Live data from Hacker News

Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

letsencrypt.org

281–290 of 404 posts

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#281

It their right to do that. But can we still trust them? I am not well versed in how their systemwide certificate issuance works: If they have to add this to their terms to comply with their government, could the same government use pressure to leverage let’s encrypt to do harm.

Yes, of course it could and it will. I don't think the US government has ever missed an opportunity to be corrupt and break shit for stupid reasons.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#282

Does it mean that russian/iranian web-sites using letsencrypt stop working and need to change their certificate provider?

Depends on whether LE is compelled to terminate service to BGP AS numbers hosted in U.S.-sanctioned countries, and whether LE continues operating out of the U.S..

It works like this. The US gov sends LE a nastygram saying they must terminate service to sanctioned entities. LE either does that or several people go to jail. The USgov doesn't care how it happens, as long as they can't find any evidence that any sanctioned entities are LE customers.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#283
post #198

Time for a non-US equivalent of Let's Encrypt?

How will you get Mozilla and Google to trust it?

Especially since sanctions are transitive. Mozilla and Google, being US companies, are actually not allowed to trust any entity whose purpose is to work around sanctions. Their members could go to jail for that.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#284
post #144

Earlier quoted context omitted.

The RISC-V move was laughable. It’s still US tech, developed largely with DARPA funds.

So what? If I disagree with the direction any FOSS project (or its maintainers) is taking... I can just fork it. People have done that countless times in the history of FOSS, most notably in the xOffice schism.

No remotely western company will risk US sanctions violations or whatever other regulatory burden by using US technology where it can't be used. Even Chinese companies depending on how state backed they are might not be willing to risk it.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#285
post #247

Earlier quoted context omitted.

When you say “our legal requirements” do you mean requirements LE imposes in its agreements or requires imposed on LE by governments?

I was referring to the requirements imposed on us. When it comes to sanctions, we do not block anything more than what is required by law.

The current US government sanctions political enemies [0].

Wouldn't the more rational response to this legal situation be to leave the USA and move somewhere more willing to respect international law?

[0] https://www.whitehouse.gov/presidential-actions/2025/02/impo...

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#287

Earlier quoted context omitted.

I always saw it as a trust-chain and think that anyone is welcomed to create a root certificate and distribute it to whomever trusts them. Most simple services may not need TLS, but with the ISPs eavesdropping on our communication, a form of secure communication is required and the currently best solution we have requires a trust-chain to be built.

It is such a great improvement that ISPs cannot eavesdrop us anymore... only for everyone to terminate TLS at cloudflare so they (and thus US government) can now eavesdrop everyone.

If you have a service that shares information between people all over the world, a few big companies and one government is for most cases an improvement over all the involved ISPs and all of their respective governments.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#288
post #137

Earlier quoted context omitted.

Are you saying the ICC is the EU? Or that it's Greenland?

I think the point is people are getting sanctioned for arbitrarily stupid reasons these days.

It wasn't made very well.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#289

Let's Encrypt’s mission is to create a more secure and privacy-respecting web, except for people residing in countries with the most need for a more secure and privacy-respecting web. Sure, that's great. That said, pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries. I'm sure some of y'all are old enough to remember when web browsers came in "international fr…

> Let's Encrypt’s mission is to create a more secure and privacy-respecting web, except for people residing in countries with the most need for a more secure and privacy-respecting web. Sure, that's great. If complying with the law gets in the way of the mission I’m not sure that counts as a change to the mission.

> If complying with a law gets in the way of the mission I’m not sure that counts as a change to the mission.

It's already illegal to use in NK, but if it's the US, well it's time to steer the mission around it? Gross.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#290

Let's Encrypt’s mission is to create a more secure and privacy-respecting web, except for people residing in countries with the most need for a more secure and privacy-respecting web. Sure, that's great. That said, pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries. I'm sure some of y'all are old enough to remember when web browsers came in "international fr…

Some (well, at least one) of us are old enough to have owned one of these: http://www.cypherspace.org/adam/uk-shirt.html A t-shirt with a Perl script that implemented RSA encryption strong enough to be technically illegal to export from the US. (I must sadly admit to being too cowardly/sensible to have taken that shirt to the US in the late 90s...)

I wore the rsa-dolphin t-shirt all over the place and nobody batted an eye back then, but a dolphin made up of ASCII characters is quite a bit less obvious than the one you linked.

OpenBSD being based in Canada ships strong crypto, but has had a sometimes troubled relationship with certain regimes.

https://www.openbsd.org/lyrics.html#34

Post reply on HN