Live data from Hacker News

Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

letsencrypt.org

261–270 of 404 posts

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#261
post #231

Earlier quoted context omitted.

US sanctions law saying that you must not transfer X from the US to Iran, directly or indirectly, is reasonable. US sanctions law saying that you must not transfer X from Brazil to Iran is gross overreach. Yes, of course the US can apply its absurdly extraterritorial laws to any parent company in the US, just as Iran could penalise any Iranian company whose US subsidiary distributed a depiction of the prophet or what…

That's a fair opinion to have. But the US isn't really unique in applying their laws extraterritorially. See GDPR, Universal jurisdiction laws, China's National Security Law, etc... Every jurisdiction with sizable power does it. Some of these are even more extraterritorial in scope than US sanctions are.

> GDPR

Only applies to EU citizens' personal data, so while technically extraterritorial it doesn't feel like overreach in the same way.

> Universal jurisdiction laws

Rightly controversial when applied beyond things that are internationally agreed to be crimes against humanity, like torture or genocide.

> China's National Security Law

A perfect example of the kind of thing that the US used to define itself in opposition to.

Nations are sovereign and those with the might to push their requirements on others can do so. But I liked it better when we had a sense of the value of an open international order, where things like internet protocols were shared standards that everyone would collaborate on other than a handful of pariah states.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#262
We all knew something like this was coming when we decided to centralise the web around Let's Encrypt.

In reality of course you can probably just ignore this as long as you request the certificate from a proxy in a nonsanctioned country and you don't stick out to the government.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#263
post #261

Earlier quoted context omitted.

That's a fair opinion to have. But the US isn't really unique in applying their laws extraterritorially. See GDPR, Universal jurisdiction laws, China's National Security Law, etc... Every jurisdiction with sizable power does it. Some of these are even more extraterritorial in scope than US sanctions are.

> GDPR Only applies to EU citizens' personal data, so while technically extraterritorial it doesn't feel like overreach in the same way. > Universal jurisdiction laws Rightly controversial when applied beyond things that are internationally agreed to be crimes against humanity, like torture or genocide. > China's National Security Law A perfect example of the kind of thing that the US used to define itself in opposit…

The difference between any of these is just a matter of opinion on what sovereignty means, what or who or where it applies to, what is a “human rights violation”, and who has the bigger britches to back it up. /shrug

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#264

Couldn't LE have a branch in Europe or anywhere outside the USA and its minions? Because they're betraying their own goals, as stated in their About page: “It is a service run for the public’s benefit. [...] Anyone who owns a domain name can use Let’s Encrypt to obtain a trusted certificate at zero cost. [...] Let’s Encrypt is a joint effort to benefit the community, beyond the control of any one organization.” Now t…

They could, but if the branch didn’t follow these laws, the main US branch would still be liable.

What if the branch in Iran was the main branch?

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#265

Earlier quoted context omitted.

The way you are using these words seems to indicate you might be confused about how this works. The US has not "sanctioned" LetsEncrypt or ISRG. The US sanctions foreign entities as punishment for various reasons precisely because they are not subject to US law. That's the entire point of leveraging a sanction -- to pressure those outside of your legal jurisdiction. If they were in your jurisdiction, you'd simply arr…

This is not that though. This is literally about a company that has a branch in the USA and another branch in another country, where it's bound by that country's laws. If the foreign entity which just so happens to be commercially linked to the one in the USA has any dealings with countries sanctioned by the US, the US branch is punished. There was a case a few years ago where a public University in Brazil bought lab…

Why didn't the university just ignore the terms of service?

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#266
post #197
post #51

Earlier quoted context omitted.

I trust governments much less that a conglomerate of competing corporations. With all the problems with Web PKI, at least the bad actors are getting distrusted, and this provides a very strong enforcement on the rest. And Certificate Transparency makes sure the mis-issuance would be caught. It is not perfect by any means, but things are getting better. With DANE (or other country-issued certificates), every governmen…

I'm not really in favor of DANE, because DNSSEC is such a mess ... but. Certificate transparency is nice. Browsers could require it for DANE certificates, just like they require it for current Web PKI certificates. The people controlling the TLD of interesting can exert control over the domain of interest in order to issue a DANE certificate. But they can also exert control over the domain of interest in order to req…

CT seems useless for DANE because the cert is self signed, so anyone can just flood the CT with self signed certs for your website. It's useful with WebPKI because only certs signed by a CA go in CT and it's a big deal if one is mis-issued. Anyone can mis-issue a self-signed cert at home for fun.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#267
post #165

Earlier quoted context omitted.

DANE is entirely dependent on DNSSEC, and DNSSEC is, by design, under the government control, with all the bureaucratic mess and mistakes this implies. This would be pretty terrible if anyone actually cared about DNSSEC, but luckily for us, no one cares.. So let's keep things this way.

You obviously don't know how DNSSEC works. The DNS root of trust is ICANN, not a government.

That's worse, because ICANN is effectively the US government.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#268
post #165

Earlier quoted context omitted.

> every government will absolutely double-issue certificates to police, secret service and friends of goverment, and no one will have any recourse. Countries already have CA that issue certificates with more legal force than a handwritten signature. I can open a bank account, pay my taxes and sign up to all government services. But I can't use them for a webpage. > With DANE (or other country-issued certificates) DAN…

DANE is entirely dependent on DNSSEC, and DNSSEC is, by design, under the government control, with all the bureaucratic mess and mistakes this implies. This would be pretty terrible if anyone actually cared about DNSSEC, but luckily for us, no one cares.. So let's keep things this way.

Domain registries can already get a certificate for your domain by changing the address to their own server temporarily and then doing ACME with LE. So no new vector is introduced by directly putting the cert in DNS.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#269
post #183

Earlier quoted context omitted.

One, in a democracy, is accountable to adults in the same jurisdiction. The other is only accountable to those with financial ties to its success.

> One, in a democracy, is accountable to adults in the same jurisdiction Or so they say. How's that been working out in practice?

If each country could only sign its own domains it would make sense. If the US could only tamper with .us domains the system could be trusted in general. After all, that's no worse than what they already do by coming to your house and putting a gun to your head.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#270

Earlier quoted context omitted.

I suspect any "backdoor" would be inserted at the protocol level. See https://web.archive.org/web/20130918135152/http://www.thegua...

How would they do that? The ACME protocol is "take the basic artifacts you use for certificate signing, wrap them in JSON (cryptographically, using standard JWS), then send them over using HTTP + TLS." Every part of that is something for which there exists a buttload of implementations in whatever language you care to use.

> How would they do that?

Let me introduce you to the phrase "I don't see a mechanism."

Post reply on HN