Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

He was probably talking about the centralised model used with CAs, and trying to start a discussion about an alternative to the CA model, probably some way of decentralised control, hence the bitcoin reference. Convergence [1] comes to mind.

[1] http://convergence.io/



I would be in favor of decentralised as well; nobody should have to pay money to some bunch of trolls just to use encryption; this is a friction point for a lot of newcomers to web development. In fact, making HTTPS free to use would probably be the best thing that could ever be done for cybersecurity for mankind. Make it zero-friction over HTTP, somehow.

Perhaps Google might want to sponsor this? :)


> In fact, making HTTPS free to use would probably be the best thing that could ever be done for cybersecurity for mankind

I guess we'll eventually get there, but unless we get decentralised I don't see how it could be done.


Let's encrypt works on the assumption that there is no reason why https certificate cannot be easy (not as cumbersome?) to use AND free of cost. They hope to start availability in the middle of this year. Free of cost is possible. We just need to make it easy, reliable, and repeatable for domain name owners to prove their ownership.

https://letsencrypt.org/


For the time being, use CloudFlare. They have SSL enabled even in the free plan.


CloudFlare is funded by the department of homeland security: http://thenextweb.com/insider/2011/06/07/cloudflare-a-websit...


Why is that a proper reply/




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: