Live data from Hacker News

Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

letsencrypt.org

211–220 of 404 posts

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#211

Let's Encrypt’s mission is to create a more secure and privacy-respecting web, except for people residing in countries with the most need for a more secure and privacy-respecting web. Sure, that's great. That said, pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries. I'm sure some of y'all are old enough to remember when web browsers came in "international fr…

I’m actually old enough to remember how PGP code was exported as a book printout because exporting computer code for cryptography with strong keys in digital form was disallowed but a book was fine (protected by first amendment rights). The printout was scanned abroad to reconstitute the source and build pgp legally.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#212
post #183

Earlier quoted context omitted.

> I trust governments much less that a conglomerate of competing corporations. There’s no essential difference between the two from my perspective. Why are these my only choices?

One, in a democracy, is accountable to adults in the same jurisdiction. The other is only accountable to those with financial ties to its success.

>One, in a democracy, is accountable to adults in the same jurisdiction

Or so they say. How's that been working out in practice?

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#213
post #64
post #28

Earlier quoted context omitted.

It's about time SOME entities start moving from US entirely.

Other countries sanction each other too.

They mostly don't.

Or rather, when other countries say "sanctions", they are almost always talking about something completely different than the United States.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#214
post #200

Earlier quoted context omitted.

Philosophically, trust isn't a "solvable" problem. It can only be mitigated to varying degrees. However, some degree of trust is probably better than none.

One thing is sure, pinning trust on trust chains down from Root Certificate Authorities is fundamentally incompatible with our notion of trust and an almost absurd idea to start with. Most people using a browser don't even know any person from such an organization nor would or should they have any rational reason to trust them.

> our notion of trust

I suspect I may have a different notion of trust than you

> Most people using a browser don't even know any person from such an organization nor would or should they have any rational reason to trust them.

Back up one step further -- most people using a browser don't understand the problem set we're talking about even exists

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#215

Couldn't LE have a branch in Europe or anywhere outside the USA and its minions? Because they're betraying their own goals, as stated in their About page: “It is a service run for the public’s benefit. [...] Anyone who owns a domain name can use Let’s Encrypt to obtain a trusted certificate at zero cost. [...] Let’s Encrypt is a joint effort to benefit the community, beyond the control of any one organization.” Now t…

It shouldn't be located in Europe (because, as you said, US minions are no better than the US itself). Instead it should move to a neutral country, somewhere like Singapore or Uruguay.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#216
post #203

Earlier quoted context omitted.

It could also be an easy way to not have to implement backdoors for the government/military.

What "backdoor" would Let's Encrypt even implement? That's not how a CA works. They might be compelled to issue a certificate to an unauthorized (by browser PKI policies, not local law) entity, but that would be very conspicuous due to Certificate Transparency.

I suspect any "backdoor" would be inserted at the protocol level. See https://web.archive.org/web/20130918135152/http://www.thegua...

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#217
post #144

Earlier quoted context omitted.

Seems in all thing tech at the moment the US legal system is accelearting a great split and erectinga digital iron curtain, from AI models to the more mundane like TLS certs. Its been standard for a while for many Linux distros based in the US to toe the party line - like RedHat having notices pretty similar to this one by LE. Seems any meaningful Open Projects will have to choose what path they want to take, be like…

The RISC-V move was laughable. It’s still US tech, developed largely with DARPA funds.

So what? If I disagree with the direction any FOSS project (or its maintainers) is taking... I can just fork it. People have done that countless times in the history of FOSS, most notably in the xOffice schism.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#218
post #188

Earlier quoted context omitted.

If you truly need a secure and private web you should be using tor.

Say what, now? Anonymity and encrypted communication are two very, very different things. Have one but not the other and you're essentially handing off your private data incl. passwords to whoever that has a tap on the communication between you and the server can fetch them, too. Have the other but not the one and everyone will know who you are, but they can't eavesdrop.

I've had people straight up serve me malware when you attempt to OSINT them with Tor. Sometimes you need different kinds of anonymity, and I see a lot of one sized fits all proclamations on HN.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#219

Couldn't LE have a branch in Europe or anywhere outside the USA and its minions? Because they're betraying their own goals, as stated in their About page: “It is a service run for the public’s benefit. [...] Anyone who owns a domain name can use Let’s Encrypt to obtain a trusted certificate at zero cost. [...] Let’s Encrypt is a joint effort to benefit the community, beyond the control of any one organization.” Now t…

It shouldn't be located in Europe (because, as you said, US minions are no better than the US itself). Instead it should move to a neutral country, somewhere like Singapore or Uruguay.

Suddenly the idea of having a CA hosted in space on a satellite issuing certs seems like a good idea.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#220
post #28

Earlier quoted context omitted.

They could, but if the branch didn’t follow these laws, the main US branch would still be liable.

It's about time SOME entities start moving from US entirely.

This is part of why the EU is looking to move away from US-based infrastructure. The CLOUD Act basically lets Washington have an off-switch on your computing infrastructure as well as giving Washington unlimited access to any data on your computers (or that passes through them).
Post reply on HN