Launching 2015: a New Certificate Authority To Encrypt the Entire Web
Peter Eckersley writes: Today EFF, Mozilla, Cisco, and Akamai announced a forthcoming project called Let's Encrypt. Let's Encrypt will be a certificate authority that issues free certificates to any website, using automated protocols (demo video here). Launching in summer 2015, we believe this will be the missing piece that deprecates the woefully insecure HTTP protocol in favor of HTTPS.
how can one verify that this future "certificate authority that issues free certificates to any website" hasn't issued a cert to the NSA for your domain? is it possible?
We already have a free certificate autority: CAcert. The problem is that their root certificate is not included by default in major web browsers. Why would that be any different? I guess since Mozilla is involved Firefox will get it. But why don't just they allow CAcert? And what about Google and Microsoft?
Horseshit.
Some things they just keep secret.
Other things, they commit perjury and perform parallel construction to hide how they got it in the first place.
In other words, they don't need no steenking warrants, they don't need to care about the law, and will do anything they see fit.
They can take care of the pretense of following the law much later.
I'm long past believing they give a damn about needing to prove they obtained stuff legally.
Lost at C:>. Found at C.
This is a fantastic effort that will help people such as myself. I run sites across a dozen or so hosts, but they don't generate income and I really don't want to drop all that money into certificates. If I can get free certificates from a good CA then I'll gladly bump all my sites over to HTTPS.
Thank you!
Love sees no species.
Replace Cisco, and Akamai and then maybe I'll be convinced it's better than the current situation. But it's still oxymoronic service: A central authority that *REQUIRES* trust for people who don't trust anybody.
And what do you do for countries with draconian Cert laws like England? (They want a copy of your root cert)
The resulting entity would have to be incorporated in Iceland or something. FAR away from 5-eye's dragnets.
Obama's legacy: (N)othing (S)ecure (A)nywhere and (T)error (S)imulation (A)dministration
Where do you think there's an honest government?
This is supposed to be an alternative to just using plain HTTP. If you are already paying for a cert from a CA you trust, then this doesn't target you. Even if a couple parties have the key, it's still protects you from all of the others that don't. The whole point is that it's better than nothing. I have a personal website that doesn't do too much and I'd put https on it if I didnt have to pay for a key.