since we are talking about protecting intellectual property, there is no law protecting business models. When Lets Encrypt copied Comodo's 90 day free ssl business model, we could not protect it. Lets encrypt could have chosen 57 days, 30 days or any other number for the lifetime of their certificates. But they chose to use Comodo's 90 day Free SSL model that we established in the market place for over 9 years!!!
That is not a business model. Besides, Google has been doing that for years now[1]. If this is in the name of justice in defending their business model, they should go after Google too.
Comodo has no innovation here.
What they have is nothing new. We have been giving 90 day free certificates since 2007.
ACME is entirely new and original. It's even an open protocol, they themselves could implement it and gain a wider customer base! Why let LE be the only ACME CA?
Also their 90-day free certs don't renew for free.
Actually consumer are less safe with their certificate because if it is used maliciously they don't revoke (Unmanaged)!
Unmanaged but 100% automated, which is 100% more than they can say. Automated processes are more standardized and more quickly executed than manual, managed ones. Also LE has proactively revoked several abused certificates[2] and has NOT broken browser security with bad extensions nor issued fraudulent certificates[3] as Comodo has.
Lets get the facts right guys! We are the good guys that have been giving free SSL certificates since 2007 and managing them!
Sigh. CAs need to be working together at a time like this, not abusing trust and slinging mud.
Comments
That is not a business model. Besides, Google has been doing that for years now[1]. If this is in the name of justice in defending their business model, they should go after Google too.
Comodo has no innovation here.
ACME is entirely new and original. It's even an open protocol, they themselves could implement it and gain a wider customer base! Why let LE be the only ACME CA?
Also their 90-day free certs don't renew for free.
Unmanaged but 100% automated, which is 100% more than they can say. Automated processes are more standardized and more quickly executed than manual, managed ones. Also LE has proactively revoked several abused certificates[2] and has NOT broken browser security with bad extensions nor issued fraudulent certificates[3] as Comodo has.
Sigh. CAs need to be working together at a time like this, not abusing trust and slinging mud.
Related discussion on LE forums: https://community.letsencrypt.org/t/about-the-defending-our-...
[1]: https://twitter.com/sleevi_/status/746099416864591873
[2]: https://community.letsencrypt.org/c/incidents
[3]: https://news.ycombinator.com/item?id=11962371
That guy is a real piece of work. Is the CA industry generally populated with that kind of personality? He sounds like he runs a payday loan store.
Rent seekers tend to be like this in my experience. This is how you stay alive if you lack the ability to innovate.
I know multiple people like this, who genuinely believe the BS they themselves come up with. Across all industries.
The CA industry is a racket.
So, yes.