It their right to do that. But can we still trust them? I am not well versed in how their systemwide certificate issuance works: If they have to add this to their terms to comply with their government, could the same government use pressure to leverage let’s encrypt to do harm.
Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
281–290 of 404 posts
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#282Does it mean that russian/iranian web-sites using letsencrypt stop working and need to change their certificate provider?
Depends on whether LE is compelled to terminate service to BGP AS numbers hosted in U.S.-sanctioned countries, and whether LE continues operating out of the U.S..
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#283Time for a non-US equivalent of Let's Encrypt?
Especially since sanctions are transitive. Mozilla and Google, being US companies, are actually not allowed to trust any entity whose purpose is to work around sanctions. Their members could go to jail for that.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#284Earlier quoted context omitted.
The RISC-V move was laughable. It’s still US tech, developed largely with DARPA funds.
So what? If I disagree with the direction any FOSS project (or its maintainers) is taking... I can just fork it. People have done that countless times in the history of FOSS, most notably in the xOffice schism.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#285Earlier quoted context omitted.
When you say “our legal requirements” do you mean requirements LE imposes in its agreements or requires imposed on LE by governments?
I was referring to the requirements imposed on us. When it comes to sanctions, we do not block anything more than what is required by law.
Wouldn't the more rational response to this legal situation be to leave the USA and move somewhere more willing to respect international law?
[0] https://www.whitehouse.gov/presidential-actions/2025/02/impo...
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#286Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#287Earlier quoted context omitted.
I always saw it as a trust-chain and think that anyone is welcomed to create a root certificate and distribute it to whomever trusts them. Most simple services may not need TLS, but with the ISPs eavesdropping on our communication, a form of secure communication is required and the currently best solution we have requires a trust-chain to be built.
It is such a great improvement that ISPs cannot eavesdrop us anymore... only for everyone to terminate TLS at cloudflare so they (and thus US government) can now eavesdrop everyone.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#288Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#289Let's Encrypt’s mission is to create a more secure and privacy-respecting web, except for people residing in countries with the most need for a more secure and privacy-respecting web. Sure, that's great. That said, pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries. I'm sure some of y'all are old enough to remember when web browsers came in "international fr…
> Let's Encrypt’s mission is to create a more secure and privacy-respecting web, except for people residing in countries with the most need for a more secure and privacy-respecting web. Sure, that's great. If complying with the law gets in the way of the mission I’m not sure that counts as a change to the mission.
It's already illegal to use in NK, but if it's the US, well it's time to steer the mission around it? Gross.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#290Let's Encrypt’s mission is to create a more secure and privacy-respecting web, except for people residing in countries with the most need for a more secure and privacy-respecting web. Sure, that's great. That said, pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries. I'm sure some of y'all are old enough to remember when web browsers came in "international fr…
Some (well, at least one) of us are old enough to have owned one of these: http://www.cypherspace.org/adam/uk-shirt.html A t-shirt with a Perl script that implemented RSA encryption strong enough to be technically illegal to export from the US. (I must sadly admit to being too cowardly/sensible to have taken that shirt to the US in the late 90s...)
OpenBSD being based in Canada ships strong crypto, but has had a sometimes troubled relationship with certain regimes.