Live data from Hacker News

Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

letsencrypt.org

101–110 of 404 posts

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#101
Let's Encrypt’s mission is to create a more secure and privacy-respecting web, except for people residing in countries with the most need for a more secure and privacy-respecting web. Sure, that's great.

That said, pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries. I'm sure some of y'all are old enough to remember when web browsers came in "international friendly" versions that supported 40 bit encryption, or "fancy secure" versions with 128 bit encryption.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#102
post #71

Earlier quoted context omitted.

love thought-terminating cliches. really helps keep from actually thinking ever.

Your comment reads like a thought-terminating cliché. If Russia occupied your city, killed your family and friends and left you homeless, you might reconsider giving freedom to those who take it away from others. Unfortunately, sanctions are often very easy to evade.

Ah right, that's why there's US sanctions on Israel?

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#103
post #9

Earlier quoted context omitted.

3 90-day ACME certs for free. 180€/year for unlimited 90-day certs and 5 yearly ones. That’s a pretty steep increase. I would almost be more interested in a monthly fee per cert.

From their docs[0] this doesn't seem to apply if using ACME, but they don't exactly make that clear... > By using ZeroSSL's ACME feature, you will be able to generate an unlimited amount of 90-day SSL certificates at no charge, also supporting multi-domain certificates and wildcards. Each certificate you create will be stored in your ZeroSSL account. [0]: https://zerossl.com/documentation/acme/

Yeah, they don't make it that clear, but you get basically the same functionality as with LetsEncrypt for free, including wildcard certs. You basically only need to pay for manually issued certs, or some of their other additional features.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#104
post #50
post #5

Earlier quoted context omitted.

EU? There’s almost zero information on the company, no privacy policy? The only place I found any mention is the footer, “HID Global Corporation, part of ASSA ABLOY”. Assa Abloy seems Swedish but HID Global is a US company as far as a quick search goes. But without a proper company info page and privacy policy I wouldn’t consider it anywhere near a “good alternative” regardless.

Jumping in here since we’ve been seeing more mentions of ZeroSSL lately, likely related to the recent CA/B Forum discussions around 1‑year certificates and ACME automation. - We’re based in Austria (ZeroSSL GmbH). The company was acquired by HID in 2024, which is part of Assa Abloy (Sweden). - We’re not positioning ourselves as a purely EU-based CA substitute, and we generally don’t market it that way. - For DV certs…

Sectigo used to be Comodo's CA business. If memory serves, that business was purchased by a US PE firm and renamed "Sectigo". Sectigo Inc.'s corporate headquarters is now in Scottsdale, AZ.

There's no reason to believe they're any less subject to US jurisdiction than LetsEncrypt.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#105

This somehow confirms my gut feeling that digital certificates are mainly a means to enforce exclusion on behalf of the certificate authority ownership. It is a tool to prevent people from taking full ownership and control of whatever is affected by digital certificates, be it software, firmware, hardware, or as in this case SSL/TLS. That's digital tyranny in disguise.

> This somehow confirms my gut feeling that digital certificates are mainly a means to enforce exclusion on behalf of the certificate authority ownership. It is a tool to prevent people from taking full ownership and control of whatever is affected by digital certificates, be it software, firmware, hardware, or as in this case SSL/TLS. That's digital tyranny in disguise. I think the "digital tyranny" is a side effect…

I always thought the main goal was to force people to pay money for certificates.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#106
post #91

Maybe consolidating ~60% of the web's certificates on to a single provider was a mistake.

Well good thing everyone using the provider is using an open protocol and it's stupid easy to switch

Which free CA should I use instead of lets encrypt that has same browser support?

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#108

This somehow confirms my gut feeling that digital certificates are mainly a means to enforce exclusion on behalf of the certificate authority ownership. It is a tool to prevent people from taking full ownership and control of whatever is affected by digital certificates, be it software, firmware, hardware, or as in this case SSL/TLS. That's digital tyranny in disguise.

While it seems like certificate authority has the primary control here, the real control lies in browsers and operative systems in which certificate authorities are trusted. Users also have, at least for the moment, control to add or remove certificate authorities, even if that control is slightly less clear for devices like smart phones.

Digital certificates that signs software packages are used to enforce exclusion by some manufacturers. Let's encrypt is not in that space to my knowledge, but it is a place where you the owner do not have the right to determine which certificate authority should be trusted, and generally the only one that is trusted is the manufacturer. Its arguable if we even should be calling such entities a certificate authority, even if they technically are the owner of the root certificate that signs the package.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#109

This somehow confirms my gut feeling that digital certificates are mainly a means to enforce exclusion on behalf of the certificate authority ownership. It is a tool to prevent people from taking full ownership and control of whatever is affected by digital certificates, be it software, firmware, hardware, or as in this case SSL/TLS. That's digital tyranny in disguise.

I always saw it as a trust-chain and think that anyone is welcomed to create a root certificate and distribute it to whomever trusts them. Most simple services may not need TLS, but with the ISPs eavesdropping on our communication, a form of secure communication is required and the currently best solution we have requires a trust-chain to be built.

It is such a great improvement that ISPs cannot eavesdrop us anymore... only for everyone to terminate TLS at cloudflare so they (and thus US government) can now eavesdrop everyone.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#110

Earlier quoted context omitted.

Well good thing everyone using the provider is using an open protocol and it's stupid easy to switch

Which free CA should I use instead of lets encrypt that has same browser support?

ZeroSSL / BuyPass
Post reply on HN