Live data from Hacker News

Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

letsencrypt.org

311–320 of 404 posts

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#311

Earlier quoted context omitted.

You're assuming that satellites are exterritorial. They aren't, they're ab initio the launching state's property and responsibility, barring other agreements to transfer them - and getting one out into a "legal void" isn't going to be trivial.

Over the centuries I am sure there will be random satellites that are defunct that will be hacked or otherwise "taken over" by someone with the right skills. These things are tiny compared to the distances involved and in the future you might end up using them as data reservoirs since in many cases it will be cost prohibitive for any authority to go collect or otherwise stake authority over an old piece of hardware c…

In a hundred years, sure. Current satellites have neither storage nor compute capabilities of note.

That said, they don't have to grab the satellite. They have to grab you. Computer vandalism/sabotage/... laws in a lot of legal systems already apply to the controlling people in their home location regardless of the physical location/origin of the computer activity. Your controlling the computer/satellite/botnet/... is the illegal act, not the network packets leaving those systems.

They'll have to identify you first though, which might give some legal shielding.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#312
post #300

Earlier quoted context omitted.

Seems in all thing tech at the moment the US legal system is accelearting a great split and erectinga digital iron curtain, from AI models to the more mundane like TLS certs. Its been standard for a while for many Linux distros based in the US to toe the party line - like RedHat having notices pretty similar to this one by LE. Seems any meaningful Open Projects will have to choose what path they want to take, be like…

It isn't just the US. China, Russia, the EU, and Australia and probably others are all increasingly trying to create virtual walls of various forms in the internet.

It is in the nature of nation states to assert control over national borders. That the Internet and the globalised flow of information it enables circumvents this is a historical anomaly.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#313
post #175

Earlier quoted context omitted.

> pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries This is most likely OFAC. Lets Encrypt could apply for a license to do business with sanctioned entities, and given their use case it would most likely be approved. https://ofac.treasury.gov/ofac-license-application-page

OFAC regulates commerce, not speech. Let's Encrypt is not doing "business", they're operating a free informational service. Lots of organizations interpret any information exchange as subject to OFAC regulation, and you and Let's Encrypt have good company in this interpretation, but I think it's unnecessarily ceding ground.

IANAL, but this seems wrong.

In an alternate universe, Let’s Encrypt has a chat with someone and then states, publicly, like a speech, that they think that person owns a domain.

In our universe, Let’s Encrypt lets a client open an “account”, enters into a contract with the client (the contract is the topic of this entire post), and gives the client an API by which the client requests a certificate. Then Let’s Encrypt grants the certificate. Maybe the certificate is somehow speech. The rest sure doesn’t sound like speech to me.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#314
post #108

This somehow confirms my gut feeling that digital certificates are mainly a means to enforce exclusion on behalf of the certificate authority ownership. It is a tool to prevent people from taking full ownership and control of whatever is affected by digital certificates, be it software, firmware, hardware, or as in this case SSL/TLS. That's digital tyranny in disguise.

While it seems like certificate authority has the primary control here, the real control lies in browsers and operative systems in which certificate authorities are trusted. Users also have, at least for the moment, control to add or remove certificate authorities, even if that control is slightly less clear for devices like smart phones. Digital certificates that signs software packages are used to enforce exclusion…

> the real control lies in browsers and operative systems in which certificate authorities are trusted

Wasn't Let's encrypt a Mozilla child ?

The real control lies at who defines what is trusted.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#315

Let's Encrypt’s mission is to create a more secure and privacy-respecting web, except for people residing in countries with the most need for a more secure and privacy-respecting web. Sure, that's great. That said, pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries. I'm sure some of y'all are old enough to remember when web browsers came in "international fr…

Some (well, at least one) of us are old enough to have owned one of these: http://www.cypherspace.org/adam/uk-shirt.html A t-shirt with a Perl script that implemented RSA encryption strong enough to be technically illegal to export from the US. (I must sadly admit to being too cowardly/sensible to have taken that shirt to the US in the late 90s...)

DeCSS printed on stuff was a thing for a while, too.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#316
post #208

Earlier quoted context omitted.

US law is something US citizens get to decide. If they think it's "batshit", they should vote accordingly. In this case sanctions seem a pretty good alternative to going to war.

The US is an oligarchy. Voting in the US is completely irrelevant to which laws pass - there have been studies about this.

It's clear that those who voted recently for the President are getting what they wanted. Voting made a radical difference, even if the outcome isn't one I like. Whatever "studies" you read are obvious nonsense.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#317
post #239

Earlier quoted context omitted.

Let's Encrypt continues to be available to almost every vulnerable population in the world, including those that need it most. I say almost as I'm hesitant to speak in absolutes regarding a topic as complex as this. Most of our sanctions-related blocks apply only to the governments of certain sanctioned countries, not their general population. This subscriber agreement update was intended to better reflect our legal…

> Most of our sanctions-related blocks apply only to the governments of certain sanctioned countries, not their general population. The agreement very plainly says otherwise: > You are not a person or entity that is: (a) located in, organized under the laws of, or ordinarily resident in any country or territory that is the target of comprehensive U.S. sanctions The general population of those countries are absolutely…

I assumed that they meant that they will not enforce it via technical means.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#318

Let's Encrypt’s mission is to create a more secure and privacy-respecting web, except for people residing in countries with the most need for a more secure and privacy-respecting web. Sure, that's great. That said, pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries. I'm sure some of y'all are old enough to remember when web browsers came in "international fr…

I mean, noone is stopping someone to clone letsencrypt - it shouldn't be very hard.

Google had a similar dilemma - do they want to offer a (censored) service in China, and have a hope of keeping some marketshare, or not (and be kicked out immediately).

In this case though, it seems to be an unforced move by letsencrypt ? Or was it compelled by LEAs?

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#319
All they can do is disable support for certain ccTLDs, but other than that, it's unenforceable.

That's why many tech companies echo these laws overtly and with a lot of fanfare... They know they have no real control over who uses their services, so this is a way to signal their good faith and best effort in advance, in case they end up caught up in some foreign cyberbullshit.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#320

Is this actually new? Looks like a standard US export restriction for encryption technology to me. These sorts of restrictions have been around since the '90s. Let's Encrypt becomes subject to US export restrictions on cryptography if they are a US company, or if they post anything to github or post anything to major app stores. Every app I have ever posted to Google Play has had to submit a form to the US government…

A certificate is not cryptography, though, it's a number. The entity requesting the certificate already has the cryptographic software installed on their servers, as do the clients trying to connect to them. There's nothing technologically special about the number, it's all in the realm of the social contract, in that it has been blessed by a chain of trust.

Everything is a number.
Post reply on HN