news.volyx.in

10 Years of Let's Encrypt (letsencrypt.org)

817 points by SGran · 226 days ago · 349 comments on HN

Article summary

Let's Encrypt, a nonprofit certificate authority, has issued billions of free SSL/TLS certificates since its launch in 2015, making it the largest certificate authority in the world. The organization has played a significant role in increasing the prevalence of HTTPS encryption on the web, with the global percentage of encrypted connections rising from below 30% to around 80% over the past decade. Let's Encrypt's automated certificate issuance process has made it easy for website owners to obtain and renew certificates, contributing to the widespread adoption of HTTPS. The organization is celebrating its 10-year anniversary and reflecting on its achievements and future goals.

Main themes

  • Let's Encrypt anniversary
  • HTTPS encryption
  • Certificate authority
  • Web security
  • Nonprofit organization
  • Internet infrastructure

What commenters say

  • The widespread adoption of Let's Encrypt has made it easy to take web security for granted, with some arguing that it has become the new baseline for website development.
  • Some commenters feel that the push for universal HTTPS encryption has created unnecessary burdens for small websites or personal blogs that do not handle sensitive information.
  • Others argue that the benefits of HTTPS encryption, such as increased security and privacy, outweigh the costs and complexities of implementation, even for small websites.
  • There is a concern that the centralization of the web, with more information being hosted on social media platforms, may undermine the benefits of decentralized web infrastructure and increase the influence of large gatekeepers.
  • Some argue that the requirement for HTTPS encryption has become overly broad, applying to websites that do not require it, and that this has created unnecessary work and costs for website owners.
  • The use of Let's Encrypt has been seen as a key factor in the decline of plain HTTP traffic, with many commenters praising the organization's role in promoting web security.
  • There is a debate about the trade-offs between security, convenience, and decentralization, with some arguing that the benefits of security and convenience are worth the costs of increased centralization.
  • Some commenters feel that the browser manufacturers' push for universal HTTPS encryption has been overly aggressive, and that this has created problems for website owners who are not equipped to handle the technical requirements of HTTPS.