Hacker News new | ask | show | jobs
by altairprime 534 days ago
Let’s Encrypt is focusing on other concerns next year but noted that donations are what funds their ability to progress:

https://letsencrypt.org/2024/12/11/eoy-letter-2024/

As with any donation-supported venture, their ability to consider “someday” concerns is directly tied to donations and sponsorships. Reading between the lines of the recent revocation shutdown, I estimate their operating budget does not have room to consider PQC, when they have more pressing concerns to focus on.

So, their disinterest in PQC does not likely inform on whether others should do PQC or not; to each their own risk assessments, etc.

1 comments

What is addressed recently by NIST, Cloudflare, Google, Apple, and others primarily involves potential(?) weaknesses in TLS key exchange & asymmetric cryptography. Let's Encrypt is more about certificates, I think, no?
The cert gives assurance the right endpoint has been reached to bootstrap tls. So arguably its part of the attack surface. The tls key exchange may not have direct dependency but it has some indirect? Clearly the on the wire pki used to establish emphemeral session keys would be the main issue and that is down to the webserver and browser not letsencrypt.