Live data from Hacker News

Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

letsencrypt.org

181–190 of 404 posts

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#181

Earlier quoted context omitted.

They have the secret of the private keys used to sign certificates. Looking at LavaBit^1 I really would not be so comfortable. The world and especially the US has not gotten more free since then. [1] https://en.wikipedia.org/wiki/Lavabit

They could mint certificates, for / about any name. But, those certificates won't work in popular applications unless the certificates include proof of logging. So to be effective this means a hypothetical bad actor (maybe the US government or anybody else) issues bogus certificates, then either logs them - making a permanent record for everybody to see, or also subverts two or more logs, so that they issue bogus pro…

For the vast majority of cases, would anyone notice these malicious certificates being created and logged?

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#182

Earlier quoted context omitted.

The way you are using these words seems to indicate you might be confused about how this works. The US has not "sanctioned" LetsEncrypt or ISRG. The US sanctions foreign entities as punishment for various reasons precisely because they are not subject to US law. That's the entire point of leveraging a sanction -- to pressure those outside of your legal jurisdiction. If they were in your jurisdiction, you'd simply arr…

This is not that though. This is literally about a company that has a branch in the USA and another branch in another country, where it's bound by that country's laws. If the foreign entity which just so happens to be commercially linked to the one in the USA has any dealings with countries sanctioned by the US, the US branch is punished. There was a case a few years ago where a public University in Brazil bought lab…

Incorporating a subsidiary in a foreign country doesn't make the parent company immune to the legal obligations it has in it's home country. It would be absurd if that were the case. Sometimes people try setting up subsidiaries overseas to hide their evasion of the law, but it is illegal to do so.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#183
post #51

Earlier quoted context omitted.

I trust governments much less that a conglomerate of competing corporations. With all the problems with Web PKI, at least the bad actors are getting distrusted, and this provides a very strong enforcement on the rest. And Certificate Transparency makes sure the mis-issuance would be caught. It is not perfect by any means, but things are getting better. With DANE (or other country-issued certificates), every governmen…

> I trust governments much less that a conglomerate of competing corporations. There’s no essential difference between the two from my perspective. Why are these my only choices?

One, in a democracy, is accountable to adults in the same jurisdiction. The other is only accountable to those with financial ties to its success.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#184

Earlier quoted context omitted.

They could mint certificates, for / about any name. But, those certificates won't work in popular applications unless the certificates include proof of logging. So to be effective this means a hypothetical bad actor (maybe the US government or anybody else) issues bogus certificates, then either logs them - making a permanent record for everybody to see, or also subverts two or more logs, so that they issue bogus pro…

For the vast majority of cases, would anyone notice these malicious certificates being created and logged?

What constitutes the "vast majority" ? Periodically I check mine, and I sometimes have reason to check others, I no longer run my own log auditing (I did when I worked somewhere else because it was close to my main field of interest) but other people do.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#186
Is this actually new? Looks like a standard US export restriction for encryption technology to me. These sorts of restrictions have been around since the '90s.

Let's Encrypt becomes subject to US export restrictions on cryptography if they are a US company, or if they post anything to github or post anything to major app stores. Every app I have ever posted to Google Play has had to submit a form to the US government declaring what use they make of cryptography.

These restrictions have been in force since that late 1950s (with a long and complicated history with respect to computer cryptography). This particular text looks like a boilerplate restriction, that's required to comply with US EAR export requirements to me.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#187

This somehow confirms my gut feeling that digital certificates are mainly a means to enforce exclusion on behalf of the certificate authority ownership. It is a tool to prevent people from taking full ownership and control of whatever is affected by digital certificates, be it software, firmware, hardware, or as in this case SSL/TLS. That's digital tyranny in disguise.

The entire point of a trust model is to exclude people. That's the stated goal. If you want encryption without trust, just use self-signed certs.

The problem is that the current trust model is totally untrustworthy.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#188

Let's Encrypt’s mission is to create a more secure and privacy-respecting web, except for people residing in countries with the most need for a more secure and privacy-respecting web. Sure, that's great. That said, pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries. I'm sure some of y'all are old enough to remember when web browsers came in "international fr…

If you truly need a secure and private web you should be using tor.

Say what, now?

Anonymity and encrypted communication are two very, very different things. Have one but not the other and you're essentially handing off your private data incl. passwords to whoever that has a tap on the communication between you and the server can fetch them, too. Have the other but not the one and everyone will know who you are, but they can't eavesdrop.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#189
post #28

Earlier quoted context omitted.

It's about time SOME entities start moving from US entirely.

RISC-V Foundation did.. though they go out of their way to talk about it in terms that try not to piss anyone off.. > "Across 2018-2019, the RISC-V community has reflected on the geo-political landscape and we have heard concerns from around the world that investment in RISC-V must come with IP access continuity to ensure a long-term strategic investment. We first mentioned our intentions to move at the December 2018…

The RISC-V foundation and related companies also got a bunch of money from Europe. I am not so sure this was about leaving a repressive regime as much as chasing the European "homegrown computing" money.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#190
post #187

Earlier quoted context omitted.

The entire point of a trust model is to exclude people. That's the stated goal. If you want encryption without trust, just use self-signed certs.

The problem is that the current trust model is totally untrustworthy.

Philosophically, trust isn't a "solvable" problem. It can only be mitigated to varying degrees. However, some degree of trust is probably better than none.
Post reply on HN