Earlier quoted context omitted.
Pretty well, in my experience.
Yeah, that's why most countries in EU, as well as US, are in a huge dissarray, politicians have all time low approvals, people vote for something and get the opposite, and the economy and social climate turned to shit... I guess one doing well enough can be oblivious to all this...
Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
341–350 of 404 posts
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#342Earlier quoted context omitted.
> I trust governments much less that a conglomerate of competing corporations Let's not create a world wide PKI based on a political ideology. > country-issued certificates [...] every government will absolutely double-issue certificates This is such a strange argument. If you register a .ru domain, do you really think you are safe should the Russian intelligence services ask for a valid certificate? Controlling the…
> The problem with our current SSL PKI, as so very many people have pointed out over the years, is that any CA is allowed to issue valid certificates for any domain name. There have been proposals to use X.509 extensions to remedy this, but they have seen lesser real world usage than the various certificate revocation schemes, which is very close to zero already. Some of the browser root programs include (or have inc…
[1] https://community.letsencrypt.org/t/sub-ca-with-wildcard-cer...
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#343Let's Encrypt’s mission is to create a more secure and privacy-respecting web, except for people residing in countries with the most need for a more secure and privacy-respecting web. Sure, that's great. That said, pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries. I'm sure some of y'all are old enough to remember when web browsers came in "international fr…
to not export SSL technology to enemy countries
sounds like to not export mathematicsRe: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#344Earlier quoted context omitted.
Do we also need to put all our letters into strongboxes before we send them? Maybe we should have solve the ISP snooping problem by making that illegal instead.
> Do we also need to put all our letters into strongboxes before we send them? If it were as cheap and efficient as TLS these days, yes, absolutely > Maybe we should have solve the ISP snooping problem by making that illegal instead. We could do both! ISP snooping is still a problem for metadata (SNI).
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#345Earlier quoted context omitted.
No remotely western company will risk US sanctions violations or whatever other regulatory burden by using US technology where it can't be used. Even Chinese companies depending on how state backed they are might not be willing to risk it.
This is the big irony of the current situation: while the US is dependent on China for manufactured goods, China is dependent on the US for external demand for its manufactured goods. One is the mirror image of the other and neither economy can exist in its current state in isolation. So China has the US over a barrel when it comes to actually building stuff, rare earths and all of that, but equally US sanctions stil…
Who says they’re stuck or unhappy?
This is politics. We’re all just bait. In reality they’re friends.
US and China have made more gains by pretending to be enemies than friends and they likely plotted it all together.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#346Makes sense, they are US company. I am surprised it took them that long.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#347Makes sense, they are US company. I am surprised it took them that long.
That's just another reminder that no one from outside of US should deal with US companies.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#348On desktops browser displaying the fingerprint/hash requires clicks, on mobile is not implemented and on native apps practically not existing.
The keys should be shown, so they could be verified manually in person or via other channel. Just like the SSH do. Someone say people would just click "accept" without a thought, but the button is already here, just no information what actually is accepted.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#349Iran and other tyrannical governments can easily set up their own CAs and force their citizens to use them. Iran likely already has this infra in place. This ban does nothing but highlights LE as the liability it is. The decades-old certificate authority scheme is no longer fit for purpose and needs to go.
If you're a web developer, consider offering your site through public key-addressable networks. Reticulum and Tor are good options that work today.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#350Earlier quoted context omitted.
Not back when SSL and the PKI ecosystem was developed.
Yes actually you still could've. But it would require a pass through the IETF to stabdaddize a DNS record type, and that would delay Netscape's release.