logoalt Hacker News

toomuchtodotoday at 6:35 PM2 repliesview on HN

They could stand up their own version of Let's Encrypt with less than 20 people and $5M/year. It is inevitable. Let's Encrypt had a budget of $3.6M and 13 employees as of 2019 [1], but I don't have recent funding and staff figures as of this comment (replies with context welcome!). Probably spread the cost across the BRICS to make it US sanction resistant.

[1] https://news.ycombinator.com/item?id=24085559 (citations)


Replies

misanotoday at 6:51 PM

It’s not merely about setting up a CA. The CA certificates would have to be added to the trust stores of every operating system, browser, framework, and application, creating a sea of security risks for the public. It’s an isolated, privacy-invasive process.

show 1 reply
lxgrtoday at 6:54 PM

Sure they can, but very importantly, so far the US has not forced them to for extremely good reasons.

As just one example, you can take a guess as to whether such a CA will support certificate transparency...