Hacker News new | ask | show | jobs
by phasmantistes 821 days ago
I'm super excited about Sunlight. The CT ecosystem is really fragile right now, with current log implemetations being expensive to operate and very difficult to operate correctly, as evidenced by the recent failures of multiple logs[1][2]. And if too many logs fall over, it becomes infeasible to include the requisite number of SCTs in certificates, or worse, already-issued certificates can become effectively untrusted.

If Sunlight reduces costs by a couple orders or magnitude and significantly reduces deployment complexity -- both of which it seems to do successfully -- it will be a huge boon to the whole ecosystem. I really hope browsers accept sunlight logs as trusted in the near future.

[1]: https://groups.google.com/a/chromium.org/g/ct-policy/c/6mvSo... [2]: https://groups.google.com/a/chromium.org/g/ct-policy/c/_dhkS...