Earlier quoted context omitted.
So what? If I disagree with the direction any FOSS project (or its maintainers) is taking... I can just fork it. People have done that countless times in the history of FOSS, most notably in the xOffice schism.
No remotely western company will risk US sanctions violations or whatever other regulatory burden by using US technology where it can't be used. Even Chinese companies depending on how state backed they are might not be willing to risk it.
Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
361–370 of 404 posts
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#362Earlier quoted context omitted.
> Do we also need to put all our letters into strongboxes before we send them? If it were as cheap and efficient as TLS these days, yes, absolutely > Maybe we should have solve the ISP snooping problem by making that illegal instead. We could do both! ISP snooping is still a problem for metadata (SNI).
Apparently the cost of TLS these days is to subject yourself to whatever laws that countries of "free" TLS want to impose on you. That isn't very cheap.
As for who does that authentication: Given all the suggestions in the sibling threads, I really don't think we're in a situation where there's a single entity gatekeeping access by any means.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#363How are they going to enforce this?
I would imagine, as a CA that issues only DV certs, they'd disallow issuance to various ccTLDs, and perhaps stop newAccount registrations with email addresses at those ccTLDs. That's about as much as they could do - IP-blocking by region is ineffective and crude at best.
They also likely would have to implement some kind of domain name screening, just like banks have to block transfers that mention "Havana" or "Tehran".
They are currently not doing anything, even ccTLD blocks. They have issued certificates for .kp domains this month and in August of last year.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#364Earlier quoted context omitted.
> How would they do that? Let me introduce you to the phrase "I don't see a mechanism."
>Let me introduce you to the phrase "I don't see a mechanism." I'm not familiar with this phrase, but I think I did a good job citing a comparable example in my original post.
Things that definitely don't happen. Those same encryption standards are used by the US military, and the international cryptography community can pretty readily rule out keyed backdoors.
The thought that supercomputers could break Internet encryption by brute force is laughable. One would have to be innumerate to think such a thing.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#365Earlier quoted context omitted.
> pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries This is most likely OFAC. Lets Encrypt could apply for a license to do business with sanctioned entities, and given their use case it would most likely be approved. https://ofac.treasury.gov/ofac-license-application-page
OFAC regulates commerce, not speech. Let's Encrypt is not doing "business", they're operating a free informational service. Lots of organizations interpret any information exchange as subject to OFAC regulation, and you and Let's Encrypt have good company in this interpretation, but I think it's unnecessarily ceding ground.
And here: https://github.blog/news-insights/policy-news-and-insights/a...
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#366Earlier quoted context omitted.
Seems in all thing tech at the moment the US legal system is accelearting a great split and erectinga digital iron curtain, from AI models to the more mundane like TLS certs. Its been standard for a while for many Linux distros based in the US to toe the party line - like RedHat having notices pretty similar to this one by LE. Seems any meaningful Open Projects will have to choose what path they want to take, be like…
The RISC-V move was laughable. It’s still US tech, developed largely with DARPA funds.
> Open source standards provide great benefits to U.S. taxpayers in reducing the cost of advanced military system development, and also increases security by allowing the government to build their own trusted implementations at low cost.
You can read more about it here: https://riscv.org/about/ -> See section "DARPA Influence"About their move to Switzerland, they say:
> RISC-V International has not incorporated in Switzerland based on any one country, company, government, or event. This move is reflective of community concern and managing strategic risk for our community investing in RISC-V for the next 50+ years.Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#367Earlier quoted context omitted.
That's a fair opinion to have. But the US isn't really unique in applying their laws extraterritorially. See GDPR, Universal jurisdiction laws, China's National Security Law, etc... Every jurisdiction with sizable power does it. Some of these are even more extraterritorial in scope than US sanctions are.
> GDPR Only applies to EU citizens' personal data, so while technically extraterritorial it doesn't feel like overreach in the same way. > Universal jurisdiction laws Rightly controversial when applied beyond things that are internationally agreed to be crimes against humanity, like torture or genocide. > China's National Security Law A perfect example of the kind of thing that the US used to define itself in opposit…
That's not true.
The GDPR applies to the personal data of anyone physically in the EU, to the extent that the data are processed[0] while they are in the EU.
It also applies to the personal data of anybody anywhere in the world if the data controllers are based in the EU.
The reason why it's different to US sanctions/export controls is that the GDPR doesn't say you can't work with certain people in certain circumstances because of who they are in order to punish those people for whatever reason. It's fundamentally to protect the data subjects.
[0] which includes collection of said data
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#368Earlier quoted context omitted.
Let's Encrypt continues to be available to almost every vulnerable population in the world, including those that need it most. I say almost as I'm hesitant to speak in absolutes regarding a topic as complex as this. Most of our sanctions-related blocks apply only to the governments of certain sanctioned countries, not their general population. This subscriber agreement update was intended to better reflect our legal…
You issued a certificate for North Korea's email infrastructure as recently as six days ago : https://crt.sh/?id=26878583197 (06/04/2026 smtp.star-co.net.kp) https://crt.sh/?id=20256841119 (08/11/2025 *.star.net.kp) Star Joint Venture is the manager of the .kp TLD and one of DPRK's two email providers (the other is silibank.net.kp) [1], used as the official email for various government bodies ex. ipa817@star-co.net.k…
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#369Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#370Earlier quoted context omitted.
Yes actually you still could've. But it would require a pass through the IETF to stabdaddize a DNS record type, and that would delay Netscape's release.
Any DNS-based solution needs something like DNSSEC to work. I believe DNSSEC didn't exist yet when HTTPS was being developed and even if it did, it wasn't anywhere near ubiquitous enough. Is it even these days?