Twelve years after launching Universal SSL, Cloudflare is applying to become a certificate authority.

45 points•ewpratten•1 day ago•26 comments•

26 comments

vg1 day ago
A very welcome move because for years Cloudflare has freeloaded certs from Let's Encrypt without sponsoring Let's Encrypt finacially. Though Cloudflare has contributed in otherwise to the ecosystem like by running CT logs etc.

Now, it looks like WebPKI is going to fracture into two regarding PQ Crypto. With Google (GTS and Chrome), Cloudflare and Let's Encrypt all preferring MTC and legacy CA's like Digicert, Sectigo, Globalsign all heading towards non MTC.

If Cloudflare would not have decied to become a PQ CA for MTC. We would have a duopoly with GTS and Let's Encrypt. This is a worse off situation. Therefore I welcome Cloudflare CA for MTC.

Also, its not like they are going to make any money of the CA business if they are going to issue DV certs for free. It will reduce the pressure on Let's Encrypt from carrying the burden of securing 60% of the world's webistes.

sneakabout 15 hours ago
> A very welcome move because for years Cloudflare has freeloaded certs from Let's Encrypt without sponsoring Let's Encrypt finacially.

It's not freeloading to accept a gift freely given. I'm sure the people who do fund LE are happy to see the world's largest TLS terminator using LE certs to secure the web - that is and was the whole point of LE in the first place. It's being used as intended.

Would like to see them working more with TLD operators here, I'd like to see a CA partner with TLD ops to offer distributed and resilient issuance (especially with shorter cert lifetimes) with intermediate certificates locked to their TLDs, TLD operators are already a significant part of the chain of trust since it's all based on DNS today.
vg1 day ago
What you are proposing sounds like DANE with TLSA and DNSSec. Great idea but most CC TLDs are still using 1024 RSA ZSKs. Right now PQ DNSSEC is very uncertain. PQ DNSSEC will likely take about 5 more years or so to standardise. And thats too late for companies like Google and Cloudlfare which want to go PQ Crypto by 2029.
phillipseamoreabout 19 hours ago
No, I'm proposing that TLD can handle issuance themselves since they technically have 100% control over domains under their TLDs anyways. I think this might be important when we look at a combination of short (and getting shorter) lifetimes for end-user certificates and increasing volatility of the world (cyberattacks, sabotage and war). It would be desirable for ccTLD's specifically to be able to maintain certificate issuance even though the country was virtually or physically isolated from the rest of the world. (Which DANTE could/would have mitigated but is not my proposal here)
It makes sense for them to issue their own certificates because it’s inline with the rest of their offerings, but it seems kind of strange you can just buy someone else’s root certificate and issue under their name. It kind of defeats the point of trusting the root. What if a bad actor starting buying up authorities? You could compromise a bunch of services without them even knowing.
Tomteabout 23 hours ago
It is, but that‘s why I trust Honest Achmed (https://bugzilla.mozilla.org/show_bug.cgi?id=647959). He is a man of integrity and will not be bought!
Not a huge difference between buying the root cert itself and getting a cross-sign. LE started out with cross-signs from Identrust.

"On October 19, 2015, the intermediate certificates became cross-signed by IdenTrust, causing all certificates issued by Let's Encrypt to be trusted by all major browsers."

evan_a_a1 day ago
There are a whole host of controls in place to mitigate this risk. Plus such an acquisition wouldn't be easy to keep secret, so as soon as an untrusted actor acquired control over a root, the CAB would likely immediately distrust the cert.

https://cabforum.org/working-groups/server/baseline-requirem...

vg1 day ago
CAB has nothing to do with trust/distrust here. Its the Root CA Store Operators (Mozilla, Google, Apple, Microsoft, Adobe) which have to distrust here.
vg1 day ago
Google (GTS) has done the same. GTS controls GlobalSign R4. GlobalSign R4 was a root cert which was created by GlobalSign and later sold to Google.

If a bad actor starts buying up CA's, then very quickly that CA would be distrusted by Root Cert Store Operators. No different than what happened with DigiNotr and Entrust.

abofh1 day ago
Me too, just add my root and you'll never be warned again!

You have access to unlimited free certificates based on DNS delegation through this method, but need more.

It might be useful to explain why this adds value that another CA can't

vgabout 20 hours ago
Are you as honest as Honest Achmed? (https://bugzilla.mozilla.org/show_bug.cgi?id=647959)
bossyTeacher1 day ago
The internet was meant to be a decentralized network. Why are humans so narrow minded short-termists?
thephyber1 day ago
Why does every criticism of CloudFlare ignore the fact that they mitigate the largest DDoSes in the world in an age where DDoS-for-hire cost only a few dollars per minute? Nobody could do that on the budget of a 1996 local ISP with one or 2 part-time IT techs.

CloudFlare was launched as a stupid-simple CDN, but DDoS mitigation and bot reduction are actually valuable features for many websites. Sure, CF isn't the only business in this space, but most of their rivals are large enough to be in the S&P500 / Russell 2000, so it's not like garage startups are competing for this business.

"Was meant to be"

This isn't a law of physics. This was a starry-eyed hope by techno-utopians and academics when the internet was still 100% funded by Uncle Sam. When the internet moved out of its parents' basement, it had to grow up and get a job to pay the bills. Some people are fine with a SquareSpace webpage instead of running their own custom Apache httpd website on bare metal in a colo like it's 2005. The cost of maintenance and cognitive load is a cost we shouldn't ignore.

It turns out that economies of scale exist. The Internet doesn't need 10,000 small CDNs and they would all be inefficient and expensive if that was the distribution. Instead, there are a few large ones that can afford to colo in many geographically dispersed data centers and who negotiated bandwidth peering contracts for advantageous pricing.

jartabout 23 hours ago
They're good at stopping DDOS but they've never been the best at it. What Cloudflare has always done best is making SSL and DNSSEC as frictionless and pain free as possible. If TrustCor was trustworthy enough to be allowed to operate a root certificate authority out of a UPS Store at a strip mall in Toronto, then why not Cloudflare? The thing we've always wanted for the Internet is DNSSEC https://youtu.be/b9j-sfP9GUU which the major players like Google have stubbornly sought to avoid. Ideally Cloudflare would help enough websites adopt it that it'll become more practical for the rest of us to use.
edelbitterabout 17 hours ago
> they mitigate the largest DDoSes in the world

> DDoS-for-hire cost only a few dollars per minute

I imagine those two are closely related. If not for Cloudflare and similar offers, we would spend more effort & resources on non-symptomatic treatment of internet-scale bad actors and its enablers (lately, more under-maintained "smart" devices than dumb modems, I hear). Every unresolved-for-years botnet is excellent advertising for CF, and they are not even paying for it. (We are all paying for it, dearly.)

bhhaskin1 day ago
Except they protect the same people running DDoS services...
nottorpabout 20 hours ago
... because some people can think long term ...
aseippabout 15 hours ago
You could also make the alternative argument: the internet as a truly decentralized network as imagined by nerds was never going to actually work due to its (now obvious) impact on the political economy of the world and its actors, and because fundamentally centralized economies of scale are how humans tend to organize society. So why are internet nerds on forums so narrow minded that they don't read understand this, because they don't read books? But both of these "arguments" are pointless posts designed to get head-pats, because everyone has made up their mind. Buy your DV certs from another ACME provider.
stubish1 day ago
Capitalism, starting the moment TLD registrars first bid for the monopoly to charge rent. And continuing today, where I think only Cloudflare offer below or at cost domain registration, charging nothing themselves and just passing on the other mandatory fees to the rent seekers. It has had centralization at its heart since the beginning, when someone had to allocate IP addresses and everyone else had to agree (or we would have internets and not The Internet), which enabled this. I wonder if it would have turned out differently if, instead of central IP address allocation, clients had generated a UUID and it was accepted on The Internet unless consensus agreed it wasn't unique? But I don't think we knew how to do that then and technical limitations. Heck, crypto export laws would have killed it and required a central authority to prove that a UUID was you and not an imposter.
zoobababout 15 hours ago
Because some people want power, and abuse it.
N_Lens1 day ago
Evolution & the illusion of the separate self.

Read the full thread on Hacker News →

Related stories