Live data from Hacker News

Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

letsencrypt.org

201–210 of 404 posts

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#202
post #6

Is this a canary? What's gonna happen if I were to begin or continue using one letsencrypt certificate from ... Greenland? Cuba? The EU? Has letsencrypt been served with a subpoena?

> Has letsencrypt been served with a subpoena? While it's certainly possible that ISRG has been served a subpoena because it appears the US DOJ is now a mix of hacks and incompetent buffoons, it wouldn't matter because the whole point is that they don't know anything - what you told them is literally logged publicly for everybody to see without even knowing how to spell "subpoena" let alone issue one. Some people hav…

> Some people have this insane idea that somehow the CA has some secret which either they minted and sent to the CA, or the CA minted and gave them a copy and so the US government could get this secret with a subpoena

LetsEncrypt certainly doesn't, but I've seen certificate storefronts that generate the key on their side and provide you the key and the certificate, so you don't have to figure out how to generate a key.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#203

Let's Encrypt’s mission is to create a more secure and privacy-respecting web, except for people residing in countries with the most need for a more secure and privacy-respecting web. Sure, that's great. That said, pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries. I'm sure some of y'all are old enough to remember when web browsers came in "international fr…

It could also be an easy way to not have to implement backdoors for the government/military.

What "backdoor" would Let's Encrypt even implement? That's not how a CA works.

They might be compelled to issue a certificate to an unauthorized (by browser PKI policies, not local law) entity, but that would be very conspicuous due to Certificate Transparency.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#204

Earlier quoted context omitted.

They could mint certificates, for / about any name. But, those certificates won't work in popular applications unless the certificates include proof of logging. So to be effective this means a hypothetical bad actor (maybe the US government or anybody else) issues bogus certificates, then either logs them - making a permanent record for everybody to see, or also subverts two or more logs, so that they issue bogus pro…

For the vast majority of cases, would anyone notice these malicious certificates being created and logged?

I don't subscribe for my personal domains, because who cares, but when I was in charge of certificates for something important I subscribed to notifications from several providers to make sure I didn't miss anything.

I would like to think at least all the high profile destinations have someone watching.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#205

Earlier quoted context omitted.

I always saw it as a trust-chain and think that anyone is welcomed to create a root certificate and distribute it to whomever trusts them. Most simple services may not need TLS, but with the ISPs eavesdropping on our communication, a form of secure communication is required and the currently best solution we have requires a trust-chain to be built.

Do we also need to put all our letters into strongboxes before we send them? Maybe we should have solve the ISP snooping problem by making that illegal instead.

> Do we also need to put all our letters into strongboxes before we send them?

If it were as cheap and efficient as TLS these days, yes, absolutely

> Maybe we should have solve the ISP snooping problem by making that illegal instead.

We could do both! ISP snooping is still a problem for metadata (SNI).

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#206

This somehow confirms my gut feeling that digital certificates are mainly a means to enforce exclusion on behalf of the certificate authority ownership. It is a tool to prevent people from taking full ownership and control of whatever is affected by digital certificates, be it software, firmware, hardware, or as in this case SSL/TLS. That's digital tyranny in disguise.

The entire point of a trust model is to exclude people. That's the stated goal. If you want encryption without trust, just use self-signed certs.

If you don't care about who you're talking to, why use certificates at all?

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#207

This should be one of those things that should be an quick EU win. Running Let's Encrypt is $3-4mill a year, the EU probably uses that on pencils. The EU could easily bootstrap a Let's Encrypt competitor if it truly cared about removing dependencies on US based entities.

Yes, but EU would have to convince Google and Apple to get a new root certificate to browsers.

Not really. They just have to convince an existing CA that cross-signing their CA won't make Google and Apple mad.

Cross-signed roots are common. Just takes money and maybe audits, but it's the same audit they'd need to get in the browser root stores anyway.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#208
post #33
post #25

Earlier quoted context omitted.

"US company must obey US law" doesn't make for a very interesting headline.

The headline is more « US law is batshit and extends well beyond its borders with real world consequences »

US law is something US citizens get to decide. If they think it's "batshit", they should vote accordingly. In this case sanctions seem a pretty good alternative to going to war.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#209

Iran is blocking internet for months, US ...bans creation of secure connections - that'll show 'em! Russian quasi-government structures are spending quadrillion of rubles on a TSPU (censorship system) to spy on Russian residents, US ...helps them by making snooping on what is currently encrypted traffic possible by banning accessible encryption!

[Iranian here] Completely agreed. Reminds me of how US banned citizens and businesses in Iran from using cloud infrastructure like AWS or digital ocean, leading to people and businesses moving to the government-sponsored local cloud services, and that made it super easy for the government to block internet access whenever they want without essential services like banking, ecommerce, online taxi booking, food delivery etc being disrupted.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#210
post #175

Let's Encrypt’s mission is to create a more secure and privacy-respecting web, except for people residing in countries with the most need for a more secure and privacy-respecting web. Sure, that's great. That said, pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries. I'm sure some of y'all are old enough to remember when web browsers came in "international fr…

> pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries This is most likely OFAC. Lets Encrypt could apply for a license to do business with sanctioned entities, and given their use case it would most likely be approved. https://ofac.treasury.gov/ofac-license-application-page

OFAC regulates commerce, not speech. Let's Encrypt is not doing "business", they're operating a free informational service. Lots of organizations interpret any information exchange as subject to OFAC regulation, and you and Let's Encrypt have good company in this interpretation, but I think it's unnecessarily ceding ground.
Post reply on HN