Live data from Hacker News

Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

letsencrypt.org

251–260 of 404 posts

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#251
The title was a bit misleading.

When I read it, I interpreted it as "let's encrypt bans certificate usage in - any territories endorsed by the US". Took me reading a couple comments to understand it actually meant "territories under US sanctions".

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#252

Let's Encrypt’s mission is to create a more secure and privacy-respecting web, except for people residing in countries with the most need for a more secure and privacy-respecting web. Sure, that's great. That said, pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries. I'm sure some of y'all are old enough to remember when web browsers came in "international fr…

Some (well, at least one) of us are old enough to have owned one of these: http://www.cypherspace.org/adam/uk-shirt.html A t-shirt with a Perl script that implemented RSA encryption strong enough to be technically illegal to export from the US. (I must sadly admit to being too cowardly/sensible to have taken that shirt to the US in the late 90s...)

And if you missed the original run, you can buy a reprint from Adam's current company: https://store.blockstream.com/products/rsa-t-shirt

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#253

Earlier quoted context omitted.

It shouldn't be located in Europe (because, as you said, US minions are no better than the US itself). Instead it should move to a neutral country, somewhere like Singapore or Uruguay.

Suddenly the idea of having a CA hosted in space on a satellite issuing certs seems like a good idea.

A ship in international waters with satellite internet connection would be much cheaper, except it runs into the same problems as described by the sibling comment: https://news.ycombinator.com/item?id=48469397

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#254
post #175

Earlier quoted context omitted.

> pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries This is most likely OFAC. Lets Encrypt could apply for a license to do business with sanctioned entities, and given their use case it would most likely be approved. https://ofac.treasury.gov/ofac-license-application-page

OFAC regulates commerce, not speech. Let's Encrypt is not doing "business", they're operating a free informational service. Lots of organizations interpret any information exchange as subject to OFAC regulation, and you and Let's Encrypt have good company in this interpretation, but I think it's unnecessarily ceding ground.

Wasn't there news a bit ago about some people being suddenly excluded from Linux kernel development for presumably similar reasons?

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#255

Earlier quoted context omitted.

What constitutes the "vast majority" ? Periodically I check mine, and I sometimes have reason to check others, I no longer run my own log auditing (I did when I worked somewhere else because it was close to my main field of interest) but other people do.

How can you check other people's certs? How do you know whether a cert issued is authorized by them or not? The only one who can check for maliciously published certs is the entity authorized to request them. I think most companies are happy when they manage to have valid, not expired certs and do not care too much about making sure there are not too many of them. You are right that if the state would start issuing m…

> How can you check other people's certs?

There are red flags you can look for, but you need to confirm with the domain owner to be sure. CAA records can tell you what CAs are supposed to issue a certificate. Many companies always use the same CA, so a change to a different one could be suspect.

For the wiretapping scenario, domain verified certificates do not protect against that scenario. If the wiretap has full control of your server's network, then it can issue a certificate of its own. No need to compromise a CA.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#256

Earlier quoted context omitted.

Suddenly the idea of having a CA hosted in space on a satellite issuing certs seems like a good idea.

You're assuming that satellites are exterritorial. They aren't, they're ab initio the launching state's property and responsibility, barring other agreements to transfer them - and getting one out into a "legal void" isn't going to be trivial.

Over the centuries I am sure there will be random satellites that are defunct that will be hacked or otherwise "taken over" by someone with the right skills. These things are tiny compared to the distances involved and in the future you might end up using them as data reservoirs since in many cases it will be cost prohibitive for any authority to go collect or otherwise stake authority over an old piece of hardware considered junked.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#257

Earlier quoted context omitted.

Suddenly the idea of having a CA hosted in space on a satellite issuing certs seems like a good idea.

A ship in international waters with satellite internet connection would be much cheaper, except it runs into the same problems as described by the sibling comment: https://news.ycombinator.com/item?id=48469397

You don't get 1,361 W/m² of continuous free energy when you're Earth bound and all those pesky water molecules.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#258

Let's Encrypt’s mission is to create a more secure and privacy-respecting web, except for people residing in countries with the most need for a more secure and privacy-respecting web. Sure, that's great. That said, pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries. I'm sure some of y'all are old enough to remember when web browsers came in "international fr…

> Let's Encrypt’s mission is to create a more secure and privacy-respecting web, except for people residing in countries with the most need for a more secure and privacy-respecting web. Sure, that's great.

If complying with the law gets in the way of the mission I’m not sure that counts as a change to the mission.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#259

Earlier quoted context omitted.

A ship in international waters with satellite internet connection would be much cheaper, except it runs into the same problems as described by the sibling comment: https://news.ycombinator.com/item?id=48469397

You don't get 1,361 W/m² of continuous free energy when you're Earth bound and all those pesky water molecules.

> free energy

It is free only if you ignore the cost of getting the thing into the orbit in the first place.

Edit: also, AFAIK, normal microchips (without special radiation hardening) don't last that long in space

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#260

Let's Encrypt’s mission is to create a more secure and privacy-respecting web, except for people residing in countries with the most need for a more secure and privacy-respecting web. Sure, that's great. That said, pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries. I'm sure some of y'all are old enough to remember when web browsers came in "international fr…

http://www.geekytattoos.com/illegal-tattoos-rsa-tattoos

tattoo yourself with crypto code to become munitions

Post reply on HN