Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Thanks to let's encrypt it's now at least possible to get a valid certificate anonymously, but it's a pain that requires renewal every 60 to 90 days and puts you at their mercy.

If they decide they don't like your brand of free speech it's lights out and they are the only game in town.

Yes, I know you can automate renewal if you have shell access, but you'll probably have to remember to do it manually if you use shared hosting that doesn't provide a cert for you.

That's a lot of work, and a lot of risk, to secure a message that's meant to be publicly broadcast in the first place.

I imagine it to be a bit like encrypting OTA television. Sure, you could stop a pirate broadcast from inpersonating your station by encrypting it, but that's not actually a threat model that applies to normal people most of the time and it makes everything far more complex.

Can your ISP MITM you? Yep, and if they do you should cancel your service then sue them into the ground.



Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: