Twelve years after launching Universal SSL, Cloudflare is applying to become a certificate authority.
26 comments
Now, it looks like WebPKI is going to fracture into two regarding PQ Crypto. With Google (GTS and Chrome), Cloudflare and Let's Encrypt all preferring MTC and legacy CA's like Digicert, Sectigo, Globalsign all heading towards non MTC.
If Cloudflare would not have decied to become a PQ CA for MTC. We would have a duopoly with GTS and Let's Encrypt. This is a worse off situation. Therefore I welcome Cloudflare CA for MTC.
Also, its not like they are going to make any money of the CA business if they are going to issue DV certs for free. It will reduce the pressure on Let's Encrypt from carrying the burden of securing 60% of the world's webistes.
It's not freeloading to accept a gift freely given. I'm sure the people who do fund LE are happy to see the world's largest TLS terminator using LE certs to secure the web - that is and was the whole point of LE in the first place. It's being used as intended.
"On October 19, 2015, the intermediate certificates became cross-signed by IdenTrust, causing all certificates issued by Let's Encrypt to be trusted by all major browsers."
https://cabforum.org/working-groups/server/baseline-requirem...
If a bad actor starts buying up CA's, then very quickly that CA would be distrusted by Root Cert Store Operators. No different than what happened with DigiNotr and Entrust.
You have access to unlimited free certificates based on DNS delegation through this method, but need more.
It might be useful to explain why this adds value that another CA can't
CloudFlare was launched as a stupid-simple CDN, but DDoS mitigation and bot reduction are actually valuable features for many websites. Sure, CF isn't the only business in this space, but most of their rivals are large enough to be in the S&P500 / Russell 2000, so it's not like garage startups are competing for this business.
"Was meant to be"
This isn't a law of physics. This was a starry-eyed hope by techno-utopians and academics when the internet was still 100% funded by Uncle Sam. When the internet moved out of its parents' basement, it had to grow up and get a job to pay the bills. Some people are fine with a SquareSpace webpage instead of running their own custom Apache httpd website on bare metal in a colo like it's 2005. The cost of maintenance and cognitive load is a cost we shouldn't ignore.
It turns out that economies of scale exist. The Internet doesn't need 10,000 small CDNs and they would all be inefficient and expensive if that was the distribution. Instead, there are a few large ones that can afford to colo in many geographically dispersed data centers and who negotiated bandwidth peering contracts for advantageous pricing.
> DDoS-for-hire cost only a few dollars per minute
I imagine those two are closely related. If not for Cloudflare and similar offers, we would spend more effort & resources on non-symptomatic treatment of internet-scale bad actors and its enablers (lately, more under-maintained "smart" devices than dumb modems, I hear). Every unresolved-for-years botnet is excellent advertising for CF, and they are not even paying for it. (We are all paying for it, dearly.)
Read the full thread on Hacker News →
Related stories
- The Verge · 0 points · 5 days ago
- Show HN: Last Internet Connectiongithub.comHacker News · 1 points · 8 days ago
- Hacker News · 2 points · 7 days ago
- Hacker News · 60 points · 13 days ago
- Measure internet censorshipooni.orgHacker News · 218 points · 11 days ago
- Hacker News · 1 points · 8 days ago