Live data from Hacker News

Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

letsencrypt.org

271–280 of 404 posts

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#271
post #202

Earlier quoted context omitted.

> Has letsencrypt been served with a subpoena? While it's certainly possible that ISRG has been served a subpoena because it appears the US DOJ is now a mix of hacks and incompetent buffoons, it wouldn't matter because the whole point is that they don't know anything - what you told them is literally logged publicly for everybody to see without even knowing how to spell "subpoena" let alone issue one. Some people hav…

> Some people have this insane idea that somehow the CA has some secret which either they minted and sent to the CA, or the CA minted and gave them a copy and so the US government could get this secret with a subpoena LetsEncrypt certainly doesn't, but I've seen certificate storefronts that generate the key on their side and provide you the key and the certificate, so you don't have to figure out how to generate a ke…

The Certificate Authorities are specifically forbidden from doing this because it's so obviously a terrible idea. Many of them also require that their resellers (obviously Let's Encrypt basically doesn't have resellers because that's stupid) also do not do this because it's a terrible idea.

But yes, you're correct that, especially when "cheap SSL" was a thing, outfits which did this really existed. In fact one of the companies which did this, and then deliberately revealed customer keys, resulting in all the affected certificates being revoked, isn't even bankrupt so apparently their customers are so stupid than they're still paying money for a service that's much worse than useless. Not an optimistic thought about humanity.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#272

Earlier quoted context omitted.

> I always saw it as a trust-chain and think that anyone is welcomed to create a root certificate and distribute it to whomever trusts them. Note that phones already try to prevent you from using a certificate that you provide yourself.

" Try to prevent"? What does that mean?

It means they prevent, unless you perform several undocumented arcane rituals.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#273

Earlier quoted context omitted.

You could that with a much saner approach like DANE.

Not back when SSL and the PKI ecosystem was developed.

Yes actually you still could've. But it would require a pass through the IETF to stabdaddize a DNS record type, and that would delay Netscape's release.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#274
post #29

It seems that, as soon as you transact with a sanctioned entity, you are globally in breach of the agreement and risking the revocation of all your certificates — also the ones for non-sanctioned countries. Front matter: - it is called a "Subscriber Agreement" and not anything that suggests that its scope is a single certificate - it's a "contract [...] regarding Your [...] rights and duties relating to [...] Certifi…

I said hi to an Iranian today. Lets see if LE revokes my website.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#275
post #137
post #130

Earlier quoted context omitted.

Have you heard about the judge from international court or whatever it is called? https://www.france24.com/en/americas/20250820-us-hits-icc-wi...

Are you saying the ICC is the EU? Or that it's Greenland?

I think the point is people are getting sanctioned for arbitrarily stupid reasons these days.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#276

Now this is very bad, as bad as it can get. As soon as all local services will stop working in sanctioned countries, those countries' governments will force all users to either install a root certificate or lose access to all local services and websites. And then it will be possible to use that root certificate for MITM attacks. In the worst case scenario, after the majority of users will install the root certificate…

Sounds like the sanctions worked.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#277
post #91

Maybe consolidating ~60% of the web's certificates on to a single provider was a mistake.

Before this, they were all unencrypted and you had to pay to get a cert. I guess we could go back to that - now knowing that every unencrypted connection is being MITMed (the world is so much more hostile now)...

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#278

Earlier quoted context omitted.

How would they do that? The ACME protocol is "take the basic artifacts you use for certificate signing, wrap them in JSON (cryptographically, using standard JWS), then send them over using HTTP + TLS." Every part of that is something for which there exists a buttload of implementations in whatever language you care to use.

> How would they do that? Let me introduce you to the phrase "I don't see a mechanism."

>Let me introduce you to the phrase "I don't see a mechanism."

I'm not familiar with this phrase, but I think I did a good job citing a comparable example in my original post.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#279
post #208
post #33

Earlier quoted context omitted.

The headline is more « US law is batshit and extends well beyond its borders with real world consequences »

US law is something US citizens get to decide. If they think it's "batshit", they should vote accordingly. In this case sanctions seem a pretty good alternative to going to war.

The US is an oligarchy. Voting in the US is completely irrelevant to which laws pass - there have been studies about this.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#280

Earlier quoted context omitted.

> but I don't see many companies stepping up to provide competing services Maybe because the US dropped most of its anti trust regulations, leading to ridiculously monopolistic practices such as "acquire everything that may be threatening".

When was the last time you heard about a European cellphone manufacturer, or social media network, or web browser being acquired by an American monopoly? I can only think of Nokia, purchased by microsoft in 2014. Those phones ran windows CE before that even, so you could hardly have avoided the american tech industry. All I'm trying to say is, it's impossible for Europeans to both A) be on the internet and B) avoid t…

In the EU there is the threat of jail time if a user of your service does something bad and you haven't completed the necessary bureaucracy to be immune to it. This is the opposite of the US. See for example pissmail.
Post reply on HN