Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Question: any possible case of bad apples that make let's encrypt suddenly lose their trust? Eg bcoz it's free, it's used by "bad guys" just like .info tld.


The purpose of Let's Encrypt, and the SSL certificate infrastructure in general, isn't to prevent "bad guys" from getting certificates. It's to ensure that if you own the box, the certificate verifies that a web client is speaking directly to that box with nothing in between. (Or more generally, directly to an authorized end point by the owner of that DNS entry. Authority can be delegated.)

In other words, it keeps bad guys out of the middle, not the end point. That's all SSL can do, even if it works perfectly. Bad guys will still own end points, in both the conventional sense of the word own and the pwning sense of the word own. SSL can not (directly) do much about that. If you speak SSL to a bad actor, well, there aren't any other actors between you and the bad actor, but you're still speaking on an encrypted, authenticated channel to a bad actor.

This is in contrast to the DNS infrastructure in which it is sensible for a TLD owner to attempt to prevent "people they don't want on their TLD" (more generally than "bad guys" since a lot of the restrictions enforced are far beyond that).


Source?

I remember reports in the past decrying CAs for issuing certificates for phishing sites in the style of "gooogle.com" etc.


Some in the industry, including some CAs (Certificate Authorities), believe that issuing certificates to "malicious" websites should be against the rules of the CA/B Forum, the industry body that sets guidelines for CA behavior.

You are right that some news articles and reports continue to chastise CAs who issue to sites in the style of "gooogle.com". Do not let them trick you - that is only their opinion on the matter. It is NOT against the industry rules to issue those certificates.[1]

What IS against the rules is to issue a certificate for "domain.com" to someone who has not proven ownership of "domain.com". That is the BIG no-no that leads to consequences such as being un-trusted. There are standardized methods for meeting the burden of proof, and every CA uses more or less the same mechanisms to do so.

Let's Encrypt, or any CA, may issue a certificate to "paaypal.com". Even if that site was a Paypal phishing site, a CA is under no obligation to revoke the certificate or prevent that user from getting another certificate.

Some CAs CHOOSE to do this. To some extent, I think it is sensible to try to thwart malicious use. However, the case is often made that CAs and SSL certificates are not meant to "police content", and furthermore, that they are not very effective at doing so.

Flagging a malicious site through a tool like Google's SafeBrowsing is significantly more effective than revoking their SSL certificate.

[1] Except for a more recent stipulation that Microsoft added to their root program. If they request the revocation of a certificate they believe is malicious, the CA is expected to comply. If they dont, they are only at risk of being punished by Microsoft.


That's properly understood as a variant of getting a certificate of a domain you don't own, for practical purposes. And the point there is still that the "bad guys" shouldn't be able to get a cert that appears to identify them as Google, not that the bad guys can't get a cert. It's two different things. It is not a bug for Let's Encrypt to hand out certs to "bad" people.


That's fair and makes sense. Still, do you have a source for that type of CA policy? With all due respect, I can't tell if this is just your opinion or a codified threat model.


If Comodo and Symantec are able to retain their trust status, then Let's Encrypt most certainly can.


Do you mean .tk? AFAIK .info costs money.


Yes, but it's usually cheaper.


what's wrong with the .info tld?


People distrust it because it's 99% spam?


.info is really not all that bad, in the grand scheme of things. .biz is much worse (and has been since its launch in 2001!), and some of the new TLDs like .top and .xyz have been abused pretty heavily as well.


I actually like the .info tld... perfect domain for "informational" websites, wikis etc. Though there may be better ones with the recent goldrush of new tlds available.

Though I also liked .io, and felt the higher pricing and harder registration kept a lot of the squatters away.


I think there are 2 factors. 1) Do LE do a good job of ensuring that they only grant certificates to domain holders. 2) Do they do a good job of representing what they're signing (authentication versus identification http://imgur.com/a/fAaYH)

The certificate is a kind of "encryption only" certificate, it's treated as a second class citizen (you might get a grey lock for example) so it's encrypting the communication but it's not very useful for convincing you that you're talking to your bank when you aren't.

Of course if LE don't do a good job of (1) then we're f*ed because they'll issue certificates to bad actors and LE have a hard job because now they're trusted they're a good target for DNS cache poisoning etc.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: