Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
201–210 of 404 posts
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#202Is this a canary? What's gonna happen if I were to begin or continue using one letsencrypt certificate from ... Greenland? Cuba? The EU? Has letsencrypt been served with a subpoena?
> Has letsencrypt been served with a subpoena? While it's certainly possible that ISRG has been served a subpoena because it appears the US DOJ is now a mix of hacks and incompetent buffoons, it wouldn't matter because the whole point is that they don't know anything - what you told them is literally logged publicly for everybody to see without even knowing how to spell "subpoena" let alone issue one. Some people hav…
LetsEncrypt certainly doesn't, but I've seen certificate storefronts that generate the key on their side and provide you the key and the certificate, so you don't have to figure out how to generate a key.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#203Let's Encrypt’s mission is to create a more secure and privacy-respecting web, except for people residing in countries with the most need for a more secure and privacy-respecting web. Sure, that's great. That said, pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries. I'm sure some of y'all are old enough to remember when web browsers came in "international fr…
It could also be an easy way to not have to implement backdoors for the government/military.
They might be compelled to issue a certificate to an unauthorized (by browser PKI policies, not local law) entity, but that would be very conspicuous due to Certificate Transparency.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#204Earlier quoted context omitted.
They could mint certificates, for / about any name. But, those certificates won't work in popular applications unless the certificates include proof of logging. So to be effective this means a hypothetical bad actor (maybe the US government or anybody else) issues bogus certificates, then either logs them - making a permanent record for everybody to see, or also subverts two or more logs, so that they issue bogus pro…
For the vast majority of cases, would anyone notice these malicious certificates being created and logged?
I would like to think at least all the high profile destinations have someone watching.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#205Earlier quoted context omitted.
I always saw it as a trust-chain and think that anyone is welcomed to create a root certificate and distribute it to whomever trusts them. Most simple services may not need TLS, but with the ISPs eavesdropping on our communication, a form of secure communication is required and the currently best solution we have requires a trust-chain to be built.
Do we also need to put all our letters into strongboxes before we send them? Maybe we should have solve the ISP snooping problem by making that illegal instead.
If it were as cheap and efficient as TLS these days, yes, absolutely
> Maybe we should have solve the ISP snooping problem by making that illegal instead.
We could do both! ISP snooping is still a problem for metadata (SNI).
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#206This somehow confirms my gut feeling that digital certificates are mainly a means to enforce exclusion on behalf of the certificate authority ownership. It is a tool to prevent people from taking full ownership and control of whatever is affected by digital certificates, be it software, firmware, hardware, or as in this case SSL/TLS. That's digital tyranny in disguise.
The entire point of a trust model is to exclude people. That's the stated goal. If you want encryption without trust, just use self-signed certs.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#207This should be one of those things that should be an quick EU win. Running Let's Encrypt is $3-4mill a year, the EU probably uses that on pencils. The EU could easily bootstrap a Let's Encrypt competitor if it truly cared about removing dependencies on US based entities.
Yes, but EU would have to convince Google and Apple to get a new root certificate to browsers.
Cross-signed roots are common. Just takes money and maybe audits, but it's the same audit they'd need to get in the browser root stores anyway.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#208Earlier quoted context omitted.
"US company must obey US law" doesn't make for a very interesting headline.
The headline is more « US law is batshit and extends well beyond its borders with real world consequences »
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#209Iran is blocking internet for months, US ...bans creation of secure connections - that'll show 'em! Russian quasi-government structures are spending quadrillion of rubles on a TSPU (censorship system) to spy on Russian residents, US ...helps them by making snooping on what is currently encrypted traffic possible by banning accessible encryption!
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#210Let's Encrypt’s mission is to create a more secure and privacy-respecting web, except for people residing in countries with the most need for a more secure and privacy-respecting web. Sure, that's great. That said, pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries. I'm sure some of y'all are old enough to remember when web browsers came in "international fr…
> pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries This is most likely OFAC. Lets Encrypt could apply for a license to do business with sanctioned entities, and given their use case it would most likely be approved. https://ofac.treasury.gov/ofac-license-application-page