Live data from Hacker News

Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

letsencrypt.org

231–240 of 404 posts

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#231
post #223

Earlier quoted context omitted.

> Incorporating a subsidiary in a foreign country doesn't make the parent company immune to the legal obligations it has in it's home country. We're not talking about legal obligations in its home country though . I can buy Jack Daniels at age 19 in my country from their local subsidiary, and no-one thinks that this should be a crime for their US parent company because the US drinking age is higher. (Of course it wou…

If you are in the US you must ensure that your local company, and any sub-entity you control abroad complies with sanctions law. That is US law, and the US can apply that law to Dell the parent company, because it is in the US and controls the subsidary. > I can buy Jack Daniels at age 19 in my country from their local subsidiary, and no-one thinks that this should be a crime for their US parent company because the U…

US sanctions law saying that you must not transfer X from the US to Iran, directly or indirectly, is reasonable. US sanctions law saying that you must not transfer X from Brazil to Iran is gross overreach. Yes, of course the US can apply its absurdly extraterritorial laws to any parent company in the US, just as Iran could penalise any Iranian company whose US subsidiary distributed a depiction of the prophet or whatever, but that doesn't make it good law or good practice.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#232
post #203

Earlier quoted context omitted.

What "backdoor" would Let's Encrypt even implement? That's not how a CA works. They might be compelled to issue a certificate to an unauthorized (by browser PKI policies, not local law) entity, but that would be very conspicuous due to Certificate Transparency.

I suspect any "backdoor" would be inserted at the protocol level. See https://web.archive.org/web/20130918135152/http://www.thegua...

How would they do that? The ACME protocol is "take the basic artifacts you use for certificate signing, wrap them in JSON (cryptographically, using standard JWS), then send them over using HTTP + TLS." Every part of that is something for which there exists a buttload of implementations in whatever language you care to use.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#233
post #51

Earlier quoted context omitted.

I trust governments much less that a conglomerate of competing corporations. With all the problems with Web PKI, at least the bad actors are getting distrusted, and this provides a very strong enforcement on the rest. And Certificate Transparency makes sure the mis-issuance would be caught. It is not perfect by any means, but things are getting better. With DANE (or other country-issued certificates), every governmen…

> I trust governments much less that a conglomerate of competing corporations. There’s no essential difference between the two from my perspective. Why are these my only choices?

What other choices are there?

An international body might work, or just move the issue one step back.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#234
post #183

Earlier quoted context omitted.

One, in a democracy, is accountable to adults in the same jurisdiction. The other is only accountable to those with financial ties to its success.

> One, in a democracy, is accountable to adults in the same jurisdiction Or so they say. How's that been working out in practice?

Pretty well, in my experience.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#235
post #231

Earlier quoted context omitted.

If you are in the US you must ensure that your local company, and any sub-entity you control abroad complies with sanctions law. That is US law, and the US can apply that law to Dell the parent company, because it is in the US and controls the subsidary. > I can buy Jack Daniels at age 19 in my country from their local subsidiary, and no-one thinks that this should be a crime for their US parent company because the U…

US sanctions law saying that you must not transfer X from the US to Iran, directly or indirectly, is reasonable. US sanctions law saying that you must not transfer X from Brazil to Iran is gross overreach. Yes, of course the US can apply its absurdly extraterritorial laws to any parent company in the US, just as Iran could penalise any Iranian company whose US subsidiary distributed a depiction of the prophet or what…

That's a fair opinion to have.

But the US isn't really unique in applying their laws extraterritorially. See GDPR, Universal jurisdiction laws, China's National Security Law, etc... Every jurisdiction with sizable power does it. Some of these are even more extraterritorial in scope than US sanctions are.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#236
Took me a minute to parse the headline -- Sanctioned as as in "imposed penalty" (ie "sanctions"), not as in dictionary definition #2 "official permission or approval".

Perhaps because "US territories" are a thing, perhaps because it's way more newsworthy if LE bans the US, or perhaps im just a dummie.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#237
post #175

Earlier quoted context omitted.

> pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries This is most likely OFAC. Lets Encrypt could apply for a license to do business with sanctioned entities, and given their use case it would most likely be approved. https://ofac.treasury.gov/ofac-license-application-page

OFAC regulates commerce, not speech. Let's Encrypt is not doing "business", they're operating a free informational service. Lots of organizations interpret any information exchange as subject to OFAC regulation, and you and Let's Encrypt have good company in this interpretation, but I think it's unnecessarily ceding ground.

The government may use as wide of an interpretation of commerce as they can get away with. We've seen this happen before [0]. Sure, Let's Encrypt isn't taking money from the entities they offer certificates to. But the OFAC desk jockey assigned to that case only has to concoct some sufficiently plausible-sounding trail of money connecting the backing 501(c)3 and a sanctioned entity in order to levy penalties, and the legal team will not like that risk, even if it's unlikely for OFAC to win on appeal in a court.

[0]: https://en.wikipedia.org/wiki/Wickard_v._Filburn

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#238

And now imagine that one of the Trump tantrums contains an announcement of sanctions against the European Union.

He already announced sanctions against Spain. And took them back when Germany announced that sanctions against one EU country meant sanctions against them all.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#239

Let's Encrypt’s mission is to create a more secure and privacy-respecting web, except for people residing in countries with the most need for a more secure and privacy-respecting web. Sure, that's great. That said, pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries. I'm sure some of y'all are old enough to remember when web browsers came in "international fr…

Let's Encrypt continues to be available to almost every vulnerable population in the world, including those that need it most. I say almost as I'm hesitant to speak in absolutes regarding a topic as complex as this.

Most of our sanctions-related blocks apply only to the governments of certain sanctioned countries, not their general population.

This subscriber agreement update was intended to better reflect our legal requirements. It does not reflect a major change in the service we provide. Our compliance program does evolve over time, and part of that is communicating about it better in our terms of service. It's clear from some of the comments here that we have more work to do to make that text more understandable, we'll work on that.

> That said, pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries. I'm sure some of y'all are old enough to remember when web browsers came in "international friendly" versions that supported 40 bit encryption, or "fancy secure" versions with 128 bit encryption.

It doesn't.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#240
post #64

Earlier quoted context omitted.

Other countries sanction each other too.

This is not about countries sanctioning each other. This is the US sanctioning a local company because a foreign company doesn’t follow certain US laws in foreign soil, where such laws don’t apply. It’s a bit like the US arresting your mom at home in Texas because you ate a baggie of magic truffles in Amsterdam.

Ah, so it would be like the EU fining a US based company for not following certain GDPR laws even if they don't have a presence in the EU? Definitely would never happen!
Post reply on HN