Earlier quoted context omitted.
Any DNS-based solution needs something like DNSSEC to work. I believe DNSSEC didn't exist yet when HTTPS was being developed and even if it did, it wasn't anywhere near ubiquitous enough. Is it even these days?
That's kind of like saying that any CA-based solution needs something like a root program. Sure, but that would just be part of creating a DANE-like solution. Both the current CA solution and DANE or another hypothetical DNS-based solution are fundamentally similar on a technical level: hierarchical delegation of authorization backed by public key crypto. The main difference is where on the delegation chain you limit…
Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
381–390 of 404 posts
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#382Earlier quoted context omitted.
One thing is sure, pinning trust on trust chains down from Root Certificate Authorities is fundamentally incompatible with our notion of trust and an almost absurd idea to start with. Most people using a browser don't even know any person from such an organization nor would or should they have any rational reason to trust them.
> our notion of trust I suspect I may have a different notion of trust than you > Most people using a browser don't even know any person from such an organization nor would or should they have any rational reason to trust them. Back up one step further -- most people using a browser don't understand the problem set we're talking about even exists
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#383Earlier quoted context omitted.
Let's Encrypt continues to be available to almost every vulnerable population in the world, including those that need it most. I say almost as I'm hesitant to speak in absolutes regarding a topic as complex as this. Most of our sanctions-related blocks apply only to the governments of certain sanctioned countries, not their general population. This subscriber agreement update was intended to better reflect our legal…
> Most of our sanctions-related blocks apply only to the governments of certain sanctioned countries, not their general population. The agreement very plainly says otherwise: > You are not a person or entity that is: (a) located in, organized under the laws of, or ordinarily resident in any country or territory that is the target of comprehensive U.S. sanctions The general population of those countries are absolutely…
This is not something that you apply for; a general license already applies to everyone. The legalese or restrictions companies use exist because they cannot (or will not) validate everyone is who they say they are. This obviously doesn't apply to companies who deal with controlled exports, where they are responsible for whoever ultimately receives the controlled export.
I am not a lawyer and this is not legal advice.
https://ofac.treasury.gov/selected-general-licenses-issued-o...
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#384Earlier quoted context omitted.
> Most of our sanctions-related blocks apply only to the governments of certain sanctioned countries, not their general population. The agreement very plainly says otherwise: > You are not a person or entity that is: (a) located in, organized under the laws of, or ordinarily resident in any country or territory that is the target of comprehensive U.S. sanctions The general population of those countries are absolutely…
They have "clarified" elsewhere on here that the normal citizenry get a legal exemption [waves hands mystically] somehow, and that they're only blocking people when they legally have to. Obviously (to the rest of us) if the agreement says otherwise, then they're saying that it's LE that is forbidding the citizens of these countries, and it's not (entirely) the government's fault, which completely contradicts what the…
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#385Earlier quoted context omitted.
I'm not really in favor of DANE, because DNSSEC is such a mess ... but. Certificate transparency is nice. Browsers could require it for DANE certificates, just like they require it for current Web PKI certificates. The people controlling the TLD of interesting can exert control over the domain of interest in order to issue a DANE certificate. But they can also exert control over the domain of interest in order to req…
And if they don't, DNS is already a database. You could just query domains to check their certificates. People running recursive DNS servers could double-check certificates.
CT addresses scoped attacks by making all webpki trusted certificates public knowledge. You would want something similar with DANE.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#386Earlier quoted context omitted.
> pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries This is most likely OFAC. Lets Encrypt could apply for a license to do business with sanctioned entities, and given their use case it would most likely be approved. https://ofac.treasury.gov/ofac-license-application-page
OFAC regulates commerce, not speech. Let's Encrypt is not doing "business", they're operating a free informational service. Lots of organizations interpret any information exchange as subject to OFAC regulation, and you and Let's Encrypt have good company in this interpretation, but I think it's unnecessarily ceding ground.
Now, does this serve a policy purpose? Perhaps not--US computers trust plenty of non-US CAs that could continue to serve these customers. But that's not how comprehensive sanctions are set up, they are effectively a complete embargo.
A better question is whether telecom carveouts (general licenses) in the sanctions may allow this. That is a country by country question as each one is worded differently.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#387Earlier quoted context omitted.
A certificate is not cryptography, though, it's a number. The entity requesting the certificate already has the cryptographic software installed on their servers, as do the clients trying to connect to them. There's nothing technologically special about the number, it's all in the realm of the social contract, in that it has been blessed by a chain of trust.
Everything is a number.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#388Earlier quoted context omitted.
OFAC regulates commerce, not speech. Let's Encrypt is not doing "business", they're operating a free informational service. Lots of organizations interpret any information exchange as subject to OFAC regulation, and you and Let's Encrypt have good company in this interpretation, but I think it's unnecessarily ceding ground.
Providing information (website, CT log, CRL) is fine, but creating a certificate on request is clearly a service. How is that different than providing a computation or LLM output in response to a prompt? Moreover, it is clearly not just the physical act of signing a CSR, but the verification of ownership that comes with it. That's just as much as service fully automated as if a human were doing it. Now, does this ser…
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#389Earlier quoted context omitted.
> Most of our sanctions-related blocks apply only to the governments of certain sanctioned countries, not their general population. The agreement very plainly says otherwise: > You are not a person or entity that is: (a) located in, organized under the laws of, or ordinarily resident in any country or territory that is the target of comprehensive U.S. sanctions The general population of those countries are absolutely…
OFAC sanctions are far more nuanced than what you make them out to be. Very often "general licenses" are carved out for providing IT services or technology to individuals for personal use. The purpose of this is for censorship circumvention, which often supports American interests abroad. This is not something that you apply for; a general license already applies to everyone. The legalese or restrictions companies us…
Generally the software carveouts are very limited - it's not just "providing IT services or technology to individuals for personal use", i.e. Sudan:
> software updates for medical devices to Sudan
Indeed, of the software carveouts listed on that page, only two are not related to the operation or update of medical devices:
- provision of Internet services to the people of the Ukraine (read: "Starlink")
- provision of messaging services to members of the Government of Venezuela.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#390Earlier quoted context omitted.
Let's Encrypt continues to be available to almost every vulnerable population in the world, including those that need it most. I say almost as I'm hesitant to speak in absolutes regarding a topic as complex as this. Most of our sanctions-related blocks apply only to the governments of certain sanctioned countries, not their general population. This subscriber agreement update was intended to better reflect our legal…
> Most of our sanctions-related blocks apply only to the governments of certain sanctioned countries, not their general population. The agreement very plainly says otherwise: > You are not a person or entity that is: (a) located in, organized under the laws of, or ordinarily resident in any country or territory that is the target of comprehensive U.S. sanctions The general population of those countries are absolutely…