Live data from Hacker News

Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

letsencrypt.org

151–160 of 404 posts

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#151
post #146

Is Let's Encrypt the only provider of SSL certificates? Genuine question! Because I assumed there were other places you could get a SSL certificate, but people in this thread seem to be implying that without Let's Encrypt, there's no way for people in those sanctioned territories to get a cert.

If nothing has changed it's still the only one that's free and instant. Back in the day you'd had to pay $10/y and install manually

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#152
post #146

Is Let's Encrypt the only provider of SSL certificates? Genuine question! Because I assumed there were other places you could get a SSL certificate, but people in this thread seem to be implying that without Let's Encrypt, there's no way for people in those sanctioned territories to get a cert.

> Is Let's Encrypt the only provider of SSL certificates?

No.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#153

This should be one of those things that should be an quick EU win. Running Let's Encrypt is $3-4mill a year, the EU probably uses that on pencils. The EU could easily bootstrap a Let's Encrypt competitor if it truly cared about removing dependencies on US based entities.

Yes, but EU would have to convince Google and Apple to get a new root certificate to browsers.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#154
post #146

Is Let's Encrypt the only provider of SSL certificates? Genuine question! Because I assumed there were other places you could get a SSL certificate, but people in this thread seem to be implying that without Let's Encrypt, there's no way for people in those sanctioned territories to get a cert.

There are some options. actalis.com is European alternative but free tier is a bit less than Let's Encrypt.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#155
post #146

Is Let's Encrypt the only provider of SSL certificates? Genuine question! Because I assumed there were other places you could get a SSL certificate, but people in this thread seem to be implying that without Let's Encrypt, there's no way for people in those sanctioned territories to get a cert.

If it was a genuine question, the genuine answer is it's the provider that democratised streamlined ACME certificate verification and made it for free

No account, no payment, a single bash command or a certbot that runs regularly and you have your own globally recognised certificate

Historically, providers used to make the most frictions so that they could justify absolutely crazy fees for signing any certificates. It doesn't goes down well in DevOps, it doesn't work with indies who don't have 3 to 4 digits figures to blow in httpS, everyone including organisations ended up making certificates authorities of their own to sign stuff... and let's encrypt was successful at making certificates easy, free and actually secure

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#156
post #58

Earlier quoted context omitted.

Pretty much any big government has a CA they can exert direct control over whenever needed.

Maybe, but then can only do it once. Then they get caught, and their CA is distrusted. See Diginotar [0] for example. And things only gotten better since - we now have CT logs, and browsers require them, so any mis-issuance can be detected automatically, by any interested third party. If we go to DANE, we lose this all. "Oops, our CT uploader process failed, we will fix Real Soon(tm) we promise" - and what are browse…

The Dutch government didn't exercise control over Diginotar.

In the Dutch hacker scene, Diginotar was a meme. Everyone knew it was a mess there.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#157
post #33
post #25

Earlier quoted context omitted.

"US company must obey US law" doesn't make for a very interesting headline.

The headline is more « US law is batshit and extends well beyond its borders with real world consequences »

This is not specific to US law ...

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#158

Earlier quoted context omitted.

[flagged]

"concepts like "man" and "woman" are deeply sexist and offensive in their culture". Only to people who have a need to be offended.

[flagged]

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#160
post #64

Earlier quoted context omitted.

Other countries sanction each other too.

This is not about countries sanctioning each other. This is the US sanctioning a local company because a foreign company doesn’t follow certain US laws in foreign soil, where such laws don’t apply. It’s a bit like the US arresting your mom at home in Texas because you ate a baggie of magic truffles in Amsterdam.

The way you are using these words seems to indicate you might be confused about how this works.

The US has not "sanctioned" LetsEncrypt or ISRG. The US sanctions foreign entities as punishment for various reasons precisely because they are not subject to US law. That's the entire point of leveraging a sanction -- to pressure those outside of your legal jurisdiction. If they were in your jurisdiction, you'd simply arrest them.

People and organizations basically anywhere not permitted to do business with anyone your country has sanctioned. Anyone who does business internationally should be aware of their country's sanctioned list. That applies no matter where you live on the planet.

Post reply on HN