Live data from Hacker News

Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

letsencrypt.org

81–90 of 404 posts

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#81

This actually makes sense. No freedom for the enemies of freedom.

the list of ppl under US sanctions is staggering

Europe starts to shield itself from the risk since Nicolas Guillou, the French ICC judge who issued a warrant against bibi got sanctioned (France officially protested about this case)

China is being successful at blocking US firms out of their supply chains (they already use Linux on Loongarch processors with some homemade architecture and pioneer RISC V), since a bunch of their companies also got sanctions for supplying the governement

US stands so much for freedom that it's the first country to refuse immigration to FIFA world cup teams and athletes, with Iranians not allowed to stay between games and Somali goalkeeper being turned away at the border. Germany itself didn't do for the 1936 Olympics.

So at best, they're only shooting themselves in the foot by showing any US component in a supply chain is a risk, while using US clouds were already a risk of loss of revenue from FISA requests to undercut your bid and rot your company and using US dollars for trade was already a liability

In the meantime, US companies can do anything, break any financial law and abuse every human right, they'll just sign DPAs to avoid prosecution

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#82
post #28

Earlier quoted context omitted.

They could, but if the branch didn’t follow these laws, the main US branch would still be liable.

It's about time SOME entities start moving from US entirely.

[flagged]

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#83
Iran is blocking internet for months, US ...bans creation of secure connections - that'll show 'em!

Russian quasi-government structures are spending quadrillion of rubles on a TSPU (censorship system) to spy on Russian residents, US ...helps them by making snooping on what is currently encrypted traffic possible by banning accessible encryption!

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#84

> active eavesdropping (e.g., monster-in-the-middle attacks) is this standard MitM, or is it some crucially distinct variation?

[flagged]

"concepts like "man" and "woman" are deeply sexist and offensive in their culture".

Only to people who have a need to be offended.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#85

Earlier quoted context omitted.

I kinda like this framing. It effectively classifies companies such as Zscaler and CloudFlare as monsters.

It's particularly funny because "monster-in-the-middle" appears to be a deliberately quirky marketing term invented by cloudflare.

Fun fact: some older articles were originally written using the term man-in-the-middle, but at some point were updated... except that the diagrams still use man-in-the-middle because search-and-replace doesn't work on images.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#86
This is bullshit on par with the Chinese firewall, meant to effectively prevent the (entire!) western world from information by parties deemed persona non-grata. SSL certificates are supposed to be about security, not geopolitics.

I'm pretty sure a LE server hitting an Iranian or North Korean endpoint and validating a crypto challenge does not break any OFAC or EAR rules, and no money changes hands. And if a non-US entity wants to do it, the US would just sanction them. Microsoft and Mozilla are certainly not going to include a North Korean or Russian state CA in the root trusted certs (and if they did, the US government could just threaten them with sanctions, too).

Hard not to say "we warned you" about making self-signed certs completely unusable in favor of a very centralized approach.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#87
post #71

Earlier quoted context omitted.

love thought-terminating cliches. really helps keep from actually thinking ever.

Your comment reads like a thought-terminating cliché. If Russia occupied your city, killed your family and friends and left you homeless, you might reconsider giving freedom to those who take it away from others. Unfortunately, sanctions are often very easy to evade.

Now imagine the USA did that to the city you live in...

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#88
post #33
post #25

Earlier quoted context omitted.

"US company must obey US law" doesn't make for a very interesting headline.

The headline is more « US law is batshit and extends well beyond its borders with real world consequences »

This is not an example of that. It is perfectly within US jurisdiction to prevent US companies from doing business with sanctioned countries. That is the point of a sanction, and US is in good company in choosing to use sanctions as a diplomatic tool.

It is more of an example of how the internet/software industry is too consolidated to the US, and thus other countries are too dependent on the US in those areas. If the internet infrastructure was well distributed, then people in sanction countries could simply get certificates issued by a different CA, and in some cases they can. However, this is complicated by the fact that the list of trusted CAs is dominated by US organizations (Google, Mozilla, Apple, Microsoft). If you want to reach western audience you must use certs from a CA approved by them.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#89

Iran is blocking internet for months, US ...bans creation of secure connections - that'll show 'em! Russian quasi-government structures are spending quadrillion of rubles on a TSPU (censorship system) to spy on Russian residents, US ...helps them by making snooping on what is currently encrypted traffic possible by banning accessible encryption!

wait until you find out about Facebook!

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#90
post #50
post #5

Earlier quoted context omitted.

EU? There’s almost zero information on the company, no privacy policy? The only place I found any mention is the footer, “HID Global Corporation, part of ASSA ABLOY”. Assa Abloy seems Swedish but HID Global is a US company as far as a quick search goes. But without a proper company info page and privacy policy I wouldn’t consider it anywhere near a “good alternative” regardless.

Jumping in here since we’ve been seeing more mentions of ZeroSSL lately, likely related to the recent CA/B Forum discussions around 1‑year certificates and ACME automation. - We’re based in Austria (ZeroSSL GmbH). The company was acquired by HID in 2024, which is part of Assa Abloy (Sweden). - We’re not positioning ourselves as a purely EU-based CA substitute, and we generally don’t market it that way. - For DV certs…

Any plans on becoming an independent CA? Would certificates issued in your name also risk being affected by US sanctions trough sentigo?
Post reply on HN