Live data from Hacker News

Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

letsencrypt.org

301–310 of 404 posts

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#301

Earlier quoted context omitted.

They could, but if the branch didn’t follow these laws, the main US branch would still be liable.

Just close down completely in the US and move to the EU

So simple, just uproot your lives and move to a different continent 4heads!

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#302

Earlier quoted context omitted.

Suddenly the idea of having a CA hosted in space on a satellite issuing certs seems like a good idea.

A ship in international waters with satellite internet connection would be much cheaper, except it runs into the same problems as described by the sibling comment: https://news.ycombinator.com/item?id=48469397

Also, pirates

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#303
post #197

Earlier quoted context omitted.

I'm not really in favor of DANE, because DNSSEC is such a mess ... but. Certificate transparency is nice. Browsers could require it for DANE certificates, just like they require it for current Web PKI certificates. The people controlling the TLD of interesting can exert control over the domain of interest in order to issue a DANE certificate. But they can also exert control over the domain of interest in order to req…

CT seems useless for DANE because the cert is self signed, so anyone can just flood the CT with self signed certs for your website. It's useful with WebPKI because only certs signed by a CA go in CT and it's a big deal if one is mis-issued. Anyone can mis-issue a self-signed cert at home for fun.

You'd have to do something like pre-publish in DNS, submit to CT which verifies that it's in DNS before logging. And the CT could rate limit on domain name or something to reduce abuse.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#304
post #149

Earlier quoted context omitted.

Do you really think the EU wants to sign up for PR that’s essentially “the US is being too mean to Russia” right now?

I think the EU should do it regardless of Russia. The EU should invest in its own technology and not depend so much on an increasingly undependable ally.

The EU is more likely to issue fines to the ISRG and all involved parties.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#305
post #261

Earlier quoted context omitted.

> GDPR Only applies to EU citizens' personal data, so while technically extraterritorial it doesn't feel like overreach in the same way. > Universal jurisdiction laws Rightly controversial when applied beyond things that are internationally agreed to be crimes against humanity, like torture or genocide. > China's National Security Law A perfect example of the kind of thing that the US used to define itself in opposit…

The difference between any of these is just a matter of opinion on what sovereignty means, what or who or where it applies to, what is a “human rights violation”, and who has the bigger britches to back it up. /shrug

Meh. You can fall back on might makes right and a Hobbesian war of all against all, or you can recognise that the Westphalian system has brought immense value to humanity and is worth trying to preserve and build on. There will always be disputes about how to extend our principles into new domains, but that doesn't mean those disputes are insoluble or that a few disagreements mean we should tear down the whole project.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#306

Earlier quoted context omitted.

OFAC regulates commerce, not speech. Let's Encrypt is not doing "business", they're operating a free informational service. Lots of organizations interpret any information exchange as subject to OFAC regulation, and you and Let's Encrypt have good company in this interpretation, but I think it's unnecessarily ceding ground.

The government may use as wide of an interpretation of commerce as they can get away with. We've seen this happen before [0]. Sure, Let's Encrypt isn't taking money from the entities they offer certificates to. But the OFAC desk jockey assigned to that case only has to concoct some sufficiently plausible-sounding trail of money connecting the backing 501(c)3 and a sanctioned entity in order to levy penalties, and the…

IANAL, but it seems like the argument from Wickard v Filburn would apply to LE. They may not be taking money but they do impact the commerce of the market for certificates.

I disagree with that ruling, and I have some serious problems with sanctions against entire countries/regions, but it definitely makes sense that LE would interpret it as being impacted by OFAC.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#307

Earlier quoted context omitted.

The current US government sanctions political enemies [0]. Wouldn't the more rational response to this legal situation be to leave the USA and move somewhere more willing to respect international law? [0] https://www.whitehouse.gov/presidential-actions/2025/02/impo...

> move somewhere more willing to respect international law? Some of these sanctions are required by international law (i.e. sanctions imposed by UNSC). For the other ones, international law generally lets countries have whatever trade policy they see fit including sanctions, unless they violate some other rule of international law or treaty obligation.

Sanctioning the ICC obviously has nothing to do with trade policy.

The USA signed the Rome Statute but never ratified it, and then withdrew its signatory status. There's an argument to be made that there was a treaty obligation there, but it's pretty weak.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#308
post #51

Earlier quoted context omitted.

I trust governments much less that a conglomerate of competing corporations. With all the problems with Web PKI, at least the bad actors are getting distrusted, and this provides a very strong enforcement on the rest. And Certificate Transparency makes sure the mis-issuance would be caught. It is not perfect by any means, but things are getting better. With DANE (or other country-issued certificates), every governmen…

> I trust governments much less that a conglomerate of competing corporations Let's not create a world wide PKI based on a political ideology. > country-issued certificates [...] every government will absolutely double-issue certificates This is such a strange argument. If you register a .ru domain, do you really think you are safe should the Russian intelligence services ask for a valid certificate? Controlling the…

> The problem with our current SSL PKI, as so very many people have pointed out over the years, is that any CA is allowed to issue valid certificates for any domain name. There have been proposals to use X.509 extensions to remedy this, but they have seen lesser real world usage than the various certificate revocation schemes, which is very close to zero already.

Some of the browser root programs include (or have included) restrictions on what tlds a CA is allowed to sign. I think for some of the iffier CAs that nonetheless had a huge marketshare in their country of origin.

No need for the CA itself to include it in their root certificate.

It would be handy if the name restrictions actually worked though. Then you could probably get a CA to sign an intermediate CA authorized only to issue certs for your domain(s). There are some CAs that will do that already where they provide an HSM with the intermediate CA's key that will only sign certs for authorized domains, but the CA cert does not encode the constraint and this is permitted by the ca/b agreement. It just seems like it'd be nicer if it just worked.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#309
post #163

Earlier quoted context omitted.

> Let's Encrypt certificates continue to be available in both Iran and Russia, just not for the Iranian and Russian governments. According to https://news.ycombinator.com/item?id=48457280 it affects all people ordinarily resident in those territories, not just their governments: > You are not a person or entity that is: > (a) located in, organized under the laws of, or ordinarily resident in any country or territory…

Sanctions compliance is unfortunately fairly complex. Let's Encrypt can issue certificates for non-government entities in Iran and Russia due to statutory exemptions protecting personal communications, alongside specific Office of Foreign Assets Control (OFAC) authorizations designed to promote Internet freedom and human rights. We will look into whether we can make things more easily understandable in the subscriber…

> You are not a person or entity that is: (a) located in, organized under the laws of, or ordinarily resident in any country or territory that is the target of comprehensive U.S. sanctions

Seems to be pretty clear that it would include non-government entities in sanctioned countries.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#310
post #247

Earlier quoted context omitted.

I was referring to the requirements imposed on us. When it comes to sanctions, we do not block anything more than what is required by law.

The current US government sanctions political enemies [0]. Wouldn't the more rational response to this legal situation be to leave the USA and move somewhere more willing to respect international law? [0] https://www.whitehouse.gov/presidential-actions/2025/02/impo...

According to the current administration, almost half of the US is considered a political enemy of the current administration.

Soon they might be pushing for Operating Systems to gather political party preference information, so they can know who should be restricted from the use of strong encryption. The options being:

1. I love america

2. Radical left looney

3. Neither male nor female.

4. Those that tremble as if they were mad[0]

[0]: https://thewhippet.org/the-whippet-134-those-that-tremble/#c...

Post reply on HN