Live data from Hacker News

Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

letsencrypt.org

21–30 of 404 posts

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#22

Does it mean that russian/iranian web-sites using letsencrypt stop working and need to change their certificate provider?

Depends on whether LE is compelled to terminate service to BGP AS numbers hosted in U.S.-sanctioned countries, and whether LE continues operating out of the U.S..

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#23

Couldn't LE have a branch in Europe or anywhere outside the USA and its minions? Because they're betraying their own goals, as stated in their About page: “It is a service run for the public’s benefit. [...] Anyone who owns a domain name can use Let’s Encrypt to obtain a trusted certificate at zero cost. [...] Let’s Encrypt is a joint effort to benefit the community, beyond the control of any one organization.” Now t…

They could, but if the branch didn’t follow these laws, the main US branch would still be liable.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#24

> active eavesdropping (e.g., monster-in-the-middle attacks) is this standard MitM, or is it some crucially distinct variation?

[flagged]

I kinda like this framing. It effectively classifies companies such as Zscaler and CloudFlare as monsters.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#26
post #5
post #4

Has anyone got any experience with Zero SSL? https://zerossl.com/ It seems like a good EU alternative.

EU? There’s almost zero information on the company, no privacy policy? The only place I found any mention is the footer, “HID Global Corporation, part of ASSA ABLOY”. Assa Abloy seems Swedish but HID Global is a US company as far as a quick search goes. But without a proper company info page and privacy policy I wouldn’t consider it anywhere near a “good alternative” regardless.

The privacy policy is under legal in the footer, exactly where I'd expect it to be honest. It also gives the company registration: > 1.1. We, ZeroSSL GmbH, FN 443956b (the “Company“) and below that the company address (registered in Austria).

Don't get me wrong, I agree that there is some lack of "who actually runs/controls this", especially on the about page where I expect such things to be.

At the very least it's not as transparent as I'd wish from a CA. E.g their Certificate Agreement is from Sectigo, so are they involved? No mention anywhere else from what I can see.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#27
post #9
post #4

Has anyone got any experience with Zero SSL? https://zerossl.com/ It seems like a good EU alternative.

3 90-day ACME certs for free. 180€/year for unlimited 90-day certs and 5 yearly ones. That’s a pretty steep increase. I would almost be more interested in a monthly fee per cert.

From their docs[0] this doesn't seem to apply if using ACME, but they don't exactly make that clear...

> By using ZeroSSL's ACME feature, you will be able to generate an unlimited amount of 90-day SSL certificates at no charge, also supporting multi-domain certificates and wildcards. Each certificate you create will be stored in your ZeroSSL account.

[0]: https://zerossl.com/documentation/acme/

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#28

Couldn't LE have a branch in Europe or anywhere outside the USA and its minions? Because they're betraying their own goals, as stated in their About page: “It is a service run for the public’s benefit. [...] Anyone who owns a domain name can use Let’s Encrypt to obtain a trusted certificate at zero cost. [...] Let’s Encrypt is a joint effort to benefit the community, beyond the control of any one organization.” Now t…

They could, but if the branch didn’t follow these laws, the main US branch would still be liable.

It's about time SOME entities start moving from US entirely.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#29
It seems that, as soon as you transact with a sanctioned entity, you are globally in breach of the agreement and risking the revocation of all your certificates — also the ones for non-sanctioned countries.

Front matter:

   - it is called a "Subscriber Agreement" and not anything that suggests that its scope is a single certificate

   - it's a "contract [...] regarding Your [...] rights and duties relating to [...] Certificates" - plural
2.1 "Term":

  - "[the agreement] will remain in force during the entire period during which *any* of Your Certificates are valid" - plural
3.1 "Warranties":

  - "[by] requesting, accepting, or using *a* Let’s Encrypt Certificate" - plural

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#30

Earlier quoted context omitted.

[flagged]

I kinda like this framing. It effectively classifies companies such as Zscaler and CloudFlare as monsters.

It's particularly funny because "monster-in-the-middle" appears to be a deliberately quirky marketing term invented by cloudflare.
Post reply on HN