Live data from Hacker News

Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

letsencrypt.org

111–120 of 404 posts

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#111

Earlier quoted context omitted.

Well good thing everyone using the provider is using an open protocol and it's stupid easy to switch

Which free CA should I use instead of lets encrypt that has same browser support?

Actalis, based in Italy offers a free tier, with ACME https://www.actalis.com/subscription

ZeroSSL from Austria also has a limited free tier. https://zerossl.com/pricing/

I mean really, if you use lets encrypt for anything that runs in a production environment, the responsible thing to do is build a fallback to switch to another provider in case LE has a bad day (or hits a brick wall and needs to say, enforce export restrictions).

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#113
post #3

Makes sense, they are US company. I am surprised it took them that long.

That's just another reminder that no one from outside of US should deal with US companies.

Of course not! just find viable alternatives to Microsoft, Apple, Mozilla, YCombinator, Google, Intel, AMD, ...

In all seriousness, as an American I'd love to see a healthier, more well-distributed tech industry, but I don't see many companies stepping up to provide competing services. It's my understanding that china has alternatives to many of these products/services, but I really don't see how anyone in Europe could possibly use a US-free internet.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#114

Let's Encrypt’s mission is to create a more secure and privacy-respecting web, except for people residing in countries with the most need for a more secure and privacy-respecting web. Sure, that's great. That said, pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries. I'm sure some of y'all are old enough to remember when web browsers came in "international fr…

Seems in all thing tech at the moment the US legal system is accelearting a great split and erectinga digital iron curtain, from AI models to the more mundane like TLS certs. Its been standard for a while for many Linux distros based in the US to toe the party line - like RedHat having notices pretty similar to this one by LE. Seems any meaningful Open Projects will have to choose what path they want to take, be like RISC-V and relocate or LE and others and enforce the divide.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#116

This actually makes sense. No freedom for the enemies of freedom.

But what if you're the baddies?

Then try not to be completely dependent on the products of a company that is under the control of your enemy.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#118

Iran is blocking internet for months, US ...bans creation of secure connections - that'll show 'em! Russian quasi-government structures are spending quadrillion of rubles on a TSPU (censorship system) to spy on Russian residents, US ...helps them by making snooping on what is currently encrypted traffic possible by banning accessible encryption!

Let's Encrypt certificates continue to be available in both Iran and Russia, just not for the Iranian and Russian governments.

The terms of service update to clarify what we have always done, comply with relevant law, has not changed the situation for either country.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#119
It their right to do that.

But can we still trust them?

I am not well versed in how their systemwide certificate issuance works: If they have to add this to their terms to comply with their government, could the same government use pressure to leverage let’s encrypt to do harm.

Post reply on HN