The encyclopedia · Software & IT · Technical decision · 2014–2017
Let's Encrypt made HTTPS default by giving certificates away for free
Automated, free certificates removed the cost barrier, and Chrome labeling HTTP 'Not secure' finished the push to encrypted-by-default.
Internet Security Research Group (ISRG) · Mozilla · Google · Cisco · Akamai · Electronic Frontier Foundation
the move
Encrypting the web was technically solved for years, yet by late 2015 only about 40% of page views were HTTPS. The blockers were the cost of a certificate and the manual work of installing and renewing it.
Let's Encrypt, backed by Mozilla and run under ISRG, launched a free certificate authority. Within six months it had issued over 1.7 million certificates and moved roughly 2.4 million domains onto HTTPS. It exited beta in April 2016.
why it works
- Free, automated certificates removed the two real obstacles: price and installation complexity.
- Browsers marking HTTP as 'Not secure' made the insecure choice visibly worse to ordinary users.
- Let's Encrypt let a single host (such as WordPress.com or a provider) secure all its customers at once, compounding the effect.
- Certificates that are cheap and easy to renew remove the expiry risk that made owners avoid them.
what transfers
To move an entire ecosystem to a better default, remove the barrier and change the visible default: free supply plus a visible warning can beat a decade of pleading.
what came after
HTTPS became the dominant mode of web traffic. By late 2016 over half of Chrome page loads were HTTPS, and Chrome 56 in January 2017 began explicitly labeling HTTP sites 'Not secure'. Let's Encrypt went on to issue hundreds of millions of certificates and is now the largest certificate authority on the web.
references
- Let's Encrypt free HTTPS certification push exits beta
- Google: 'Web has never been more secure', as HTTPS dominates Chrome browsing
spotted an error? The archive wants to know.