Live data from Hacker News

Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

letsencrypt.org

41–50 of 404 posts

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#41
post #19
post #10

Earlier quoted context omitted.

No it isn't. Not unless it's free. This is the main reason letsencrypt is so popular.

They do have a free plan with unlimited ACME DV certs, though! Not marketed very well and no wildcard certs, but it does exist.

Had to look for but found: https://www.actalis.com/activate-free-plan

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#42
post #5

Earlier quoted context omitted.

EU? There’s almost zero information on the company, no privacy policy? The only place I found any mention is the footer, “HID Global Corporation, part of ASSA ABLOY”. Assa Abloy seems Swedish but HID Global is a US company as far as a quick search goes. But without a proper company info page and privacy policy I wouldn’t consider it anywhere near a “good alternative” regardless.

The privacy policy is under legal in the footer, exactly where I'd expect it to be honest. It also gives the company registration: > 1.1. We, ZeroSSL GmbH, FN 443956b (the “Company“) and below that the company address (registered in Austria). Don't get me wrong, I agree that there is some lack of "who actually runs/controls this", especially on the about page where I expect such things to be. At the very least it's n…

I don’t see “legal” in the footer on mobile. Or any other link. Or a link to an About page in the main nav. There’s nothing.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#43
post #39

Can anyone explain me what went wrong with http://www.cacert.org/ and why they are not supported by any major browser ?

the wikipedia page has links to projects that removed CAcert where reasons are stated. the main one being that CAcert didn't complete a security audit or because they were not yet accepted by mozilla (because of the lack of an audit, but also because CAcert actually withdrew the request to be included). one group removed it because CAcert has a strict root redistribtion license that they can't follow.

LWN has a good writeup on the audit situation as of 2014: https://lwn.net/Articles/590879/

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#46

This somehow confirms my gut feeling that digital certificates are mainly a means to enforce exclusion on behalf of the certificate authority ownership. It is a tool to prevent people from taking full ownership and control of whatever is affected by digital certificates, be it software, firmware, hardware, or as in this case SSL/TLS. That's digital tyranny in disguise.

I always saw it as a trust-chain and think that anyone is welcomed to create a root certificate and distribute it to whomever trusts them. Most simple services may not need TLS, but with the ISPs eavesdropping on our communication, a form of secure communication is required and the currently best solution we have requires a trust-chain to be built.

We could, and should, switch to DANE. Or else, switch to how X.509 was supposed to be used, with each country running a CA for their nationals.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#48

This somehow confirms my gut feeling that digital certificates are mainly a means to enforce exclusion on behalf of the certificate authority ownership. It is a tool to prevent people from taking full ownership and control of whatever is affected by digital certificates, be it software, firmware, hardware, or as in this case SSL/TLS. That's digital tyranny in disguise.

> This somehow confirms my gut feeling that digital certificates are mainly a means to enforce exclusion on behalf of the certificate authority ownership. It is a tool to prevent people from taking full ownership and control of whatever is affected by digital certificates, be it software, firmware, hardware, or as in this case SSL/TLS. That's digital tyranny in disguise.

I think the "digital tyranny" is a side effect, not the main goal. They're "mainly a means" to prevent certain kinds of MITM attacks.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#49
post #33
post #25

Earlier quoted context omitted.

"US company must obey US law" doesn't make for a very interesting headline.

The headline is more « US law is batshit and extends well beyond its borders with real world consequences »

Exactly. Ever since I was a kid I never understood how the US has jurisdiction way beyond their borders.

Then I graduated in International Relations and understood that the hole is much deeper than that.

Now it's pretty obvious with all the shit that trump has been doing, but back then me and much of the people I know were oblivious to what US power really means.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#50
post #5
post #4

Has anyone got any experience with Zero SSL? https://zerossl.com/ It seems like a good EU alternative.

EU? There’s almost zero information on the company, no privacy policy? The only place I found any mention is the footer, “HID Global Corporation, part of ASSA ABLOY”. Assa Abloy seems Swedish but HID Global is a US company as far as a quick search goes. But without a proper company info page and privacy policy I wouldn’t consider it anywhere near a “good alternative” regardless.

Jumping in here since we’ve been seeing more mentions of ZeroSSL lately, likely related to the recent CA/B Forum discussions around 1‑year certificates and ACME automation.

- We’re based in Austria (ZeroSSL GmbH). The company was acquired by HID in 2024, which is part of Assa Abloy (Sweden).

- We’re not positioning ourselves as a purely EU-based CA substitute, and we generally don’t market it that way.

- For DV certs specifically, we act as a distributor. Under the hood these are Sectigo-issued certificates, similar to how other providers (for example Namecheap) operate.

Happy to clarify further if useful.

Post reply on HN