Earlier quoted context omitted.
I always saw it as a trust-chain and think that anyone is welcomed to create a root certificate and distribute it to whomever trusts them. Most simple services may not need TLS, but with the ISPs eavesdropping on our communication, a form of secure communication is required and the currently best solution we have requires a trust-chain to be built.
It is such a great improvement that ISPs cannot eavesdrop us anymore... only for everyone to terminate TLS at cloudflare so they (and thus US government) can now eavesdrop everyone.
Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
321–330 of 404 posts
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#322Let's Encrypt’s mission is to create a more secure and privacy-respecting web, except for people residing in countries with the most need for a more secure and privacy-respecting web. Sure, that's great. That said, pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries. I'm sure some of y'all are old enough to remember when web browsers came in "international fr…
Let's Encrypt continues to be available to almost every vulnerable population in the world, including those that need it most. I say almost as I'm hesitant to speak in absolutes regarding a topic as complex as this. Most of our sanctions-related blocks apply only to the governments of certain sanctioned countries, not their general population. This subscriber agreement update was intended to better reflect our legal…
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#323Earlier quoted context omitted.
It is such a great improvement that ISPs cannot eavesdrop us anymore... only for everyone to terminate TLS at cloudflare so they (and thus US government) can now eavesdrop everyone.
If you have a service that shares information between people all over the world, a few big companies and one government is for most cases an improvement over all the involved ISPs and all of their respective governments.
The involved ISP and respective governments do still see everything, but also cloudflare and the US ISPs they use see it in the clear.
Also the US has a history of abusing its position here, even with less honeypot like companies.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#324Earlier quoted context omitted.
We could, and should, switch to DANE. Or else, switch to how X.509 was supposed to be used, with each country running a CA for their nationals.
I trust governments much less that a conglomerate of competing corporations. With all the problems with Web PKI, at least the bad actors are getting distrusted, and this provides a very strong enforcement on the rest. And Certificate Transparency makes sure the mis-issuance would be caught. It is not perfect by any means, but things are getting better. With DANE (or other country-issued certificates), every governmen…
I have never worked in any company where I explicitly trust the CEO to always do the right thing in every situation.
There is usually no governance board, or review system to inquire about public harm: those things are usually external and fought against as they are regulatory burden.
So, in practice what tends to happen is that someone in the company just does stuff. Since humans aren't perfect this "doing stuff" is not always super enjoyable. If it's the CEO who "does stuff" then you're cooked because nobody except the board of directors can say anything meaningful: you gotta hope that the media wants to put pressure on.
Our elected officials on the other hand, are supposed to represent us, and thus media pressure is a lot stronger; issues that affect many people are meant to be properly reflected, and their decisions are open by default.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#325Earlier quoted context omitted.
The current US government sanctions political enemies [0]. Wouldn't the more rational response to this legal situation be to leave the USA and move somewhere more willing to respect international law? [0] https://www.whitehouse.gov/presidential-actions/2025/02/impo...
According to the current administration, almost half of the US is considered a political enemy of the current administration. Soon they might be pushing for Operating Systems to gather political party preference information, so they can know who should be restricted from the use of strong encryption. The options being: 1. I love america 2. Radical left looney 3. Neither male nor female. 4. Those that tremble as if th…
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#326Earlier quoted context omitted.
So what? If I disagree with the direction any FOSS project (or its maintainers) is taking... I can just fork it. People have done that countless times in the history of FOSS, most notably in the xOffice schism.
No remotely western company will risk US sanctions violations or whatever other regulatory burden by using US technology where it can't be used. Even Chinese companies depending on how state backed they are might not be willing to risk it.
One is the mirror image of the other and neither economy can exist in its current state in isolation.
So China has the US over a barrel when it comes to actually building stuff, rare earths and all of that, but equally US sanctions still have real bite (a lot more than China would like) because China does have to do a huge amount of international trade to export and externalise its surpluses.
They're stuck in this unhappy marriage
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#327Earlier quoted context omitted.
When you say “our legal requirements” do you mean requirements LE imposes in its agreements or requires imposed on LE by governments?
I was referring to the requirements imposed on us. When it comes to sanctions, we do not block anything more than what is required by law.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#328Earlier quoted context omitted.
I always saw it as a trust-chain and think that anyone is welcomed to create a root certificate and distribute it to whomever trusts them. Most simple services may not need TLS, but with the ISPs eavesdropping on our communication, a form of secure communication is required and the currently best solution we have requires a trust-chain to be built.
The problem is that finding a root source of trust aren't easy this days. LE was neutral, now nobody is. Russian government issued their new root certificate years ago. Nobody trusted it enough to request a certificate from them or install it on their computers. Including almost all of the russian residents. If Let's Encrypt enforces the rules, as written in pdf, a lot of people would lose a choice. Frankly, even pub…
Let's be real here… 99.99999999999999% of internet users have no idea what root CAs even are. It's the browser vendor mafia that makes the decision.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#329Iran is blocking internet for months, US ...bans creation of secure connections - that'll show 'em! Russian quasi-government structures are spending quadrillion of rubles on a TSPU (censorship system) to spy on Russian residents, US ...helps them by making snooping on what is currently encrypted traffic possible by banning accessible encryption!
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#330Earlier quoted context omitted.
No it isn't. Not unless it's free. This is the main reason letsencrypt is so popular.
They do have a free plan with unlimited ACME DV certs, though! Not marketed very well and no wildcard certs, but it does exist.