is this standard MitM, or is it some crucially distinct variation?
Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
11–20 of 404 posts
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#12> 2. officially or formally ratified or confirmed.
> 3. penalized, especially by way of discipline or to force compliance with legal obligations.
So who can use lets encrypt? Those that are penalised or those that are confirmed.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#13Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#14Because they're betraying their own goals, as stated in their About page: “It is a service run for the public’s benefit. [...] Anyone who owns a domain name can use Let’s Encrypt to obtain a trusted certificate at zero cost. [...] Let’s Encrypt is a joint effort to benefit the community, beyond the control of any one organization.” Now they own they are under the control of a political organization.
Here is the paragraph Let's Encrypt added to their Subscription Agreement on 2026-06-04:
> You are not a person or entity that is:
> (a) located in, organized under the laws of, or ordinarily resident in any country or territory that is the target of comprehensive U.S. sanctions;
> (b) a prohibited or restricted party under U.S. or other applicable sanctions and export control laws and regulations;
> or (c) owned or controlled by or acting on behalf of anyone described in (a) or (b).
> You agree to use Let’s Encrypt Certificates and any services provided by or on behalf of ISRG in compliance with applicable U.S. export control and sanctions laws and regulations.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#15Sanctioned has a double meaning here[1]: > 2. officially or formally ratified or confirmed. > 3. penalized, especially by way of discipline or to force compliance with legal obligations. So who can use lets encrypt? Those that are penalised or those that are confirmed. [1] https://www.dictionary.com/browse/sanctioned
> [You certify to LetsEncrypt that] …
> You are not a person or entity that is: (a) located in, organized under the laws of, or ordinarily resident in any country or territory that is the target of comprehensive U.S. sanctions; (b) a prohibited or restricted party under U.S. or other applicable sanctions and export control laws and regulations; or (c) owned or controlled by or acting on behalf of anyone described in (a) or (b). You agree to use Let’s Encrypt Certificates and any services provided by or on behalf of ISRG in compliance with applicable U.S. export control and sanctions laws and regulations.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#16> active eavesdropping (e.g., monster-in-the-middle attacks) is this standard MitM, or is it some crucially distinct variation?
> Also known as a monster-in-the-middle,[1][2] machine-in-the-middle,[3] meddler-in-the-middle,[4] manipulator-in-the-middle,[5][6] person-in-the-middle[7] (PITM), or adversary-in-the-middle[8] (AITM) attack.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#17> active eavesdropping (e.g., monster-in-the-middle attacks) is this standard MitM, or is it some crucially distinct variation?
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#18> active eavesdropping (e.g., monster-in-the-middle attacks) is this standard MitM, or is it some crucially distinct variation?
Man in the Middle Wiki: > Also known as a monster-in-the-middle,[1][2] machine-in-the-middle,[3] meddler-in-the-middle,[4] manipulator-in-the-middle,[5][6] person-in-the-middle[7] (PITM), or adversary-in-the-middle[8] (AITM) attack.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#19Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#20Has anyone got any experience with Zero SSL? https://zerossl.com/ It seems like a good EU alternative.