Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The whole "Let's Encrypt should solve all your problems" attitude is arrogant and short-sighted.

1) In my experience the user experience even for technical admins is still flakey on at least some popular platforms. In other words, it's not as incredible as you think.

2) It's not available to a host that doesn't connect to the internet but does occasionally get connected to by a local browser (eg. IoT firewalled inside my LAN is one obvious such case; I'm sure there are others).

And most importantly:

3) You'd have to be insane or naive to accept an architecture that leaves you dependant on a single vendor (especially if you need that vendor more than they need you!).



How fortunate, then, that LE isn't the only vendor. Not even the only ACME vendor, nor the only free vendor (https://zerossl.com/features/acme/).


If your device never connects to the internet then how would any public cert work? It would expire like any other?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: