but DNS is a defacto requirement as well.
         | Neither DNS (common TLDs) nor any of the major cert vendors I'm
         | aware of ask you your site's business before issuing.
        
           | charcircuit wrote:
           | >ask you your site's business before issuing.
           | 
           | Because they want your money. If they ask you after they get
           | to keep your money.
        
       | hulitu wrote:
       | > 10 Years of Let's Encrypt
       | 
       | Aren't they only 45 days [1] old ?
       | 
       | [1] https://letsencrypt.org/2025/12/02/from-90-to-45
        
         | p2detar wrote:
         | Not sure if you're joking or not, but I have to deal with this
         | upcoming change at some point and still haven't read in detail
         | why they decided to do this.
         | 
         | Could anyone clarify?
        
           | chippiewill wrote:
           | Lets Encrypt are doing is because of the decision that CAs
           | and browser makers made that it needs to be reduced (browsers
           | have been reducing the length of certs that they trust).
           | 
           | The why is because it's safer: it reduces the validity period
           | of private keys that could be used in a MITM attack if
           | they're leaked. It also encourages automation of cert renewal
           | which is also more secure. It also makes responding to
           | incidents at certificate authorities more practical.
        
             | dingaling wrote:
             | > it reduces the validity period of private keys that could
             | be used in a MITM attack if they're leaked
             | 
             | If a private key is leaked, 45 days is sufficient to clean-
             | out the accounts of all that company's customers. It might
             | as well be 10 years.
             | 
             | If cert compromise is really common enough to require a
             | response then the cert lifetime should be measured in
             | minutes.
        
           | bifurcation wrote:
           | Hi there, ISRG co-founder and current board member here. In
           | brief, shorter lifetimes force people to automate (which,
           | e.g., avoids outages from manual processes) and mitigates the
           | broken state of revocation in the Web PKI. That latter point
           | especially is what I understand to be driving the Web PKI
           | toward ever-shorter lifetimes.
           | 
           | I actually remember the discussion we had in ~2014 about what
           | the default certificate lifetime should be. My opening bid
           | was two weeks -- roughly the lifetime of an OCSP response.
           | The choice to issue certificates with 90 day lifetimes was
           | still quite aggressive in 2015, but it was a compromise with
           | an even more aggressive position.
        
             | everfrustrated wrote:
             | With the move to ever shorter certs the risk to letsencrypt
             | having an outage is higher.
             | 
             | It would be nice to read more about what the organization
             | is doing around resilience engineering so we can continue
             | to be confident in depending on it issuing renewals in
             | time.
             | 
             | Do you publish any of this? DR plans? Etc.
             | 
             | I don't mean for this to be a negative - really impressed
             | by LE - but we've had a lot of Cloudflare outages recently
             | and my mind is on vendor reliability & risk at the moment.
        
               | mcpherrinm wrote:
               | I'm the technical lead for Let's Encrypt SRE.
               | 
               | Publishing more about our resilience engineering sounds
               | like a great idea!
               | 
               | I'll get that on our blogging schedule for next year
        
         | nvader wrote:
         | Wow, this might be the push I needed to automate certificate
         | renewal on my personal website [0].
         | 
         | Manually clicking `make renew-cert` was barely tolerable every
         | quarter, but if I have to do it twice as frequently I may as
         | well ask an LLM to figure it out on my behalf.
         | 
         | [0]: https://danverbraganza.com
        
           | bifurcation wrote:
           | Heh, as I was saying about shorter lifetimes encouraging
           | automation...
           | 
           | https://news.ycombinator.com/item?id=46210786
        
             | nvader wrote:
             | Yep, it's just the push I needed to get off my seat ;)
        
           | dylan604 wrote:
           | And that is the very point of the short life span. One year
           | certs had the potential of the person responsible for the
           | cert no longer being the same person at time of renewal.
           | Making it easy to automate so that it was just a cron task
           | meant it didn't matter how often the person responsible
           | changed.
           | 
           | Your pain and intolerance to that button push proves their
           | intent.
        
       | Decoy1008 wrote:
       | I am so grateful for this. Bummer that they stopped with the
       | email reminder, anyways I was wondering how this would work
       | without active payments. Still amazing.
        
         | callumgare wrote:
         | Out of interest why do you care? I assume you're using acme to
         | automate renewals. Is it in case that fails? Or do you work
         | with some system that can't be automated?
        
       | asim wrote:
       | As a sysadmin in the 2007-2011 timeframe I literally used openssl
       | to generate csrs, went to godaddy to purchase SSL certificates
       | and then manually deployed them to servers. Man what a world of
       | change. Let's encrypt is one the best services we've had on the
       | internet. I wish we had more things like this.
        
         | par wrote:
         | i was doing this until a couple years back when a friend told
         | me about LetsEncrypt! It's like _magic_!!
        
       | scblock wrote:
       | LE has been really great, particularly in running hobby web sites
       | on the public internet. Getting certbot up and running wasn't
       | hard, automating renewal wasn't hard, and because they have DNS-
       | based pathways to verification you can use LE certificates for
       | sites not exposed to the public internet as well. Combine it with
       | something like Caddy and getting SSL for an app becomes the
       | default without ever having to manage certificates by hand.
       | 
       | I find it pretty amazing how far its come, and how big a change
       | it has made to the internet in the decade it's been operating.
        
       | jrochkind1 wrote:
       | it is hard to believe it's been ten years.
        
       | tracker1 wrote:
       | I'm not sure that I'm more surprised that it's only been 10 years
       | or that it's been that long. I mean, that's a relatively quick
       | turn around to pretty much dominate TLS certs to the point that
       | it's the default for so many platforms... that HTTPS has become
       | such a norm over the exception.
       | 
       | On the other hand, has it really been that long, it seems just
       | yesterday I was first trying to configure nginx for it. That
       | said, since I discovered Caddy, I haven't really looked back,
       | though I do use Traefik too.
       | 
       | I mean, by comparison, it feels like IE6 took longer to die than
       | Let's Encrypt has been around.
        
       | awaseem wrote:
       | Incredibly grateful for this project
        
       | ok123456 wrote:
       | Snowden was the other big reason that TLS became the de facto
       | standard for every site.
       | 
       | Prior to that, the consensus was that you only really needed TLS
       | if you were dealing with money and wasn't worth the hassle
       | otherwise. You could sniff traffic from Facebook and Twitter
       | easily.
       | 
       | I remember listening to a talk given by an IRS investigator in
       | around 2008 about how they were able to do a sting and shutdown
       | illegal internet casinos. They collected a good bulk of that
       | evidence from clear-text packet captures of gambling sessions and
       | messages. He preemptively answered the question of whether
       | encryption was a hurdle, by saying no one used it.
        
         | tptacek wrote:
         | This is a retcon. Facebook rolled out TLS in 2011, 2 years
         | before Snowden, and went TLS-by-default within a month of the
         | Snowden disclosures. Google Mail was TLS-by-default in 2010.
         | TLS was a universal best practice long before 2013 --- by 2010,
         | you'd have gotten a sev:hi vulnerability flagged on your site
         | if you hadn't implemented TLS. SSLLabs was 2009; BEAST was
         | 2011, and was a huge global news story because of how widely
         | deployed TLS was.
        
           | ok123456 wrote:
           | Yes. And I remember sniffing Facebook traffic in clear text
           | in 2011. The fact remains that it was considered a
           | significant engineering problem for them to deploy it. It was
           | a "best practice" that most people rolled their eyes at.
           | 
           | Most users and system owners didn't care unless money was
           | being transacted.
           | 
           | Between Snowden and ISPs injecting content into pages, the
           | consensus changed.
        
             | tptacek wrote:
             | The consensus obviously changed. It's just that it changed
             | years before the Snowden leaks.
        
               | ok123456 wrote:
               | The adversarial nature of the US Government changed the
               | threat model, and it moved from a "nice to have" best
               | practice to a business necessity. They were caught red-
               | handed undermining the privacy of US citizens by
               | systematically exploiting infrastructure vulnerabilities,
               | for example, in Google, where messages flowed in clear
               | text within nominally trusted contexts.
        
           | 8organicbits wrote:
           | I'm not sure that refutes the idea that encryption was
           | uncommon. A couple tech giants with challenging threat models
           | will be ahead of the curve.
           | 
           | Google started tracking adoption of TLS in 2015, with
           | adoption below 50% and some regions below 30%.
           | 
           | https://transparencyreport.google.com/https/overview?hl=en
        
           | schoen wrote:
           | I think you're right that this consensus was clearly emerging
           | then (I remember Firesheep in 2010 as another big
           | identifiable contributing factor), but I remember actively
           | asking _smaller_ sites to enable HTTPS in that era, and they
           | would often refuse. So I think Snowden also contributed to
           | the spread of the norm.
           | 
           | It is possible that there's a retcon element, because it's
           | not always clear in my memory exactly what year various sites
           | became more favorably disposed towards the request to use
           | HTTPS. So I could be misremembering some of them as agreeing
           | post-Snowden when they'd actually agreed one year before, or
           | something.
        
             | tptacek wrote:
             | I think it would be a stretch to say that Snowden did
             | nothing to accelerate the uptake; for better and worse he
             | clearly did. But he didn't set it into motion; we were
             | going to have an all-TLS Internet within a decade with or
             | without him.
        
         | 12_throw_away wrote:
         | I think it was a lot earlier than 2013 - SSL was inevitable by
         | the late 2000's, as soon as major ISPs decided they could make
         | more money by injecting ads into http connections (e.g., [1]).
         | It obviously took a while for the infrastructure to scale up
         | ... but I'd imagine that concerns about stolen ad impressions
         | drove a lot more HTTPS adoption than concerns about the NSA.
        
       | stego-tech wrote:
       | Let's Encrypt is something so amazingly valuable that I was
       | certain it'd be killed dead within a year to prop up the existing
       | SSL cert business.
       | 
       | Congrats on a decade, ya'll, here's to many, many more in
       | securing the free internet.
        
       | Havoc wrote:
       | Reminder that it's a non profit
        
       | vadepaysa wrote:
       | LetsEncrypt is on my end of year Donate list for the past 5
       | years. With all modern browsers requiring HTTPS everywhere, a
       | world without Let's Encrypt would be really difficult for indie
       | developers.
       | 
       | Thank You for an amazing product!
        
       | kyawzazaw wrote:
       | my friends work here! and it was founded by an alum from my
       | school Macalester College
        
       | postbase wrote:
       | thank you for your service
        
       | t1234s wrote:
       | Lets hope they stay independent and _never_ get acquired by
       | Google or any other large tech company. You can imagine a web
       | where SSL issuance is used as a tool to censor websites. I think
       | most browsers have been made to make standard http sites look
       | malicious to normal users.
        
         | mikeyouse wrote:
         | They're a nonprofit - so they can't be acquired like a typical
         | for-profit company. They could in theory sell some assets but
         | it'd be very convoluted if they were the core assets -- per US
         | tax law, nonprofit assets must remain in the nonprofit world,
         | so there's no risk of any tech company ruining them.
        
           | xandrius wrote:
           | I heard similar things about another American nonprofit and
           | now I'm not so sure about it. When money and will comes
           | along, loopholes come as well.
           | 
           | So, I wouldn't be so sure, unfortunately.
        
       | hbn wrote:
       | Yes let's. But that doesn't answer my question.
        
       | joshstrange wrote:
       | I still remember the original announcement around LE and thought
       | "Great idea, no idea if they'll be able to get buy-in from
       | browsers/etc", now I use it on all my self-hosted sites and will
       | probably be transitioning my employer over to it when we switch
       | to automated renewal sometime next year.
       | 
       | LE has been an amazing resource and every time I setup a new
       | website and get a LE cert I smile. Especially after having
       | lived/experienced the pain that was SSL/TLS before LE.
        
       | hinkley wrote:
       | The thing that has made me feel the oldest this week is that
       | someone I used to mentor posted a holiday pictures with visible
       | wrinkles. If people you think are young look old, then buddy,
       | check the mirror.
       | 
       | But this is a close second. 10 years? That can't be right. Even
       | accounting for Covid Time Dialation.
        
       | letsgetreal wrote:
       | Let's Encrypt allows anyone to have secure https communication,
       | sure, but it doesn't address the question of website
       | authenticity. I groan when I'm on an e-commerce site and I click
       | on the browser URL lock icon and see a Let's Encrypt certificate
       | because frankly anyone can create one for no cost and I don't
       | know if it's the real website or if I made a URL typo. Say what
       | you will about the expensive cert providers, but it's reassuring
       | when you see DigiCert or Sectigo - with a company name and the
       | address of the head office.
        
         | tptacek wrote:
         | It was never a reasonable goal of the WebPKI to authenticate
         | entities; only to help establish end-to-end encryption between
         | unrelated parties on the Internet. The WebPKI can ensure you're
         | talking to whoever controls `ycombinator.com`, but it has to be
         | up to some other layer of the security stack to decide whether
         | you _want_ to be talking to `ycombinator.com`. (This is in fact
         | part of the logic behind FIDO2 and phishing-proof
         | authentication).
        
           | letsgetreal wrote:
           | FIDO2 doesn't solve the first website contact trust problem -
           | only the HTTPS certificate does that.
        
             | tptacek wrote:
             | It's good to want things!
        
           | schoen wrote:
           | > It was never a reasonable goal of the WebPKI to
           | authenticate entities
           | 
           | The confusing thing is that this goal nonetheless appeared in
           | some original marketing and explanations about the web PKI
           | from the late 1990s when it was first introduced. There was
           | another smaller burst of this when people were arguing over
           | the formalization of DV certificates and of Google's UI
           | changes that stopped treating EV specially (as some people
           | found both of those changes objectionable).
           | 
           | I agree with you that the goal of authenticating entities was
           | impractical, but the mental association and expectation
           | around it still hasn't been completely dispelled. (I think I
           | saw some form of this when doing support on the Let's Encrypt
           | Community Forum, as people would sometimes complain that a
           | site shouldn't have been allowed to have a certificate,
           | either because it wasn't the organization they expected, or
           | because it was malicious somehow.)
        
             | tptacek wrote:
             | Right, and when people who haven't paid that much attention
             | to the machinations of the WebPKI (who could blame them)
             | talk about how weird it is that the browsers killed EV,
             | this is an important part of the backstory: EV was mostly a
             | failed attempt to make the WebPKI do this kind of "do-what-
             | I-mean" entity authentication.
             | 
             | The problem as I see it is: there simply isn't one coherent
             | global notion of what entity authentication means. It's
             | situational.
        
         | xandrius wrote:
         | Not really the point of ssl certs though. And I'm pretty sure
         | those limitations are the smallest hurdle, most people wouldn't
         | even care checking.
        
           | letsgetreal wrote:
           | The "most people won't care argument" doesn't inspire
           | confidence in the authenticity of the website.
           | 
           | It's essentially a self-signed cert that anyone could make
           | with the false security of a root certificate authority.
        
       | pedrozieg wrote:
       | It's easy to forget how awful TLS was before Let's Encrypt: you'd
       | pay per-hostname, file tickets, manually validate domains, and
       | then babysit a 1-year cert renewal calendar. Today it's basically
       | "install an ACME client once and forget it" and the web quietly
       | shifted from <30% HTTPS to ~80% globally and ~95% in the US in a
       | few years.
       | 
       | The impressive bit isn't just the crypto, it's that they attacked
       | the operational problem: automation (ACME), good client
       | ecosystem, and a nonprofit CA that's fine with being invisible
       | infrastructure. A boring, free cert became the default.
       | 
       | The next 10 years feel harder: shrinking lifetimes (45-day certs
       | are coming) means "click to install cert" can't exist anymore,
       | and there's still a huge long tail of internal dashboards, random
       | appliances, and IoT gear that don't have good automation hooks.
       | We've solved "public websites on Linux boxes," but not
       | "everything else on the network."
        
       | mmooss wrote:
       | Another amazing success born at Mozilla:
       | 
       | "The Let's Encrypt project was started in 2012 by two Mozilla
       | employees, Josh Aas and Eric Rescorla, together with Peter
       | Eckersley at the Electronic Frontier Foundation and J. Alex
       | Halderman at the University of Michigan."
       | 
       | https://en.wikipedia.org/wiki/Let%27s_Encrypt
       | 
       | What was Mozilla's role, beyond conception? Parenting? Care and
       | feeding? A roof?
        
       ___________________________________________________________________
       (page generated 2025-12-09 23:00 UTC)