Hacker News new | ask | show | jobs
by iso1631 155 days ago
With a 6 day lifetime you'd typically renew after 3 days. If Lets Encrypt is down or refuses to issue then you'd have to choose a different provider. Your browser trusts many different "top of the chain" providers.

With a 30 day cert with renewal 10-15 days in advance that gives you breathing room

Personally I think 3 days is far too short unless you have your automation pulling from two different suppliers.

1 comments

Thank you, I missed the part with several "top of the chain" providers. So all of them would need to go down at the same time for things to really stop working.

How many "top of chain" providers is letsencrypt using? Are they a single point of failure in that regard?

I'd imagine that other "top of chain" providers want money for their certificates and that they might have a manual process which is slower than letsencrypt?

LE has 2 primary production data centers: https://letsencrypt.status.io/

But in general, one of the points of ACME is to eliminate dependence on a single provider, and prevent vendor lock-in. ACME clients should ideally support multiple ACME CAs.

For example, Caddy defaults to both LE and ZeroSSL. Users can additionally configure other CAs like Google Trust Services.

This document discusses several failure modes to consider: https://github.com/https-dev/docs/blob/master/acme-ops.md#if...

“Are they a single point of failure in that regard?”

It depends. If the ACME client is configured to only use Let’s Encrypt, then the answer is yes. But the client could fall-back to Google’s CA, ZeroSSL, etc. And then there is no single point of failure.

Makes sense. I assume each of them is in control and at the whims of US president?
It seems that currently most free CAs have a big presence in the US, and employ quite a few US employees.

ZeroSSL/HID Global seems to be quite multi-national though, and it’s owned by a Swedish company (Assa Abloy).

I don’t know what what kind of mitigations these orgs have in place if the shit really hits the fan in the US. It’s an interesting question for sure.

Fundamentally, Microsoft, Google and Apple are all run by American citizens living in America. Firefox is pretty much the same.

The US has strong institutions which prevent the President or Government at large controlling these on a whim. If those institutions fail then they could all push out an update which removes all "top of chain" trusted certificate authorities other than ones approved by the US government.

In that situation the internet is basically finished as it stands now, and the OSes would be non-trustworthy anyway.

Fixing the SSL problems is the easy part, the free world would push its own root certificate out -- which people would have to manually install from a trusted source, but that's nothing compared to the real problem.

Sure, Ubuntu, Suse etc aren't based in the US, but the number of phones without a US based OS is basically zero, you'd have to start from scratch with a forked version of android which likely has NSA approved backdoors in it anyway. Non-linux based machines would also need to be wiped.

> Makes sense. I assume each of them is in control and at the whims of US president?

Absolutely not.

If the president attempted to force a US-based CA to do something bad they don't want to do, they would sue the government. So far, this administration loses 80% of the lawsuits brought against it.

You're putting a lot of trust in US institutions (courts etc). The rest of the world is starting to see them as not a strong and independent as they were once assumed.

And that's before more overt issues. Microsoft/Google/etc could sue to stop the US ordering them to do what they should. Is the CEO really willing to risk their life to do that? Be a terrible shame if their kids got caught up in a traffic accident.

> You're putting a lot of trust in US institutions (courts etc)

I don't have a lot of trust in US institutions actually. The most powerful universities, corporations and law firms have capitulated to him.

So far, the tech companies have placated Trump by contributing to his causes and heaping praise upon him and not speaking out regarding the tariffs. That's enough for now.

> Is the CEO really willing to risk their life to do that?

We're not at that point; at least not so far. Besides, it's much easier to blackmail them for more money or for the Department of Justice to open an investigation or to stop a merger they want to do.

Also these companies aren't just sitting around doing nothing. Apple reworked their supply chain; all iPhones sold in the US are now made in India.

They are not in control of the US president.
I'm pretty sure that the .org TLD can be shut off by the US at any point in time.
Lets Encrypt do not control the US president.

You could argue that The Don in charge of the US is in control of letsencrypt

That’s not relevant though. These CAs will gladly give you a .se/.dk/.in/whatever cert as long as validation passes.