MIDREAL

Let's Encrypt: 64-Day Certificate Lifetimes Coming Feb 2027

Comments

bombcar 4h ago on HN
At what point are we minting new certificates for each connection, and what does that mean for the original design?
Towaway69 3h ago on HN
The safest certificates are the ones that have expired before they were generated. Zombie Cat Quantum Security Corporation FTW!

/s

crote 52m ago on HN
You could also go straight for DANE and get rid of CAs entirely.
doublerabbit 2h ago on HN
I recently purchased an yearly wildcard SSL certificate and was notified that the certificate needs to be resigned every 200 days, why!?
CamperBob2 2h ago on HN
Because while the Internet and subsequently the WWW was conceived as a medium where all peers were treated equally and no centralized gatekeepers were required, this policy was widely viewed to be a Bad Idea in retrospect, treated as a bug, and fixed accordingly.
pixl97 1h ago on HN
Here's the thing, you can write your own applications and security to do anything you want. There is no gun being pointed at you to stop you, at least on PC.

Now, if you want to play with the world at large that's been dealing with security issue after security issue then you play by those rules.

You can't come to my game then get mad when I have a set of rules you don't like.

CamperBob2 1h ago on HN
my game
ocdtrekkie 1h ago on HN
Because the people on the CA/B Forum is doing security theater and doesn't have a practical view of security risks. But the tech companies that employ them view them as authorities and won't fire them for promoting dumb ideas.

The CA/B is the embodiment of the phrase "if all you have is a hammer, everything looks like a nail".

orf 1h ago on HN
To act as a forcing function to automate certificate issuance and rotation.

In aggregate this is a very good thing

crote 55m ago on HN
Because large organisations have demonstrated over time that they are fundamentally incapable of managing their certs effectively.

They usually grow enormous bureaucratic theatre around long-lived cert renewal, leaving them unable to do rapid rotation when it is required. And rather than getting their shit together, they prefer suing their CA to avoid revocation.

Given that those organisations 1) are crucial for day-to-day life (like banks, or the government), and 2) would have a giant blast radius when their certs are compromised, and 3) won't voluntarily change, the only remaining option to keep the ecosystem healthy is to force them by making complex rotation processes extremely painful and cumbersome to keep.

Hence: automated renewal, and boil the frog by slowly lowering the validity period.

Comments are loaded live from Hacker News and are not stored by Mid or Real.