Earlier quoted context omitted.
They have the secret of the private keys used to sign certificates. Looking at LavaBit^1 I really would not be so comfortable. The world and especially the US has not gotten more free since then. [1] https://en.wikipedia.org/wiki/Lavabit
They could mint certificates, for / about any name. But, those certificates won't work in popular applications unless the certificates include proof of logging. So to be effective this means a hypothetical bad actor (maybe the US government or anybody else) issues bogus certificates, then either logs them - making a permanent record for everybody to see, or also subverts two or more logs, so that they issue bogus pro…
Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
181–190 of 404 posts
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#182Earlier quoted context omitted.
The way you are using these words seems to indicate you might be confused about how this works. The US has not "sanctioned" LetsEncrypt or ISRG. The US sanctions foreign entities as punishment for various reasons precisely because they are not subject to US law. That's the entire point of leveraging a sanction -- to pressure those outside of your legal jurisdiction. If they were in your jurisdiction, you'd simply arr…
This is not that though. This is literally about a company that has a branch in the USA and another branch in another country, where it's bound by that country's laws. If the foreign entity which just so happens to be commercially linked to the one in the USA has any dealings with countries sanctioned by the US, the US branch is punished. There was a case a few years ago where a public University in Brazil bought lab…
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#183Earlier quoted context omitted.
I trust governments much less that a conglomerate of competing corporations. With all the problems with Web PKI, at least the bad actors are getting distrusted, and this provides a very strong enforcement on the rest. And Certificate Transparency makes sure the mis-issuance would be caught. It is not perfect by any means, but things are getting better. With DANE (or other country-issued certificates), every governmen…
> I trust governments much less that a conglomerate of competing corporations. There’s no essential difference between the two from my perspective. Why are these my only choices?
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#184Earlier quoted context omitted.
They could mint certificates, for / about any name. But, those certificates won't work in popular applications unless the certificates include proof of logging. So to be effective this means a hypothetical bad actor (maybe the US government or anybody else) issues bogus certificates, then either logs them - making a permanent record for everybody to see, or also subverts two or more logs, so that they issue bogus pro…
For the vast majority of cases, would anyone notice these malicious certificates being created and logged?
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#185Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#186Let's Encrypt becomes subject to US export restrictions on cryptography if they are a US company, or if they post anything to github or post anything to major app stores. Every app I have ever posted to Google Play has had to submit a form to the US government declaring what use they make of cryptography.
These restrictions have been in force since that late 1950s (with a long and complicated history with respect to computer cryptography). This particular text looks like a boilerplate restriction, that's required to comply with US EAR export requirements to me.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#187This somehow confirms my gut feeling that digital certificates are mainly a means to enforce exclusion on behalf of the certificate authority ownership. It is a tool to prevent people from taking full ownership and control of whatever is affected by digital certificates, be it software, firmware, hardware, or as in this case SSL/TLS. That's digital tyranny in disguise.
The entire point of a trust model is to exclude people. That's the stated goal. If you want encryption without trust, just use self-signed certs.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#188Let's Encrypt’s mission is to create a more secure and privacy-respecting web, except for people residing in countries with the most need for a more secure and privacy-respecting web. Sure, that's great. That said, pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries. I'm sure some of y'all are old enough to remember when web browsers came in "international fr…
If you truly need a secure and private web you should be using tor.
Anonymity and encrypted communication are two very, very different things. Have one but not the other and you're essentially handing off your private data incl. passwords to whoever that has a tap on the communication between you and the server can fetch them, too. Have the other but not the one and everyone will know who you are, but they can't eavesdrop.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#189Earlier quoted context omitted.
It's about time SOME entities start moving from US entirely.
RISC-V Foundation did.. though they go out of their way to talk about it in terms that try not to piss anyone off.. > "Across 2018-2019, the RISC-V community has reflected on the geo-political landscape and we have heard concerns from around the world that investment in RISC-V must come with IP access continuity to ensure a long-term strategic investment. We first mentioned our intentions to move at the December 2018…
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#190Earlier quoted context omitted.
The entire point of a trust model is to exclude people. That's the stated goal. If you want encryption without trust, just use self-signed certs.
The problem is that the current trust model is totally untrustworthy.