news.volyx.in

Shortening the Let's Encrypt chain of trust (letsencrypt.org)

544 points by healsdata · 1143 days ago · 283 comments on HN

Article summary

Let's Encrypt is shortening its chain of trust by removing the cross-sign from IdenTrust's DST Root CA X3, which will expire on September 30th, 2024. This change may affect users of Android 7.0 or earlier, who may need to take action to ensure continued access to websites secured by Let's Encrypt certificates. The transition will roll out in stages, with the cross-sign no longer being provided by default as of February 8th, 2024, and being completely removed by June 6th, 2024. This change is expected to reduce the number of certificate bytes sent in a TLS handshake and lower operating costs.

Main themes

  • Let's Encrypt certificate management
  • Android device compatibility
  • TLS security and complexity
  • Alternative security solutions
  • Planned obsolescence and device updates
  • Software licensing and regulation
  • Certificate revocation and management

What commenters say

  • The impact of the change on Android users will be limited, affecting only a small percentage of devices.
  • The removal of the cross-sign is a necessary step to reduce the complexity and cost of certificate management.
  • Alternative security solutions, such as tcpcrypt, may be effective in protecting against passive attacks, but are not a replacement for TLS.
  • The brittleness of TLS is a significant problem, and solutions such as DANE or certificate updates outside of normal update paths may be necessary to address it.
  • The issue of planned obsolescence in devices is a major contributor to the problems with TLS, and manufacturers should be required to provide security updates for a longer period.
  • The idea of legally mandating software licensing policies, such as requiring manufacturers to open-source their software or provide refunds, is controversial and may have unintended consequences.
  • The use of opportunistic encryption schemes, such as tcpcrypt, may be useful in certain scenarios, such as local networks, but may not provide the same level of security as TLS.
  • The problem of certificate revocation is a difficult one, and solutions such as OCSP stapling or centralized push-based solutions may be necessary to address it.