Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You think that's a lot? I'm not trying to single you out and please don't take this as a personal attack. But it's disturbing to me especially in light of the dyn attack and others people STILL are not getting how badly our security infrastructure is horrendously broken and/or non existent on the net.

Letsencrypt are one of the good guys. They are fighting the good fight. With the admirable goal of trying to get the web moved entirely over to SSL. It's an uphill battle because we have decades of SSL being a pain in the ass to deploy and maintain. "But certificates are not hard to generate and deploy!" Over 50% of the web disagrees with you.

People have got to start taking this stuff seriously. Everyone should be donating monthly to OpenBSD for OpenSSH which everyone and their grandmother uses in their infrastructure but they take it for granted and don't donate. Which I personally find appalling that it's so widely used and yet supported so very little for such a vital part of everyones infrastructure.

SSL is the same way, it's a vital part of everyones infrastructure and both the OpenBSD folks and lets encrypt should be bankrolled by the tens of millions each year from both individuals and the corporations who use this software on a massive scale. Seriously, Cisco, Juniper, Oracle (yeah I know it was a waste of bits to type that name here), every corporation using SSH should be pouring millions into the OpenBSD foundation and you should all be ashamed and publicly called out for not doing so!



I agree with your comment, but I don't see what the first sentence has to do with the rest of the comment. Yes, security infrastructure is broken, yes it needs to be better, yes I think $200k per month is a lot.


Why not both?

Yes, LE are the good guys, and everyone should be donating mountains of money to them, and the bsd-folks. But that doesn't negate the fact that $200K a month is a crazy amount.


In what way is this a 'crazy amount'? If it were 100% personnel costs, it would only pay for a dozen or two people max. Is that an unreasonable number of people working on SSL?

There are literally thousands of people working at SSL companies. 1100 at Comodo alone.


You beat me to this sentiment. That was my thought exactly, 200K/mo is peanuts for a full time development team. And I am only talking salaries. Not perks, benefits, etc.

Which is why it is disheartening to me to hear anyone gasp at this request from LE. As you said there are many many companies using SSL that are spending truckloads a month on employee salaries, sending a 10,000 dollar check to LE each month for them should be in their own interest.

We are not holding corporations making millions off fundamental pieces of infrastructure like LE and OpenSSH accountable. These corps should really be ashamed and called out publicly for not donating healthy sums each month to these projects. IMO.


It's not a crazy amount for running a company. It's a crazy amount for a crowdfunding campaign.


if you think that's crazy.. take a look at the amounts on this page:

https://en.wikipedia.org/wiki/List_of_highest_funded_crowdfu...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: