Rendered at 21:07:52 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
schoen 3 minutes ago [-]
I've worked with Let's Encrypt (I mean inside the organization, not just as an end user) a bunch and I feel like I often know or can guess rationales for things, but while I know "why short-lived certs", I surely don't know "why 64".
Is it because it's a round number in binary?
doublerabbit 3 hours ago [-]
I recently purchased an yearly wildcard SSL certificate and was notified that the certificate needs to be resigned every 200 days, why!?
crote 1 hours ago [-]
Because large organisations have demonstrated over time that they are fundamentally incapable of managing their certs effectively.
They usually grow enormous bureaucratic theatre around long-lived cert renewal, leaving them unable to do rapid rotation when it is required. And rather than getting their shit together, they prefer suing their CA to avoid revocation.
Given that those organisations 1) are crucial for day-to-day life (like banks, or the government), and 2) would have a giant blast radius when their certs are compromised, and 3) won't voluntarily change, the only remaining option to keep the ecosystem healthy is to force them by making complex rotation processes extremely painful and cumbersome to keep.
Hence: automated renewal, and boil the frog by slowly lowering the validity period.
orf 2 hours ago [-]
To act as a forcing function to automate certificate issuance and rotation.
In aggregate this is a very good thing
ocdtrekkie 25 minutes ago [-]
It will merely mean any given legitimate certificate is indistinguishable from a newly minted malicious one.
orf 21 minutes ago [-]
As it is now then?
CamperBob2 3 hours ago [-]
Because while the Internet and subsequently the WWW was conceived as a medium where all peers were treated equally and no centralized gatekeepers were required, this policy was widely viewed to be a Bad Idea in retrospect, treated as a bug, and fixed accordingly.
pixl97 2 hours ago [-]
Here's the thing, you can write your own applications and security to do anything you want. There is no gun being pointed at you to stop you, at least on PC.
Now, if you want to play with the world at large that's been dealing with security issue after security issue then you play by those rules.
You can't come to my game then get mad when I have a set of rules you don't like.
CamperBob2 2 hours ago [-]
my game
pixl97 7 minutes ago [-]
Right, set up your own game table and you get to make the rules.
That or either get a democracy to agree with you and vote, or become a dictator.
ocdtrekkie 2 hours ago [-]
Because the people on the CA/B Forum is doing security theater and doesn't have a practical view of security risks. But the tech companies that employ them view them as authorities and won't fire them for promoting dumb ideas.
The CA/B is the embodiment of the phrase "if all you have is a hammer, everything looks like a nail".
sekinfo 3 hours ago [-]
[dead]
bombcar 5 hours ago [-]
At what point are we minting new certificates for each connection, and what does that mean for the original design?
crote 1 hours ago [-]
You could also go straight for DANE and get rid of CAs entirely.
Towaway69 4 hours ago [-]
The safest certificates are the ones that have expired before they were generated. Zombie Cat Quantum Security Corporation FTW!
Is it because it's a round number in binary?
They usually grow enormous bureaucratic theatre around long-lived cert renewal, leaving them unable to do rapid rotation when it is required. And rather than getting their shit together, they prefer suing their CA to avoid revocation.
Given that those organisations 1) are crucial for day-to-day life (like banks, or the government), and 2) would have a giant blast radius when their certs are compromised, and 3) won't voluntarily change, the only remaining option to keep the ecosystem healthy is to force them by making complex rotation processes extremely painful and cumbersome to keep.
Hence: automated renewal, and boil the frog by slowly lowering the validity period.
In aggregate this is a very good thing
Now, if you want to play with the world at large that's been dealing with security issue after security issue then you play by those rules.
You can't come to my game then get mad when I have a set of rules you don't like.
That or either get a democracy to agree with you and vote, or become a dictator.
The CA/B is the embodiment of the phrase "if all you have is a hammer, everything looks like a nail".
/s