Live data from Hacker News

Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

letsencrypt.org

321–330 of 404 posts

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#321

Earlier quoted context omitted.

I always saw it as a trust-chain and think that anyone is welcomed to create a root certificate and distribute it to whomever trusts them. Most simple services may not need TLS, but with the ISPs eavesdropping on our communication, a form of secure communication is required and the currently best solution we have requires a trust-chain to be built.

It is such a great improvement that ISPs cannot eavesdrop us anymore... only for everyone to terminate TLS at cloudflare so they (and thus US government) can now eavesdrop everyone.

Ultimately, I find it likely that TLS will become a tool to prevent users from accessing foreign content (browsers stubbornly refusing to show untrusted sites in the name of security, slowly getting there), more than a tool to prevent eavesdropping on users secrets.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#322
post #239

Let's Encrypt’s mission is to create a more secure and privacy-respecting web, except for people residing in countries with the most need for a more secure and privacy-respecting web. Sure, that's great. That said, pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries. I'm sure some of y'all are old enough to remember when web browsers came in "international fr…

Let's Encrypt continues to be available to almost every vulnerable population in the world, including those that need it most. I say almost as I'm hesitant to speak in absolutes regarding a topic as complex as this. Most of our sanctions-related blocks apply only to the governments of certain sanctioned countries, not their general population. This subscriber agreement update was intended to better reflect our legal…

Thanks for responding, and to clarify, I am confident that Let's Encrypt is shared as widely as they are able. Could you explain what that requirement does stem from?

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#323
post #287

Earlier quoted context omitted.

It is such a great improvement that ISPs cannot eavesdrop us anymore... only for everyone to terminate TLS at cloudflare so they (and thus US government) can now eavesdrop everyone.

If you have a service that shares information between people all over the world, a few big companies and one government is for most cases an improvement over all the involved ISPs and all of their respective governments.

That's not the trade-off you make though.

The involved ISP and respective governments do still see everything, but also cloudflare and the US ISPs they use see it in the clear.

Also the US has a history of abusing its position here, even with less honeypot like companies.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#324
post #51

Earlier quoted context omitted.

We could, and should, switch to DANE. Or else, switch to how X.509 was supposed to be used, with each country running a CA for their nationals.

I trust governments much less that a conglomerate of competing corporations. With all the problems with Web PKI, at least the bad actors are getting distrusted, and this provides a very strong enforcement on the rest. And Certificate Transparency makes sure the mis-issuance would be caught. It is not perfect by any means, but things are getting better. With DANE (or other country-issued certificates), every governmen…

Companies have run some absolutely outstanding PR then.

I have never worked in any company where I explicitly trust the CEO to always do the right thing in every situation.

There is usually no governance board, or review system to inquire about public harm: those things are usually external and fought against as they are regulatory burden.

So, in practice what tends to happen is that someone in the company just does stuff. Since humans aren't perfect this "doing stuff" is not always super enjoyable. If it's the CEO who "does stuff" then you're cooked because nobody except the board of directors can say anything meaningful: you gotta hope that the media wants to put pressure on.

Our elected officials on the other hand, are supposed to represent us, and thus media pressure is a lot stronger; issues that affect many people are meant to be properly reflected, and their decisions are open by default.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#325

Earlier quoted context omitted.

The current US government sanctions political enemies [0]. Wouldn't the more rational response to this legal situation be to leave the USA and move somewhere more willing to respect international law? [0] https://www.whitehouse.gov/presidential-actions/2025/02/impo...

According to the current administration, almost half of the US is considered a political enemy of the current administration. Soon they might be pushing for Operating Systems to gather political party preference information, so they can know who should be restricted from the use of strong encryption. The options being: 1. I love america 2. Radical left looney 3. Neither male nor female. 4. Those that tremble as if th…

It'll be interesting when/if they sanction Antifa. Since it doesn't exist, you can't prove that you're not a member of it. So they get to sanction anyone.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#326
post #284

Earlier quoted context omitted.

So what? If I disagree with the direction any FOSS project (or its maintainers) is taking... I can just fork it. People have done that countless times in the history of FOSS, most notably in the xOffice schism.

No remotely western company will risk US sanctions violations or whatever other regulatory burden by using US technology where it can't be used. Even Chinese companies depending on how state backed they are might not be willing to risk it.

This is the big irony of the current situation: while the US is dependent on China for manufactured goods, China is dependent on the US for external demand for its manufactured goods.

One is the mirror image of the other and neither economy can exist in its current state in isolation.

So China has the US over a barrel when it comes to actually building stuff, rare earths and all of that, but equally US sanctions still have real bite (a lot more than China would like) because China does have to do a huge amount of international trade to export and externalise its surpluses.

They're stuck in this unhappy marriage

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#327
post #247

Earlier quoted context omitted.

When you say “our legal requirements” do you mean requirements LE imposes in its agreements or requires imposed on LE by governments?

I was referring to the requirements imposed on us. When it comes to sanctions, we do not block anything more than what is required by law.

By whose law? Thailand? China? Germany? Afghanistan?

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#328

Earlier quoted context omitted.

I always saw it as a trust-chain and think that anyone is welcomed to create a root certificate and distribute it to whomever trusts them. Most simple services may not need TLS, but with the ISPs eavesdropping on our communication, a form of secure communication is required and the currently best solution we have requires a trust-chain to be built.

The problem is that finding a root source of trust aren't easy this days. LE was neutral, now nobody is. Russian government issued their new root certificate years ago. Nobody trusted it enough to request a certificate from them or install it on their computers. Including almost all of the russian residents. If Let's Encrypt enforces the rules, as written in pdf, a lot of people would lose a choice. Frankly, even pub…

> Nobody trusted it

Let's be real here… 99.99999999999999% of internet users have no idea what root CAs even are. It's the browser vendor mafia that makes the decision.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#329

Iran is blocking internet for months, US ...bans creation of secure connections - that'll show 'em! Russian quasi-government structures are spending quadrillion of rubles on a TSPU (censorship system) to spy on Russian residents, US ...helps them by making snooping on what is currently encrypted traffic possible by banning accessible encryption!

TSPU isn't for spying, it's for censorship enforcement and everything else that makes the experience of using the internet here miserable without a VPN. It's SORM that's for spying. And Roskomnadzor is very much part of the government.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#330
post #19
post #10

Earlier quoted context omitted.

No it isn't. Not unless it's free. This is the main reason letsencrypt is so popular.

They do have a free plan with unlimited ACME DV certs, though! Not marketed very well and no wildcard certs, but it does exist.

Oh, I stand corrected, thank you. I actually looked and couldn't find it. Indeed they could market it better.
Post reply on HN