Live data from Hacker News

Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

letsencrypt.org

161–170 of 404 posts

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#161

Earlier quoted context omitted.

> Let's Encrypt certificates continue to be available in both Iran and Russia, just not for the Iranian and Russian governments. According to https://news.ycombinator.com/item?id=48457280 it affects all people ordinarily resident in those territories, not just their governments: > You are not a person or entity that is: > (a) located in, organized under the laws of, or ordinarily resident in any country or territory…

I wonder what "ordinarily resident" means legally. Like has a permanent address there, even if they don't live there physically..?

Yes. If you are, for example, even a US citizen, permanently living in Crimea, you are still subject to limitations, imposed by sanctions.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#162

Earlier quoted context omitted.

They could, but if the branch didn’t follow these laws, the main US branch would still be liable.

Just close down completely in the US and move to the EU

And then what? Be subject to similar sanctions from a different governing body?

e.g. https://www.consilium.europa.eu/en/policies/sanctions-agains...

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#163
post #118

Earlier quoted context omitted.

Let's Encrypt certificates continue to be available in both Iran and Russia, just not for the Iranian and Russian governments. The terms of service update to clarify what we have always done, comply with relevant law, has not changed the situation for either country.

> Let's Encrypt certificates continue to be available in both Iran and Russia, just not for the Iranian and Russian governments. According to https://news.ycombinator.com/item?id=48457280 it affects all people ordinarily resident in those territories, not just their governments: > You are not a person or entity that is: > (a) located in, organized under the laws of, or ordinarily resident in any country or territory…

Sanctions compliance is unfortunately fairly complex.

Let's Encrypt can issue certificates for non-government entities in Iran and Russia due to statutory exemptions protecting personal communications, alongside specific Office of Foreign Assets Control (OFAC) authorizations designed to promote Internet freedom and human rights.

We will look into whether we can make things more easily understandable in the subscriber agreement.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#164
post #51

Earlier quoted context omitted.

We could, and should, switch to DANE. Or else, switch to how X.509 was supposed to be used, with each country running a CA for their nationals.

I trust governments much less that a conglomerate of competing corporations. With all the problems with Web PKI, at least the bad actors are getting distrusted, and this provides a very strong enforcement on the rest. And Certificate Transparency makes sure the mis-issuance would be caught. It is not perfect by any means, but things are getting better. With DANE (or other country-issued certificates), every governmen…

> I trust governments much less that a conglomerate of competing corporations.

There’s no essential difference between the two from my perspective. Why are these my only choices?

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#165
post #51

Earlier quoted context omitted.

I trust governments much less that a conglomerate of competing corporations. With all the problems with Web PKI, at least the bad actors are getting distrusted, and this provides a very strong enforcement on the rest. And Certificate Transparency makes sure the mis-issuance would be caught. It is not perfect by any means, but things are getting better. With DANE (or other country-issued certificates), every governmen…

> every government will absolutely double-issue certificates to police, secret service and friends of goverment, and no one will have any recourse. Countries already have CA that issue certificates with more legal force than a handwritten signature. I can open a bank account, pay my taxes and sign up to all government services. But I can't use them for a webpage. > With DANE (or other country-issued certificates) DAN…

DANE is entirely dependent on DNSSEC, and DNSSEC is, by design, under the government control, with all the bureaucratic mess and mistakes this implies.

This would be pretty terrible if anyone actually cared about DNSSEC, but luckily for us, no one cares.. So let's keep things this way.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#167

Earlier quoted context omitted.

> but I don't see many companies stepping up to provide competing services Maybe because the US dropped most of its anti trust regulations, leading to ridiculously monopolistic practices such as "acquire everything that may be threatening".

When was the last time you heard about a European cellphone manufacturer, or social media network, or web browser being acquired by an American monopoly? I can only think of Nokia, purchased by microsoft in 2014. Those phones ran windows CE before that even, so you could hardly have avoided the american tech industry. All I'm trying to say is, it's impossible for Europeans to both A) be on the internet and B) avoid t…

Nokia phones ran mostly on SymbianOS

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#168

This somehow confirms my gut feeling that digital certificates are mainly a means to enforce exclusion on behalf of the certificate authority ownership. It is a tool to prevent people from taking full ownership and control of whatever is affected by digital certificates, be it software, firmware, hardware, or as in this case SSL/TLS. That's digital tyranny in disguise.

The entire point of a trust model is to exclude people. That's the stated goal.

If you want encryption without trust, just use self-signed certs.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#169
post #149

This should be one of those things that should be an quick EU win. Running Let's Encrypt is $3-4mill a year, the EU probably uses that on pencils. The EU could easily bootstrap a Let's Encrypt competitor if it truly cared about removing dependencies on US based entities.

Do you really think the EU wants to sign up for PR that’s essentially “the US is being too mean to Russia” right now?

I think the EU should do it regardless of Russia. The EU should invest in its own technology and not depend so much on an increasingly undependable ally.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#170

Let's Encrypt’s mission is to create a more secure and privacy-respecting web, except for people residing in countries with the most need for a more secure and privacy-respecting web. Sure, that's great. That said, pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries. I'm sure some of y'all are old enough to remember when web browsers came in "international fr…

If you truly need a secure and private web you should be using tor.
Post reply on HN