{"id":73771,"date":"2015-01-06T17:48:54","date_gmt":"2015-01-06T22:48:54","guid":{"rendered":"http:\/\/rbachnet.wwwmi3-ss40.a2hosted.com\/index.php\/"},"modified":"2021-07-12T16:59:03","modified_gmt":"2021-07-12T20:59:03","slug":"umich-helps-secure-the-web-with-lets-encrypt","status":"publish","type":"post","link":"https:\/\/rbach.net\/index.php\/umich-helps-secure-the-web-with-lets-encrypt\/","title":{"rendered":"UMich Helps Secure the Web with  Let\u2019s Encrypt"},"content":{"rendered":"<p><a href=\"http:\/\/www.gfi.com\/blog\/the-numbers-game-layering-your-av-protection\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-103452\" title=\"UMich Helps Secure the Web with Let\u2019s Encrypt\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/data_protection-e1567884167397-150x137.jpg?resize=109%2C100&#038;ssl=1\" alt=\"UMich Helps Secure the Web with Let\u2019s Encrypt\" width=\"109\" height=\"100\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/data_protection-e1567884167397.jpg?resize=150%2C137&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/data_protection-e1567884167397.jpg?resize=75%2C69&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/data_protection-e1567884167397.jpg?w=297&amp;ssl=1 297w\" sizes=\"auto, (max-width: 109px) 100vw, 109px\" \/><\/a>The <strong><a title=\"University of Michigan\" href=\"https:\/\/www.umich.edu\" target=\"_blank\" rel=\"noopener noreferrer\">University of Michigan<\/a><\/strong> is teaming up with leading Internet firms to <strong>help secure the web<\/strong>. <a title=\"University of Michigan\" href=\"https:\/\/jhalderm.com\/\" target=\"_blank\" rel=\"homepage nofollow noopener noreferrer\">UMich<\/a>,\u00a0<a href=\"https:\/\/www.cisco.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Cisco<\/a> (<a href=\"https:\/\/www.tradingview.com\/symbols\/NASDAQ-CSCO\/\" target=\"_blank\" rel=\"noopener noreferrer\">CSCO<\/a>),\u00a0<a href=\"https:\/\/www.akamai.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Akamai<\/a> (<a href=\"https:\/\/www.tradingview.com\/symbols\/NASDAQ-AKAM\/\" target=\"_blank\" rel=\"noopener noreferrer\">AKAM<\/a>), <a title=\"Mozilla\" href=\"https:\/\/www.mozilla.org\/en-US\/\" target=\"_blank\" rel=\"noopener noreferrer\">Mozilla<\/a>, the <strong><a title=\"Electronic Frontier Foundation\" href=\"https:\/\/www.eff.org\/\" target=\"_blank\" rel=\"homepage noopener noreferrer\">Electronic Frontier Foundation<\/a><\/strong>, and public key certificate authority <a title=\"Identrust\" href=\"https:\/\/en.wikipedia.org\/wiki\/Identrust\" target=\"_blank\" rel=\"nofollow noopener wikipedia noreferrer\">IdenTrust<\/a>, have launched a new free <a title=\"Certificate Authority\" href=\"http:\/\/searchsecurity.techtarget.com\/definition\/certificate-authority\" target=\"_blank\" rel=\"noopener noreferrer\">certificate authority<\/a> (CA) called <a title=\"Let\u2019s Encrypt\" href=\"https:\/\/www.letsencrypt.org\/\" target=\"_blank\" rel=\"noopener noreferrer\">Let\u2019s Encrypt<\/a>.<\/p>\n<p>The <strong>Let\u2019s Encrypt<\/strong> CA, which will be available in the Summer of 2015. It aims to get people to <strong>encrypt their connections to their websites<\/strong> according to a recent <em><a href=\"https:\/\/gigaom.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">GigaOM<\/a> <\/em><a title=\"Tech firms and activists join to launch free certificate authority\" href=\"https:\/\/web.archive.org\/web\/20211024004919\/https:\/\/gigaom.com\/2014\/11\/18\/tech-firms-and-activists-join-to-launch-free-certificate-authority\/\" target=\"_blank\" rel=\"noopener noreferrer\">article<\/a>. Let&#8217;s Encrypt goal is to make it easier to get a proper Secure Sockets Layer\/Transfer Layer Security (SSL\/TLS) certificate. That way the certs can be deployed to secure a Web server and its users.<\/p>\n<h3>Let\u2019s Encrypt will help secure the Internet<\/h3>\n<p><a href=\"https:\/\/letsencrypt.org\/about\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-103454\" title=\"Let\u2019s Encrypt\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/letsencrypt_logo.png?resize=120%2C38&#038;ssl=1\" alt=\"Let\u2019s Encrypt\" width=\"120\" height=\"38\" \/><\/a>According to the article Let\u2019s Encrypt, comes as the tech industry scrambles to <a title=\"Encrypted Web Traffic More Than Doubles After NSA Revelations\" href=\"http:\/\/www.wired.com\/2014\/05\/sandvine-report\/\" target=\"_blank\" rel=\"noopener noreferrer\">encrypt the web<\/a>. This is more important after the <strong>mass surveillance revelations of <a title=\"National Security Agency\" href=\"https:\/\/maps.google.com\/maps?ll=39.109,-76.77&amp;spn=0.01,0.01&amp;q=39.109,-76.77%20%28National%20Security%20Agency%29&amp;t=h\" target=\"_blank\" rel=\"geolocation noopener noreferrer\">NSA<\/a><\/strong> leaker <a title=\"Edward Snowden\" href=\"https:\/\/web.archive.org\/web\/20211220064108\/https:\/\/www.crunchbase.com\/person\/edward-snowden\" target=\"_blank\" rel=\"crunchbase nofollow noopener noreferrer\">Edward Snowden<\/a>. The CA will aid other efforts to secure the Internet.<\/p>\n<p>Let&#8217;s Encrypt is developing the Automated Certificate Management Environment or <a title=\"ACME\" href=\"https:\/\/github.com\/letsencrypt\/acme-spec\" target=\"_blank\" rel=\"noopener noreferrer\">ACME<\/a>\u00a0protocol. The ACME\u00a0protocol. will sit between Web servers and the CA. It includes support for new, stronger forms of domain validation.<\/p>\n<p><a href=\"https:\/\/www.umich.edu\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-103456 size-thumbnail\" title=\"University of Michigan\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/UMich_logo-2.png?resize=75%2C51&#038;ssl=1\" alt=\"University of Michigan\" width=\"75\" height=\"51\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/UMich_logo-2.png?resize=75%2C51&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/UMich_logo-2.png?resize=150%2C102&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/UMich_logo-2.png?w=350&amp;ssl=1 350w\" sizes=\"auto, (max-width: 75px) 100vw, 75px\" \/><\/a>Let&#8217;s Encrypt will serve as its <strong>own <a title=\"Root Certificate Authority\" href=\"https:\/\/web.archive.org\/web\/20170619161549\/http:\/\/windowsitpro.com:80\/security\/q-whats-impact-renewing-enterprise-root-cas-certificate-our-existing-pki-clients-and-subord\" target=\"_blank\" rel=\"noopener noreferrer\">root CA<\/a><\/strong>. The nonprofit CA\u00a0public benefit corporation, Internet Security Research Group (ISRG) will run the root CA. Josh Aas, the executive director of ISRG, explained securing the web is just not a simple thing to use <strong><a title=\"TLS\" href=\"http:\/\/searchsecurity.techtarget.com\/definition\/Transport-Layer-Security-TLS\" target=\"_blank\" rel=\"noopener noreferrer\">Transport Layer Security<\/a><\/strong> (TLS), the successor to <a title=\"SSL\" href=\"https:\/\/www.digicert.com\/ssl.htm\" target=\"_blank\" rel=\"noopener noreferrer\">Secure Socket Layer<\/a> (SSL). He explains that getting, paying for, and installing a certificate is too hard for many network administrators.<\/p>\n<p style=\"padding-left: 30px;\"><em>The anchor for any TLS-protected communication is a public-key certificate which demonstrates that the server you\u2019re actually talking to is the server you intended to talk to. For many server operators, getting even a basic server certificate is just too much of a hassle. The application process can be confusing. It usually costs money. It\u2019s tricky to install correctly. It\u2019s a pain to update.<\/em><\/p>\n<p><a href=\"https:\/\/www.eff.org\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-103458 size-thumbnail\" title=\"Electronic Frontier Foundation\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/eff_logo-e1567884350594-75x50.png?resize=75%2C50&#038;ssl=1\" alt=\"Electronic Frontier Foundation\" width=\"75\" height=\"50\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/eff_logo-e1567884350594.png?resize=75%2C50&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/eff_logo-e1567884350594.png?resize=150%2C101&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/eff_logo-e1567884350594.png?w=357&amp;ssl=1 357w\" sizes=\"auto, (max-width: 75px) 100vw, 75px\" \/><\/a>According to the statement, Let\u2019s Encrypt\u2019s certificates will be free. It will have an automated issuance and renewal protocol \u2013 an open standard. A step to reduce the need for input from the domain holder\u2019s side. According to an <a title=\"Launching in 2015: A Certificate Authority to Encrypt the Entire Web\" href=\"https:\/\/www.eff.org\/deeplinks\/2014\/11\/certificate-authority-encrypt-entire-web\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>EFF<\/strong> blog post<\/a>, \u201cswitching a webserver from HTTP to <strong>HTTPS<\/strong> with this CA will be as easy as issuing one command, or clicking one button.\u201d<\/p>\n<p>Records of certificate issuance and revocation will be publicly available. The organizations behind Let\u2019s Encrypt are stressing that the system won\u2019t be under any one organization\u2019s control.<\/p>\n<p><iframe loading=\"lazy\" title=\"Let&#039;s Encrypt Demo\" width=\"480\" height=\"270\" src=\"https:\/\/www.youtube.com\/embed\/Gas_sSB-5SU?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe><\/p>\n<p>The EFF has been working on helping users take advantage of HTTPS for a while. The EFF worked with the Tor Project, to create the <a title=\"HTTPS Everywhere\" href=\"https:\/\/www.eff.org\/Https-everywhere\" target=\"_blank\" rel=\"noopener noreferrer\">HTTPS Everywhere<\/a> extension for Firefox, Firefox for Android, Chrome, and Opera browsers.<\/p>\n<p>The Let\u2019s Encrypt project will use Internet-wide datasets of certificates to make higher-security decisions about when a certificate is safe to issue. The data will include the EFF\u2019s Decentralized SSL Observatory, the <a title=\"University of Michigan\u2019s scans.io,\" href=\"https:\/\/web.archive.org\/web\/20211127153243\/https:\/\/scans.io\/\" target=\"_blank\" rel=\"noopener noreferrer\">University of Michigan\u2019s scans.io,<\/a> and\u00a0<a title=\"Google\" href=\"https:\/\/www.google.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Google<\/a>&#8216;s (<a title=\"NASDAQ : GOOG\" href=\"https:\/\/www.tradingview.com\/symbols\/NASDAQ-GOOG\/\" target=\"_blank\" rel=\"noopener noreferrer\">GOOG<\/a>)\u00a0Certificate Transparency logs.<\/p>\n<p>In addition to the Let&#8217;s Encrypt project, some of the paths to secure the web include:<\/p>\n<ul>\n<li>The next version of the <a title=\"Hypertext Transfer Protocol\" href=\"http:\/\/en.wikipedia.org\/wiki\/Hypertext_Transfer_Protocol\" target=\"_blank\" rel=\"noopener wikipedia noreferrer\">HTTP protocol<\/a> will likely be <strong>encrypted by default<\/strong>.<\/li>\n<li>Mozilla and Firefox are collaborating with the EFF to bring Microsoft, Google, Opera, and others to add Let\u2019s Encrypt to their list of valid CAs.<\/li>\n<li>Google will rank up sites that use SSL\/TLS encryption.<\/li>\n<li>The content delivery and security outfit <a title=\"CloudFlare\" href=\"http:\/\/www.cloudflare.com\/\" target=\"_blank\" rel=\"homepage nofollow noopener noreferrer\">Cloudflare<\/a> is offering free <a title=\"Transport Layer Security\" href=\"http:\/\/en.wikipedia.org\/wiki\/Transport_Layer_Security\" target=\"_blank\" rel=\"nofollow noopener wikipedia noreferrer\">SSL encryption<\/a> for millions of its customers.<\/li>\n<li>And now Let\u2019s Encrypt aims to equip websites with free certificates \u2013 the proof they need to tell users\u2019 browsers that their public encryption keys are genuine and the connection is properly secured.<\/li>\n<\/ul>\n<p><strong>rb-<\/strong><\/p>\n<p><em>Many websites currently use the HTTP protocol, a standard that exposes site owners to a number of threats including cyber espionage, keyword-based censorship, account hijacking, and <a href=\"http:\/\/www.symantec.com\/connect\/articles\/five-common-web-application-vulnerabilities\" target=\"_blank\" rel=\"noopener noreferrer\">a host of web application attacks such as SQLi and XSS<\/a>. Let&#8217;s Encrypt helps reduce these risks which I think it is a good step in the right direction.<\/em><\/p>\n<p><em><a href=\"https:\/\/web.archive.org\/web\/20220224222733\/https:\/\/www.zdnet.com\/meet-the-team\/us\/larry-seltzer\/\" rel=\"author\" track=\"moduleClick\" data=\"{&quot;moduleInfo&quot;: &quot;AuthorFooter&quot;}\" rewritten=\"true\">Larry Seltzer<\/a> argues on <a title=\"Wired\" href=\"http:\/\/www.zdnet.com\/article\/will-lets-encrypt-threaten-commercial-certificate-authorities\/?_escaped_fragment_=#!\" target=\"_blank\" rel=\"noopener noreferrer\">Wired<\/a> that Let&#8217;s Encrypt does not go far enough. We want the project to not only encrypt data but also authenticate users. IMHO that is a pipe dream. Authentication will step on the toes of Symantec, Oracle, and other hugely funded firms that will squash anybody doing the right thing that threatens their profits.<\/em><\/p>\n<h6>Related Posts<\/h6>\n<ul>\n<li><a href=\"https:\/\/www.eff.org\/deeplinks\/2014\/12\/power-2014-double-your-impact\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Power Up 2014: Double Your Impact!<\/a> (eff.org)<\/li>\n<\/ul>\n<p><em><a title=\"Ralph Bach\" href=\"https:\/\/rbach.net\/index.php\/new-resume\/\" target=\"_blank\" rel=\"noopener noreferrer\">Ralph Bach<\/a>\u00a0has been in IT long enough to know better and has blogged from his\u00a0<a title=\"Bach Seat\" href=\"https:\/\/rbach.net\/\" target=\"_blank\" rel=\"noopener noreferrer\">Bach Seat<\/a> about IT, careers, and anything else that catches his attention since 2005. You can follow him on <a class=\"broken_link\" href=\"http:\/\/www.linkedin.com\/in\/rb48334\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">LinkedIn<\/a>,\u00a0<a href=\"https:\/\/www.facebook.com\/ralph.bach.14\" target=\"_blank\" rel=\"noopener noreferrer\">Facebook<\/a>,\u00a0and\u00a0<a href=\"https:\/\/twitter.com\/rbach48334\" target=\"_blank\" rel=\"noopener noreferrer\">Twitter<\/a>. Email the Bach Seat\u00a0<a href=\"mailto:\/\/bach.seat@gmail.com\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>UMich teams up with CSCO Mozilla EFF to launch new free CA &#8211; Let\u2019s Encrypt to protect web traffic against online snooping<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[3277,247,487,266,973,536,92,286,2337,2321,4,305,583,642],"class_list":["post-73771","post","type-post","status-publish","format-standard","hentry","category-security","tag-3277","tag-cisco","tag-csco","tag-eff","tag-firefox","tag-goog","tag-google","tag-https","tag-lets-encrypt","tag-mozilla","tag-security","tag-ssl","tag-tls","tag-university-of-michigan"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/73771","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/comments?post=73771"}],"version-history":[{"count":11,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/73771\/revisions"}],"predecessor-version":[{"id":132295,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/73771\/revisions\/132295"}],"wp:attachment":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/media?parent=73771"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/categories?post=73771"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/tags?post=73771"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}