EN
Back to the archive

The encyclopedia · Software & IT · Technical decision · 2014–2017

Let's Encrypt made HTTPS default by giving certificates away for free

Automated, free certificates removed the cost barrier, and Chrome labeling HTTP 'Not secure' finished the push to encrypted-by-default.

Internet Security Research Group (ISRG) · Mozilla · Google · Cisco · Akamai · Electronic Frontier Foundation

the move

Encrypting the web was technically solved for years, yet by late 2015 only about 40% of page views were HTTPS. The blockers were the cost of a certificate and the manual work of installing and renewing it.

Let's Encrypt, backed by Mozilla and run under ISRG, launched a free certificate authority. Within six months it had issued over 1.7 million certificates and moved roughly 2.4 million domains onto HTTPS. It exited beta in April 2016.

why it works

  • Free, automated certificates removed the two real obstacles: price and installation complexity.
  • Browsers marking HTTP as 'Not secure' made the insecure choice visibly worse to ordinary users.
  • Let's Encrypt let a single host (such as WordPress.com or a provider) secure all its customers at once, compounding the effect.
  • Certificates that are cheap and easy to renew remove the expiry risk that made owners avoid them.
the payoffRemove the cost, then let the browser shame plain HTTPclever

what transfers

To move an entire ecosystem to a better default, remove the barrier and change the visible default: free supply plus a visible warning can beat a decade of pleading.

what came after

HTTPS became the dominant mode of web traffic. By late 2016 over half of Chrome page loads were HTTPS, and Chrome 56 in January 2017 began explicitly labeling HTTP sites 'Not secure'. Let's Encrypt went on to issue hundreds of millions of certificates and is now the largest certificate authority on the web.

references

spotted an error? The archive wants to know.

same kind of clever