Hacker News new | past | comments | ask | show | jobs | submit login

> This hasn't been true for years! Let's Encrypt provides free certificates to anyone with a domain.

Because they are the competition.




The point being that the monopoly's back has been broken. We're no longer in a situation where there needs to be >100 CAs for market competition purposes; there's now a free, universally available, public service.


Is LE really universally available? I'm not aware of them making any public commitment to serve unpopular websites (thinking of e.g. KiwiFarms), and they used to check an opaque Google blacklist before issuing certificates.


They list no stipulations about prohibited certificate uses[1]. Their restrictions on domain uses seem to be mostly tied to legal requirements (not issuing for sanctioned countries, for example). It's all also pretty transparent, from what I can tell[2][3]. Certainly more so than a normal CA.

[1]: https://letsencrypt.org/documents/isrg-cp-v3.3/#1.4.2-prohib...

[2]: https://letsdebug.net/

[3]: https://github.com/letsdebug/letsdebug




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: