Live data from Hacker News

Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

letsencrypt.org

331–340 of 404 posts

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#331
I had been meaning to post somewhere that they issued a certificate to kza.org.kp a few months ago but didn't really seem worthy of its own thread.

I am no lawyer, but while there do appear to be some exemptions for communication related services, it's not clear that this qualifies as LE isn't actually providing telecommunications, just a certificate file. And it's not even an issue of the encryption itself, North Korea is under a general embargo so any exports or trade whatsoever is restricted by default.

As an aside, many of North Korea's web servers appear to be old enough to have Heartbleed based on their banner versions, but most don't actually have HTTPS in the first place.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#332
For all the people commenting, the ITAR rules still apply for TLS, if you want to use TLS in an app for iOS/Android, one of the requirements is to get an ITAR exemption as part of the app review [1].

The US sanctions are imposed on entire nations (eg Iran), so LetsEncrypt have no option but to state in their conditions that their service is not available. They don't have a choice as a US organization operating under US law.

Whether they choose to enforce that through technical means (eg blocking IPs etc) is up to them.

[1] https://developer.apple.com/documentation/security/complying...

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#333

Earlier quoted context omitted.

> move somewhere more willing to respect international law? Some of these sanctions are required by international law (i.e. sanctions imposed by UNSC). For the other ones, international law generally lets countries have whatever trade policy they see fit including sanctions, unless they violate some other rule of international law or treaty obligation.

Sanctioning the ICC obviously has nothing to do with trade policy. The USA signed the Rome Statute but never ratified it, and then withdrew its signatory status. There's an argument to be made that there was a treaty obligation there, but it's pretty weak.

I personally think sanctioning the ICC judges is a disgusting act. However ultimately all sanctions are decisions to refrain from trading with someone, so it is in a sense a trade policy. I think what you're getting at is that usa is implementing that policy to obtain a political/diplomatic goal, which is true, but you could say the same about most trade policies.

I think article 18(a) of the vienna convention of the law of treaties means that once you withdraw your signature, you no longer have any obligations in regards to the treaty.

Maybe you could make some sort of argument that the sanctions violate the purpose of the geneva convention as they are designed to prevent bringing to justice people accused of grave breaches of the geneva convention. Like its an attempt to frustrate the application of article 49 of the first geneva convention [Ianal]

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#334

Earlier quoted context omitted.

I hope not. We don't have any alternatives yet.

https://www.actalis.com/activate-free-plan maybe?

This page is blocked for me from server's end. I'll try later using VPN, but looks like it won't work :-)

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#335
post #239

Earlier quoted context omitted.

Let's Encrypt continues to be available to almost every vulnerable population in the world, including those that need it most. I say almost as I'm hesitant to speak in absolutes regarding a topic as complex as this. Most of our sanctions-related blocks apply only to the governments of certain sanctioned countries, not their general population. This subscriber agreement update was intended to better reflect our legal…

> Most of our sanctions-related blocks apply only to the governments of certain sanctioned countries, not their general population. The agreement very plainly says otherwise: > You are not a person or entity that is: (a) located in, organized under the laws of, or ordinarily resident in any country or territory that is the target of comprehensive U.S. sanctions The general population of those countries are absolutely…

It may be the case that "most of" their sanctions-related blocks apply only to governments (let's say there are 100 such blocks), while they still disallow usage by persons located in a country or territory that is the target of comprehensive US sanctions (let's say there are 50).

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#336

Earlier quoted context omitted.

According to the current administration, almost half of the US is considered a political enemy of the current administration. Soon they might be pushing for Operating Systems to gather political party preference information, so they can know who should be restricted from the use of strong encryption. The options being: 1. I love america 2. Radical left looney 3. Neither male nor female. 4. Those that tremble as if th…

It'll be interesting when/if they sanction Antifa. Since it doesn't exist, you can't prove that you're not a member of it. So they get to sanction anyone.

Proof has no relevance if you are prevented from accessing the legal system (e.g. thrown into a concentration camp for immigrants)

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#337
post #177

Couldn't LE have a branch in Europe or anywhere outside the USA and its minions? Because they're betraying their own goals, as stated in their About page: “It is a service run for the public’s benefit. [...] Anyone who owns a domain name can use Let’s Encrypt to obtain a trusted certificate at zero cost. [...] Let’s Encrypt is a joint effort to benefit the community, beyond the control of any one organization.” Now t…

Let's encrypt is not some code or even a company that you can split into different branches. Their existence is one based on trust relations that let's encrypt has with browsers and operative systems. It is in one part similar to both domain names and IP address space, in that the technical aspects of creating alternative roots is almost trivial in comparison to getting the trust that is required for an alternative r…

Russia already has its own root CA, the issue is that state-owned root CAs are by definition not safe from MITM attacks by the same government.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#338
post #188

Earlier quoted context omitted.

If you truly need a secure and private web you should be using tor.

Say what, now? Anonymity and encrypted communication are two very, very different things. Have one but not the other and you're essentially handing off your private data incl. passwords to whoever that has a tap on the communication between you and the server can fetch them, too. Have the other but not the one and everyone will know who you are, but they can't eavesdrop.

I've found lots on Iranians on tor.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#339

Earlier quoted context omitted.

You obviously don't know how DNSSEC works. The DNS root of trust is ICANN, not a government.

That's worse, because ICANN is effectively the US government.

I'm the first to admit ICANN has issues, but US government control doesn't seem to be one of them.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#340
post #197
post #51

Earlier quoted context omitted.

I trust governments much less that a conglomerate of competing corporations. With all the problems with Web PKI, at least the bad actors are getting distrusted, and this provides a very strong enforcement on the rest. And Certificate Transparency makes sure the mis-issuance would be caught. It is not perfect by any means, but things are getting better. With DANE (or other country-issued certificates), every governmen…

I'm not really in favor of DANE, because DNSSEC is such a mess ... but. Certificate transparency is nice. Browsers could require it for DANE certificates, just like they require it for current Web PKI certificates. The people controlling the TLD of interesting can exert control over the domain of interest in order to issue a DANE certificate. But they can also exert control over the domain of interest in order to req…

And if they don't, DNS is already a database. You could just query domains to check their certificates. People running recursive DNS servers could double-check certificates.
Post reply on HN