Live data from Hacker News

Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

letsencrypt.org

371–380 of 404 posts

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#371

Earlier quoted context omitted.

You issued a certificate for North Korea's email infrastructure as recently as six days ago : https://crt.sh/?id=26878583197 (06/04/2026 smtp.star-co.net.kp) https://crt.sh/?id=20256841119 (08/11/2025 *.star.net.kp) Star Joint Venture is the manager of the .kp TLD and one of DPRK's two email providers (the other is silibank.net.kp) [1], used as the official email for various government bodies ex. ipa817@star-co.net.k…

This is incredible. How did you find these certs?

I only noticed the star net one (not sure if it’s even in use) when writing this. I noticed the Pyongyang Zoo (which shares an IP with the Architects Society—one on 443 and one on 80 lmao) first, just from flipping through their very small IP space on Shodan.

You can see them all on crt.sh, because LE has to upload them to a CT log for browsers to trust them. (That’s how most of those subdomain finder websites work too.) The email servers seem to have gotten certs from a for profit CA back in 2015, but I’m not sure if they ever used them. Most of their webspace seems to be HTTP only. (And it’s a good thing, because some of their Apache versions are potentially old enough to have Heartbleed.)

The architects website has some pretty cool PDF magazines btw. They also have several websites for their insurance company’s (perhaps some intl org needs them to have a website for listing)—that’s a core hard currency stream for them and they previously have been accused of submitting false losses.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#372

Earlier quoted context omitted.

> If complying with a law gets in the way of the mission I’m not sure that counts as a change to the mission. It's already illegal to use in NK, but if it's the US, well it's time to steer the mission around it? Gross.

For an American enterprise? Yes, obviously. Should NRA hand out guns to everyone who can’t get a permit where permits are required? Of course not. If they are against gun permits they have to fight the law, not break it.

The National Rifle Association (NRA) describes itself as America’s longest-standing civil rights organization.

That is a specific US-internal stance.

There's a list of organizations that started in the US, ultimately having had to work around the US legal system, in pursuit of their missions:

re Planned Parenthood Global, WikiLeaks, International Campaign to Ban Landmines, Center for Reproductive Rights, selected programs of the Human Rights Campaign Foundation, et al

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#373
post #111

Earlier quoted context omitted.

Which free CA should I use instead of lets encrypt that has same browser support?

Actalis, based in Italy offers a free tier, with ACME https://www.actalis.com/subscription ZeroSSL from Austria also has a limited free tier. https://zerossl.com/pricing/ I mean really, if you use lets encrypt for anything that runs in a production environment, the responsible thing to do is build a fallback to switch to another provider in case LE has a bad day (or hits a brick wall and needs to say, enforce export…

[deleted]

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#374
post #324
post #51

Earlier quoted context omitted.

I trust governments much less that a conglomerate of competing corporations. With all the problems with Web PKI, at least the bad actors are getting distrusted, and this provides a very strong enforcement on the rest. And Certificate Transparency makes sure the mis-issuance would be caught. It is not perfect by any means, but things are getting better. With DANE (or other country-issued certificates), every governmen…

Companies have run some absolutely outstanding PR then. I have never worked in any company where I explicitly trust the CEO to always do the right thing in every situation. There is usually no governance board, or review system to inquire about public harm: those things are usually external and fought against as they are regulatory burden . So, in practice what tends to happen is that someone in the company just does…

They key is multiple, competing companies. As long as they don't collude, if one company misbehaves, others will catch it.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#375
post #206

Earlier quoted context omitted.

The entire point of a trust model is to exclude people. That's the stated goal. If you want encryption without trust, just use self-signed certs.

If you don't care about who you're talking to, why use certificates at all?

If you don't care about who you're talking to, why use encryption at all?

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#376
post #374
post #324

Earlier quoted context omitted.

Companies have run some absolutely outstanding PR then. I have never worked in any company where I explicitly trust the CEO to always do the right thing in every situation. There is usually no governance board, or review system to inquire about public harm: those things are usually external and fought against as they are regulatory burden . So, in practice what tends to happen is that someone in the company just does…

They key is multiple, competing companies. As long as they don't collude, if one company misbehaves, others will catch it.

Hows that going for…

… browsers

… phones

… operating systems

… network appliances

… payment transaction systems

I feel like if it fails so often then it can’t be relied on.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#377
post #328

Earlier quoted context omitted.

The problem is that finding a root source of trust aren't easy this days. LE was neutral, now nobody is. Russian government issued their new root certificate years ago. Nobody trusted it enough to request a certificate from them or install it on their computers. Including almost all of the russian residents. If Let's Encrypt enforces the rules, as written in pdf, a lot of people would lose a choice. Frankly, even pub…

> Nobody trusted it Let's be real here… 99.99999999999999% of internet users have no idea what root CAs even are. It's the browser vendor mafia that makes the decision.

>> 99.99999999999999% of internet users have no idea what root CAs even are

that would be like *checks math* less than a human aware of root CA? Can't be right.

anyway, people living in russia are statistically more aware. There was a campaign after new root CA was issued. It was on a news, on the official channels, in the mail and on the posters. A lot of government sites begged to install them whenever you visited.

It's not like they released it silently.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#378
post #308

Earlier quoted context omitted.

> The problem with our current SSL PKI, as so very many people have pointed out over the years, is that any CA is allowed to issue valid certificates for any domain name. There have been proposals to use X.509 extensions to remedy this, but they have seen lesser real world usage than the various certificate revocation schemes, which is very close to zero already. Some of the browser root programs include (or have inc…

Unfortunately the CA/B Forum has high requirements for constrained subordinate CA certificates[1], which to me sounds a lot like regulatory capture. [1] https://community.letsencrypt.org/t/sub-ca-with-wildcard-cer...

It's not that high of a requirement. The sub-CA is allowed to self audit. But the original CA does have to check a percentage of certificates issued by the sub-CA.

So that's not going to be free. But it might be possible to do it if you were big enough to pay for it. I have dreams of having my private CA also signed off on by webpki so apps and browsers could use the same servers without having to include webpki in my apps.

Not that I really work on such things anymore.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#380

Earlier quoted context omitted.

Yes actually you still could've. But it would require a pass through the IETF to stabdaddize a DNS record type, and that would delay Netscape's release.

Any DNS-based solution needs something like DNSSEC to work. I believe DNSSEC didn't exist yet when HTTPS was being developed and even if it did, it wasn't anywhere near ubiquitous enough. Is it even these days?

No, fewer than 5% of North American DNS names are signed, and the number has gone down over some recent years.
Post reply on HN