Live data from Hacker News

Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

letsencrypt.org

61–70 of 404 posts

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#61
post #28

Earlier quoted context omitted.

They could, but if the branch didn’t follow these laws, the main US branch would still be liable.

It's about time SOME entities start moving from US entirely.

RISC-V Foundation did.. though they go out of their way to talk about it in terms that try not to piss anyone off..

> "Across 2018-2019, the RISC-V community has reflected on the geo-political landscape and we have heard concerns from around the world that investment in RISC-V must come with IP access continuity to ensure a long-term strategic investment. We first mentioned our intentions to move at the December 2018 summit. Incorporation in Switzerland has the effect of calming concerns of political disruption to the open collaboration model. RISC-V International does not maintain any commercial interest in products or services as a non-profit, membership organization. There have not been any export restrictions on RISC-V in the US and we have complied with all US laws. The move does not circumvent any existing restrictions, but rather alleviates uncertainty going forward.

> In March 2020, the RISC-V International Association was incorporated in Switzerland. Along with this, we shifted to a new, more inclusive membership structure. Members of RISC-V International have access to and participate in the development of the RISC-V ISA specification and extensions as well as related hardware and software. RISC-V has a Board of Directors composed of member representatives as well as a Technical Committee of work group leaders."

> RISC-V International has not incorporated in Switzerland based on any one country, company, government, or event. This move is reflective of community concern and managing strategic risk for our community investing in RISC-V for the next 50+ years.

> The IP contributed and produced by RISC-V International is held under industry and global standard licenses that are already open to leverage by any company regardless of jurisdiction. This licensing is a common open source approach to foster collaboration that is not tied to any geographic regulation. IP in the public domain has not been subject to export control.

https://riscv.org/about/

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#62
post #51

Earlier quoted context omitted.

We could, and should, switch to DANE. Or else, switch to how X.509 was supposed to be used, with each country running a CA for their nationals.

I trust governments much less that a conglomerate of competing corporations. With all the problems with Web PKI, at least the bad actors are getting distrusted, and this provides a very strong enforcement on the rest. And Certificate Transparency makes sure the mis-issuance would be caught. It is not perfect by any means, but things are getting better. With DANE (or other country-issued certificates), every governmen…

> every government will absolutely double-issue certificates to police, secret service and friends of goverment, and no one will have any recourse.

Countries already have CA that issue certificates with more legal force than a handwritten signature. I can open a bank account, pay my taxes and sign up to all government services. But I can't use them for a webpage.

> With DANE (or other country-issued certificates)

DANE isn't a country-issued certificate. It's a scheme where you store your public keys on DNS records. Of course, now we have the issue that DNSSEC (signed DNS records) isn't widespread and the whole issue with DNS registries.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#63
post #6

Is this a canary? What's gonna happen if I were to begin or continue using one letsencrypt certificate from ... Greenland? Cuba? The EU? Has letsencrypt been served with a subpoena?

Neither Greenland nor the EU has been sanctioned by the US.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#64
post #28

Earlier quoted context omitted.

They could, but if the branch didn’t follow these laws, the main US branch would still be liable.

It's about time SOME entities start moving from US entirely.

Other countries sanction each other too.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#65
post #63
post #6

Is this a canary? What's gonna happen if I were to begin or continue using one letsencrypt certificate from ... Greenland? Cuba? The EU? Has letsencrypt been served with a subpoena?

Neither Greenland nor the EU has been sanctioned by the US.

They haven't been sanctioned, yet, but we live in a time where that's a real possibility.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#66
post #63
post #6

Is this a canary? What's gonna happen if I were to begin or continue using one letsencrypt certificate from ... Greenland? Cuba? The EU? Has letsencrypt been served with a subpoena?

Neither Greenland nor the EU has been sanctioned by the US.

So far

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#67
post #63
post #6

Is this a canary? What's gonna happen if I were to begin or continue using one letsencrypt certificate from ... Greenland? Cuba? The EU? Has letsencrypt been served with a subpoena?

Neither Greenland nor the EU has been sanctioned by the US.

It is not exactly an outlandish suggestion that this may happen.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#68
post #63
post #6

Is this a canary? What's gonna happen if I were to begin or continue using one letsencrypt certificate from ... Greenland? Cuba? The EU? Has letsencrypt been served with a subpoena?

Neither Greenland nor the EU has been sanctioned by the US.

Yet.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#70
post #60

Earlier quoted context omitted.

Do we also need to put all our letters into strongboxes before we send them? Maybe we should have solve the ISP snooping problem by making that illegal instead.

This just leaves every single public Wifi network - which used to mess with traffic a lot

Guys, we live in a society.
Post reply on HN