Would like to see them working more with TLD operators here, I'd like to see a CA partner with TLD ops to offer distributed and resilient issuance (especially with shorter cert lifetimes) with intermediate certificates locked to their TLDs, TLD operators are already a significant part of the chain of trust since it's all based on DNS today.
It makes sense for them to issue their own certificates because it’s inline with the rest of their offerings, but it seems kind of strange you can just buy someone else’s root certificate and issue under their name. It kind of defeats the point of trusting the root. What if a bad actor starting buying up authorities? You could compromise a bunch of services without them even knowing.
There are a whole host of controls in place to mitigate this risk. Plus such an acquisition wouldn't be easy to keep secret, so as soon as an untrusted actor acquired control over a root, the CAB would likely immediately distrust the cert.
Not a huge difference between buying the root cert itself and getting a cross-sign. LE started out with cross-signs from Identrust.
"On October 19, 2015, the intermediate certificates became cross-signed by IdenTrust, causing all certificates issued by Let's Encrypt to be trusted by all major browsers."
Capitalism, starting the moment TLD registrars first bid for the monopoly to charge rent. And continuing today, where I think only Cloudflare offer below or at cost domain registration, charging nothing themselves and just passing on the other mandatory fees to the rent seekers. It has had centralization at its heart since the beginning, when someone had to allocate IP addresses and everyone else had to agree (or we would have internets and not The Internet), which enabled this. I wonder if it would have turned out differently if, instead of central IP address allocation, clients had generated a UUID and it was accepted on The Internet unless consensus agreed it wasn't unique? But I don't think we knew how to do that then and technical limitations. Heck, crypto export laws would have killed it and required a central authority to prove that a UUID was you and not an imposter.
Why does every criticism of CloudFlare ignore the fact that they mitigate the largest DDoSes in the world in an age where DDoS-for-hire cost only a few dollars per minute? Nobody could do that on the budget of a 1996 local ISP with one or 2 part-time IT techs.
CloudFlare was launched as a stupid-simple CDN, but DDoS mitigation and bot reduction are actually valuable features for many websites. Sure, CF isn't the only business in this space, but most of their rivals are large enough to be in the S&P500 / Russell 2000, so it's not like garage startups are competing for this business.
"Was meant to be"
This isn't a law of physics. This was a starry-eyed hope by techno-utopians and academics when the internet was still 100% funded by Uncle Sam. When the internet moved out of its parents' basement, it had to grow up and get a job to pay the bills. Some people are fine with a SquareSpace webpage instead of running their own custom Apache httpd website on bare metal in a colo like it's 2005. The cost of maintenance and cognitive load is a cost we shouldn't ignore.
It turns out that economies of scale exist. The Internet doesn't need 10,000 small CDNs and they would all be inefficient and expensive if that was the distribution. Instead, there are a few large ones that can afford to colo in many geographically dispersed data centers and who negotiated bandwidth peering contracts for advantageous pricing.
No they did, but they changed their mind once people spoke out against it. They thought free speech absolutism would be good for PR, but it turns out that the general public hates bad people enough not to care.
As always, I am worried to see Cloudflare and Google Chrome -- two of the internet's biggest/worst monopolies -- working so closely together like this. Cloudflare is already undergoing enshittification, like banning all automation by default that hasn't undergone privacy-invasive certification procedures (they recently started calling disallowed bots "AI Training", but that doesn't change anything -- you still have to be on a whitelist in order to be allowed). I have no doubt that in the near future, they will release some kind of ID verification and then the vast majority of the internet is simply done.
That's not my point. Cloudflare is blocking all unregistered automation as "AI Training" by default. My guess is we will see almost no one changing that default, as opposed to the inverse where only some sites will be forced to enable the blocks. Opt-out is a very bad model for things like this because it heavily hurts users (especially assistive users) while most websites won't have a strong enough opinion to even consider it.
I don't think we will see Cloudflare enabling an "age assurance" requirement by default. I feel like I could trust them slightly more than a site operator, depending on how it's performed, but I also feel like it would be very easy for them to do much, much worse than any site operator, due to the inherent power of being a GAA. (Global Active Adversary, to those not familiar)
Me too, just add my root and you'll never be warned again!
You have access to unlimited free certificates based on DNS delegation through this method, but need more.
It might be useful to explain why this adds value that another CA can't
Would like to see them working more with TLD operators here, I'd like to see a CA partner with TLD ops to offer distributed and resilient issuance (especially with shorter cert lifetimes) with intermediate certificates locked to their TLDs, TLD operators are already a significant part of the chain of trust since it's all based on DNS today.
It makes sense for them to issue their own certificates because it’s inline with the rest of their offerings, but it seems kind of strange you can just buy someone else’s root certificate and issue under their name. It kind of defeats the point of trusting the root. What if a bad actor starting buying up authorities? You could compromise a bunch of services without them even knowing.
There are a whole host of controls in place to mitigate this risk. Plus such an acquisition wouldn't be easy to keep secret, so as soon as an untrusted actor acquired control over a root, the CAB would likely immediately distrust the cert.
https://cabforum.org/working-groups/server/baseline-requirem...
Not a huge difference between buying the root cert itself and getting a cross-sign. LE started out with cross-signs from Identrust.
"On October 19, 2015, the intermediate certificates became cross-signed by IdenTrust, causing all certificates issued by Let's Encrypt to be trusted by all major browsers."
The internet was meant to be a decentralized network. Why are humans so narrow minded short-termists?
Key signing parties don’t scale.
Evolution & the illusion of the separate self.
Capitalism, starting the moment TLD registrars first bid for the monopoly to charge rent. And continuing today, where I think only Cloudflare offer below or at cost domain registration, charging nothing themselves and just passing on the other mandatory fees to the rent seekers. It has had centralization at its heart since the beginning, when someone had to allocate IP addresses and everyone else had to agree (or we would have internets and not The Internet), which enabled this. I wonder if it would have turned out differently if, instead of central IP address allocation, clients had generated a UUID and it was accepted on The Internet unless consensus agreed it wasn't unique? But I don't think we knew how to do that then and technical limitations. Heck, crypto export laws would have killed it and required a central authority to prove that a UUID was you and not an imposter.
Why does every criticism of CloudFlare ignore the fact that they mitigate the largest DDoSes in the world in an age where DDoS-for-hire cost only a few dollars per minute? Nobody could do that on the budget of a 1996 local ISP with one or 2 part-time IT techs.
CloudFlare was launched as a stupid-simple CDN, but DDoS mitigation and bot reduction are actually valuable features for many websites. Sure, CF isn't the only business in this space, but most of their rivals are large enough to be in the S&P500 / Russell 2000, so it's not like garage startups are competing for this business.
"Was meant to be"
This isn't a law of physics. This was a starry-eyed hope by techno-utopians and academics when the internet was still 100% funded by Uncle Sam. When the internet moved out of its parents' basement, it had to grow up and get a job to pay the bills. Some people are fine with a SquareSpace webpage instead of running their own custom Apache httpd website on bare metal in a colo like it's 2005. The cost of maintenance and cognitive load is a cost we shouldn't ignore.
It turns out that economies of scale exist. The Internet doesn't need 10,000 small CDNs and they would all be inefficient and expensive if that was the distribution. Instead, there are a few large ones that can afford to colo in many geographically dispersed data centers and who negotiated bandwidth peering contracts for advantageous pricing.
Except they protect the same people running DDoS services...
No they did, but they changed their mind once people spoke out against it. They thought free speech absolutism would be good for PR, but it turns out that the general public hates bad people enough not to care.
This is BS. One quick google and selecting a result from the first page: https://zeusstress.com/
Surprise! It's on crimeflare.
Just say no. Cloudflare should not be the gatekeeper for the internet.
Who do you like to go with for certs?
I personally recommend Voldemort. His snakelike demeanour and disregard for human life impresses me with a sense of ominous authority!
Totally not a single point of failure for the whole Internet.
As always, I am worried to see Cloudflare and Google Chrome -- two of the internet's biggest/worst monopolies -- working so closely together like this. Cloudflare is already undergoing enshittification, like banning all automation by default that hasn't undergone privacy-invasive certification procedures (they recently started calling disallowed bots "AI Training", but that doesn't change anything -- you still have to be on a whitelist in order to be allowed). I have no doubt that in the near future, they will release some kind of ID verification and then the vast majority of the internet is simply done.
A bot owners enshittification is a site admins salvation. The toggle is trivial to turn on or off. What will site admins do I wonder?
That's not my point. Cloudflare is blocking all unregistered automation as "AI Training" by default. My guess is we will see almost no one changing that default, as opposed to the inverse where only some sites will be forced to enable the blocks. Opt-out is a very bad model for things like this because it heavily hurts users (especially assistive users) while most websites won't have a strong enough opinion to even consider it.
I don't think we will see Cloudflare enabling an "age assurance" requirement by default. I feel like I could trust them slightly more than a site operator, depending on how it's performed, but I also feel like it would be very easy for them to do much, much worse than any site operator, due to the inherent power of being a GAA. (Global Active Adversary, to those not familiar)
Interesting, but the article would be far more enjoyable to read if it weren’t clearly written by Claude.