logoalt Hacker News

Building a certificate authority for the whole Internet

46 points • by ewpratten • yesterday at 1:44 PM • 28 comments • view on HN

Comments

vg • today at 3:48 AM

A very welcome move because for years Cloudflare has freeloaded certs from Let's Encrypt without sponsoring Let's Encrypt finacially. Though Cloudflare has contributed in otherwise to the ecosystem like by running CT logs etc.

Now, it looks like WebPKI is going to fracture into two regarding PQ Crypto. With Google (GTS and Chrome), Cloudflare and Let's Encrypt all preferring MTC and legacy CA's like Digicert, Sectigo, Globalsign all heading towards non MTC.

If Cloudflare would not have decied to become a PQ CA for MTC. We would have a duopoly with GTS and Let's Encrypt. This is a worse off situation. Therefore I welcome Cloudflare CA for MTC.

Also, its not like they are going to make any money of the CA business if they are going to issue DV certs for free. It will reduce the pressure on Let's Encrypt from carrying the burden of securing 60% of the world's webistes.

phillipseamore • yesterday at 5:43 PM

Would like to see them working more with TLD operators here, I'd like to see a CA partner with TLD ops to offer distributed and resilient issuance (especially with shorter cert lifetimes) with intermediate certificates locked to their TLDs, TLD operators are already a significant part of the chain of trust since it's all based on DNS today.

MisterMunchkin • yesterday at 2:37 PM

It makes sense for them to issue their own certificates because it’s inline with the rest of their offerings, but it seems kind of strange you can just buy someone else’s root certificate and issue under their name. It kind of defeats the point of trusting the root. What if a bad actor starting buying up authorities? You could compromise a bunch of services without them even knowing.

➕ show 2 replies
abofh • today at 3:13 AM

Me too, just add my root and you'll never be warned again!

You have access to unlimited free certificates based on DNS delegation through this method, but need more.

It might be useful to explain why this adds value that another CA can't

bossyTeacher • yesterday at 8:04 PM

The internet was meant to be a decentralized network. Why are humans so narrow minded short-termists?

➕ show 4 replies
m463 • yesterday at 7:22 PM

Just say no. Cloudflare should not be the gatekeeper for the internet.

➕ show 1 reply
m4rtink • yesterday at 6:55 PM

Totally not a single point of failure for the whole Internet.

LoganDark • today at 1:50 AM

As always, I am worried to see Cloudflare and Google Chrome -- two of the internet's biggest/worst monopolies -- working so closely together like this. Cloudflare is already undergoing enshittification, like banning all automation by default that hasn't undergone privacy-invasive certification procedures (they recently started calling disallowed bots "AI Training", but that doesn't change anything -- you still have to be on a whitelist in order to be allowed). I have no doubt that in the near future, they will release some kind of ID verification and then the vast majority of the internet is simply done.

➕ show 1 reply
ggm • today at 12:19 AM

[dead]

ericpauley • today at 2:10 AM

Interesting, but the article would be far more enjoyable to read if it weren’t clearly written by Claude.