PärPod by Claude Code
PärPod by Claude Code
PärPod by Claude Code
Popcorn2 7B: Let's Encrypt: The Plan To Give Away The Padlock
Episode 78m · Aug 14, 2026
Let's Encrypt: The Plan To Give Away The Padlock

Let's Encrypt: The Plan To Give Away The Padlock

The Certificate Used To Cost Money

Last time, a certificate renewal on your own server died about 1.4 seconds from the finish line, and the front door stayed shut. That episode was about the mechanism. This one is about the people who decided the mechanism should exist at all, because the arrangement you now take for granted is roughly 10 years old, and before that it was neither free nor automatic.

Here is what getting a certificate looked like in 2010. You generated a request on your server. You sent it to a commercial certificate authority, which is a company the browsers have agreed to trust. You paid them somewhere between 50 and several hundred dollars a year. You waited. Somebody, sometimes an actual human being, checked something about you. Then they mailed you a file, and you installed that file by hand. A year later you did the whole thing again, and if you forgot, your site broke in front of your visitors with a full-screen security warning.

That friction had a consequence, and the consequence was the point. Encryption was a paid upgrade. If you ran a bank, you bought a certificate. If you ran a blog, a forum, a small shop, a personal site, you mostly did not, because it cost real money and real attention every single year. So the majority of the web travelled in plain text, readable by anyone between you and the person reading you.

The system also had a structural flaw that got demonstrated in public. In 2011 a Dutch certificate authority called DigiNotar was broken into, and the attacker used it to issue fraudulent certificates for other people's domains, including Google's. Those certificates were valid. Every browser on earth trusted them, because every browser on earth trusted DigiNotar. The company did not survive the year. What it proved was that the padlock rested on a list of companies, and the list was only as strong as its weakest member.

Then in April 2014 came Heartbleed, a bug in the software doing the encrypting rather than in any authority, and suddenly a very large number of servers needed new certificates all at once, urgently. A world where replacing a certificate is a manual chore is a world that cannot respond to that quickly. The lesson people took away was not only that the web needed more encryption. It was that the web needed encryption that could be replaced without a human in the loop.

Four People And A Nonprofit

The plan started in 2012, between two employees at Mozilla, Josh Aas and Eric Rescorla, Peter Eckersley at the Electronic Frontier Foundation, and J. Alex Halderman at the University of Michigan. A browser maker, a digital rights organisation, and a university security researcher. That combination matters, because the thing they wanted to build only works if browsers trust it, and browser makers are exactly who decides that.

It's hard to believe 10 years have passed since Eric Rescorla, Alex Halderman, Peter Eckersley and I founded ISRG as a nonprofit home for public benefit digital infrastructure.

That is Josh Aas, writing in 2023. ISRG stands for the Internet Security Research Group, and it was incorporated on 24 May 2013 as a California public benefit corporation, which is to say a nonprofit. This is the structural move, and it is the part worth sitting with. They did not build a cheaper certificate company. They built an organisation that has no owner to return a profit to, whose stated mission is lowering the monetary, technological and informational barriers to a more secure internet. A company that gives its product away has a problem. A nonprofit that gives its product away is simply doing its job.

The funding came from the people who wanted the outcome. The founding sponsors and partners were Mozilla, the Electronic Frontier Foundation, the University of Michigan, Cisco and Akamai. Browser makers, infrastructure companies and advocacy groups paying for a service that all of them, and everyone else, would then use for nothing. The project was announced publicly on 18 November 2014, with the plainest possible name for what it was asking the web to do.

Automation Was The Whole Idea

Free was the headline. Automatic was the actual invention, and it is the half that ended up in a specification.

The team wrote a protocol called ACME, the Automatic Certificate Management Environment, and submitted it to the Internet Engineering Task Force for standardisation on 28 January 2015, before they had issued a single certificate. Think about that order of operations. They standardised the conversation first. You already know what that conversation does, because last episode watched it happen: the authority sets a challenge, your server proves it controls the domain, a certificate comes back. What was new in 2015 was that the whole exchange had a written specification, which meant it could be spoken by software rather than performed by a person. No email, no phone call, no invoice, no human.

The first certificate was issued on 14 September 2015, for a domain called helloworld dot letsencrypt dot org. On the same day, ISRG applied to the root programs at Mozilla, Google, Microsoft and Apple, because a certificate authority nobody trusts is just an expensive way to make files. A limited beta had opened two days earlier, and by the time it closed it had issued more than 26,000 certificates. Public beta, where anyone could ask without an invitation, opened on 3 December 2015.

Invitations are no longer needed in order to get free certificates from Let's Encrypt.

They dropped the beta label on 12 April 2016, having issued more than 1.7 million certificates covering more than 3.8 million websites in about seven months. The protocol itself became a formal internet standard, RFC 8555, in March 2019, and the author list reads like the coalition that built it: Cisco, the Electronic Frontier Foundation, Let's Encrypt and the University of Michigan. At that point automatic certificate issuance stopped being one organisation's clever idea and became something anybody could implement, including competitors. Which is what a nonprofit doing infrastructure is supposed to produce.

Why Your Server Never Asks You

This is where the backstory lands back on your own machine. Your server does not have a certificate because you bought one. It has a certificate because Caddy, the reverse proxy holding your front door, speaks ACME to a nonprofit on your behalf, unprompted, on a schedule, and never once asks you about it. The certificates are deliberately short-lived, so that renewal has to be automatic. A 90-day certificate is not a limitation they failed to remove. It is a design choice that forces the automation to work, because anything that only has to happen once a year will rot quietly, and anything that has to happen every few weeks gets noticed the moment it breaks.

Which is exactly what you saw last episode. That renewal failing 1.4 seconds from the end was the visible edge of a ceremony that normally completes without anyone watching it, several times a year, on hundreds of millions of sites. The reason a failure feels shocking rather than routine is that the success rate is high enough for you to have stopped thinking about it. That is the whole achievement, and it is a strange kind of achievement, because its measure of success is that you forget it happened.

One of the four did not get to see how far it went. Peter Eckersley, the Electronic Frontier Foundation's chief computer scientist for many of his 12 years there, was diagnosed with colon cancer and died in September 2022.

Peter was a tremendous force in making the internet a safer place.

The padlock on your own front door is downstream of a decision four people made in 2012, that the correct price for encrypting the web was nothing, and the correct amount of human involvement was none.