Earlier quoted context omitted.
> This somehow confirms my gut feeling that digital certificates are mainly a means to enforce exclusion on behalf of the certificate authority ownership. It is a tool to prevent people from taking full ownership and control of whatever is affected by digital certificates, be it software, firmware, hardware, or as in this case SSL/TLS. That's digital tyranny in disguise. I think the "digital tyranny" is a side effect…
I always thought the main goal was to force people to pay money for certificates.
Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
141–150 of 404 posts
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#142Earlier quoted context omitted.
Let's Encrypt certificates continue to be available in both Iran and Russia, just not for the Iranian and Russian governments. The terms of service update to clarify what we have always done, comply with relevant law, has not changed the situation for either country.
you should update the documents to reflect this stance. " You are not a person or entity that is: (a) located in, organized under the laws of, or ordinarily resident in any country or territory that is the target of comprehensive U.S. sanctions; " this says nothing (edit: specific) about government (edit: only), and is applicable to normal people in those areas.
Still needs updating if it's supposed to only apply to governments, though.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#143Earlier quoted context omitted.
> Let's Encrypt certificates continue to be available in both Iran and Russia, just not for the Iranian and Russian governments. According to https://news.ycombinator.com/item?id=48457280 it affects all people ordinarily resident in those territories, not just their governments: > You are not a person or entity that is: > (a) located in, organized under the laws of, or ordinarily resident in any country or territory…
I wonder what "ordinarily resident" means legally. Like has a permanent address there, even if they don't live there physically..?
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#144Let's Encrypt’s mission is to create a more secure and privacy-respecting web, except for people residing in countries with the most need for a more secure and privacy-respecting web. Sure, that's great. That said, pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries. I'm sure some of y'all are old enough to remember when web browsers came in "international fr…
Seems in all thing tech at the moment the US legal system is accelearting a great split and erectinga digital iron curtain, from AI models to the more mundane like TLS certs. Its been standard for a while for many Linux distros based in the US to toe the party line - like RedHat having notices pretty similar to this one by LE. Seems any meaningful Open Projects will have to choose what path they want to take, be like…
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#145Now this is very bad, as bad as it can get. As soon as all local services will stop working in sanctioned countries, those countries' governments will force all users to either install a root certificate or lose access to all local services and websites. And then it will be possible to use that root certificate for MITM attacks. In the worst case scenario, after the majority of users will install the root certificate…
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#146Genuine question! Because I assumed there were other places you could get a SSL certificate, but people in this thread seem to be implying that without Let's Encrypt, there's no way for people in those sanctioned territories to get a cert.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#147Is this a canary? What's gonna happen if I were to begin or continue using one letsencrypt certificate from ... Greenland? Cuba? The EU? Has letsencrypt been served with a subpoena?
> Has letsencrypt been served with a subpoena? While it's certainly possible that ISRG has been served a subpoena because it appears the US DOJ is now a mix of hacks and incompetent buffoons, it wouldn't matter because the whole point is that they don't know anything - what you told them is literally logged publicly for everybody to see without even knowing how to spell "subpoena" let alone issue one. Some people hav…
Looking at LavaBit^1 I really would not be so comfortable. The world and especially the US has not gotten more free since then.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#148This somehow confirms my gut feeling that digital certificates are mainly a means to enforce exclusion on behalf of the certificate authority ownership. It is a tool to prevent people from taking full ownership and control of whatever is affected by digital certificates, be it software, firmware, hardware, or as in this case SSL/TLS. That's digital tyranny in disguise.
I always saw it as a trust-chain and think that anyone is welcomed to create a root certificate and distribute it to whomever trusts them. Most simple services may not need TLS, but with the ISPs eavesdropping on our communication, a form of secure communication is required and the currently best solution we have requires a trust-chain to be built.
Russian government issued their new root certificate years ago.
Nobody trusted it enough to request a certificate from them or install it on their computers. Including almost all of the russian residents.
If Let's Encrypt enforces the rules, as written in pdf, a lot of people would lose a choice.
Frankly, even publishing a statement like that would make the scales of trust tip for some.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#149This should be one of those things that should be an quick EU win. Running Let's Encrypt is $3-4mill a year, the EU probably uses that on pencils. The EU could easily bootstrap a Let's Encrypt competitor if it truly cared about removing dependencies on US based entities.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#150Earlier quoted context omitted.
This is not about countries sanctioning each other. This is the US sanctioning a local company because a foreign company doesn’t follow certain US laws in foreign soil, where such laws don’t apply. It’s a bit like the US arresting your mom at home in Texas because you ate a baggie of magic truffles in Amsterdam.
You're being very vague. Please explain what you mean? I don't see anything here about the US "sanctioning a local company," and I'm not aware of that being possible under US law.