When I read it, I interpreted it as "let's encrypt bans certificate usage in - any territories endorsed by the US". Took me reading a couple comments to understand it actually meant "territories under US sanctions".
Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
251–260 of 404 posts
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#252Let's Encrypt’s mission is to create a more secure and privacy-respecting web, except for people residing in countries with the most need for a more secure and privacy-respecting web. Sure, that's great. That said, pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries. I'm sure some of y'all are old enough to remember when web browsers came in "international fr…
Some (well, at least one) of us are old enough to have owned one of these: http://www.cypherspace.org/adam/uk-shirt.html A t-shirt with a Perl script that implemented RSA encryption strong enough to be technically illegal to export from the US. (I must sadly admit to being too cowardly/sensible to have taken that shirt to the US in the late 90s...)
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#253Earlier quoted context omitted.
It shouldn't be located in Europe (because, as you said, US minions are no better than the US itself). Instead it should move to a neutral country, somewhere like Singapore or Uruguay.
Suddenly the idea of having a CA hosted in space on a satellite issuing certs seems like a good idea.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#254Earlier quoted context omitted.
> pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries This is most likely OFAC. Lets Encrypt could apply for a license to do business with sanctioned entities, and given their use case it would most likely be approved. https://ofac.treasury.gov/ofac-license-application-page
OFAC regulates commerce, not speech. Let's Encrypt is not doing "business", they're operating a free informational service. Lots of organizations interpret any information exchange as subject to OFAC regulation, and you and Let's Encrypt have good company in this interpretation, but I think it's unnecessarily ceding ground.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#255Earlier quoted context omitted.
What constitutes the "vast majority" ? Periodically I check mine, and I sometimes have reason to check others, I no longer run my own log auditing (I did when I worked somewhere else because it was close to my main field of interest) but other people do.
How can you check other people's certs? How do you know whether a cert issued is authorized by them or not? The only one who can check for maliciously published certs is the entity authorized to request them. I think most companies are happy when they manage to have valid, not expired certs and do not care too much about making sure there are not too many of them. You are right that if the state would start issuing m…
There are red flags you can look for, but you need to confirm with the domain owner to be sure. CAA records can tell you what CAs are supposed to issue a certificate. Many companies always use the same CA, so a change to a different one could be suspect.
For the wiretapping scenario, domain verified certificates do not protect against that scenario. If the wiretap has full control of your server's network, then it can issue a certificate of its own. No need to compromise a CA.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#256Earlier quoted context omitted.
Suddenly the idea of having a CA hosted in space on a satellite issuing certs seems like a good idea.
You're assuming that satellites are exterritorial. They aren't, they're ab initio the launching state's property and responsibility, barring other agreements to transfer them - and getting one out into a "legal void" isn't going to be trivial.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#257Earlier quoted context omitted.
Suddenly the idea of having a CA hosted in space on a satellite issuing certs seems like a good idea.
A ship in international waters with satellite internet connection would be much cheaper, except it runs into the same problems as described by the sibling comment: https://news.ycombinator.com/item?id=48469397
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#258Let's Encrypt’s mission is to create a more secure and privacy-respecting web, except for people residing in countries with the most need for a more secure and privacy-respecting web. Sure, that's great. That said, pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries. I'm sure some of y'all are old enough to remember when web browsers came in "international fr…
If complying with the law gets in the way of the mission I’m not sure that counts as a change to the mission.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#259Earlier quoted context omitted.
A ship in international waters with satellite internet connection would be much cheaper, except it runs into the same problems as described by the sibling comment: https://news.ycombinator.com/item?id=48469397
You don't get 1,361 W/m² of continuous free energy when you're Earth bound and all those pesky water molecules.
It is free only if you ignore the cost of getting the thing into the orbit in the first place.
Edit: also, AFAIK, normal microchips (without special radiation hardening) don't last that long in space
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#260Let's Encrypt’s mission is to create a more secure and privacy-respecting web, except for people residing in countries with the most need for a more secure and privacy-respecting web. Sure, that's great. That said, pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries. I'm sure some of y'all are old enough to remember when web browsers came in "international fr…
tattoo yourself with crypto code to become munitions