Live data from Hacker News

Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

letsencrypt.org

361–370 of 404 posts

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#361
post #284

Earlier quoted context omitted.

So what? If I disagree with the direction any FOSS project (or its maintainers) is taking... I can just fork it. People have done that countless times in the history of FOSS, most notably in the xOffice schism.

No remotely western company will risk US sanctions violations or whatever other regulatory burden by using US technology where it can't be used. Even Chinese companies depending on how state backed they are might not be willing to risk it.

It doesn't matter what technology is used, sanctions are imposed when USA doesn't like something.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#362
post #205

Earlier quoted context omitted.

> Do we also need to put all our letters into strongboxes before we send them? If it were as cheap and efficient as TLS these days, yes, absolutely > Maybe we should have solve the ISP snooping problem by making that illegal instead. We could do both! ISP snooping is still a problem for metadata (SNI).

Apparently the cost of TLS these days is to subject yourself to whatever laws that countries of "free" TLS want to impose on you. That isn't very cheap.

I'd also love TOFU for TLS, at least on .local TLDs, but for publicly hosted websites, I've come around to the idea that maybe encryption without authentication would not help that much these days.

As for who does that authentication: Given all the suggestions in the sibling threads, I really don't think we're in a situation where there's a single entity gatekeeping access by any means.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#363
post #40
post #21

How are they going to enforce this?

I would imagine, as a CA that issues only DV certs, they'd disallow issuance to various ccTLDs, and perhaps stop newAccount registrations with email addresses at those ccTLDs. That's about as much as they could do - IP-blocking by region is ineffective and crude at best.

The question is, will that be enough? If OFAC can demonstrate that even with such restrictions, sanctioned entities are frequently obtaining certificates, they may be forced to require account creation or something else as a means of limiting that.

They also likely would have to implement some kind of domain name screening, just like banks have to block transfers that mention "Havana" or "Tehran".

They are currently not doing anything, even ccTLD blocks. They have issued certificates for .kp domains this month and in August of last year.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#364

Earlier quoted context omitted.

> How would they do that? Let me introduce you to the phrase "I don't see a mechanism."

>Let me introduce you to the phrase "I don't see a mechanism." I'm not familiar with this phrase, but I think I did a good job citing a comparable example in my original post.

> Those methods include covert measures to ensure NSA control over setting of international encryption standards, the use of supercomputers to break encryption with "brute force",

Things that definitely don't happen. Those same encryption standards are used by the US military, and the international cryptography community can pretty readily rule out keyed backdoors.

The thought that supercomputers could break Internet encryption by brute force is laughable. One would have to be innumerate to think such a thing.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#365
post #175

Earlier quoted context omitted.

> pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries This is most likely OFAC. Lets Encrypt could apply for a license to do business with sanctioned entities, and given their use case it would most likely be approved. https://ofac.treasury.gov/ofac-license-application-page

OFAC regulates commerce, not speech. Let's Encrypt is not doing "business", they're operating a free informational service. Lots of organizations interpret any information exchange as subject to OFAC regulation, and you and Let's Encrypt have good company in this interpretation, but I think it's unnecessarily ceding ground.

GitHub was recently granted a license from OFAC to allow there services to be used from Iran. You can read about it here: https://github.com/github/site-policy/blob/main/Policies/oth...

And here: https://github.blog/news-insights/policy-news-and-insights/a...

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#366
post #144

Earlier quoted context omitted.

Seems in all thing tech at the moment the US legal system is accelearting a great split and erectinga digital iron curtain, from AI models to the more mundane like TLS certs. Its been standard for a while for many Linux distros based in the US to toe the party line - like RedHat having notices pretty similar to this one by LE. Seems any meaningful Open Projects will have to choose what path they want to take, be like…

The RISC-V move was laughable. It’s still US tech, developed largely with DARPA funds.

Woah, I had no idea about DARPA and RISC-V. I wonder why they care about RISC-V so much? This is the best explanation that I can find:

    > Open source standards provide great benefits to U.S. taxpayers in reducing the cost of advanced military system development, and also increases security by allowing the government to build their own trusted implementations at low cost.
You can read more about it here: https://riscv.org/about/ -> See section "DARPA Influence"

About their move to Switzerland, they say:

    > RISC-V International has not incorporated in Switzerland based on any one country, company, government, or event. This move is reflective of community concern and managing strategic risk for our community investing in RISC-V for the next 50+ years.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#367
post #261

Earlier quoted context omitted.

That's a fair opinion to have. But the US isn't really unique in applying their laws extraterritorially. See GDPR, Universal jurisdiction laws, China's National Security Law, etc... Every jurisdiction with sizable power does it. Some of these are even more extraterritorial in scope than US sanctions are.

> GDPR Only applies to EU citizens' personal data, so while technically extraterritorial it doesn't feel like overreach in the same way. > Universal jurisdiction laws Rightly controversial when applied beyond things that are internationally agreed to be crimes against humanity, like torture or genocide. > China's National Security Law A perfect example of the kind of thing that the US used to define itself in opposit…

>Only applies to EU citizens' personal data

That's not true.

The GDPR applies to the personal data of anyone physically in the EU, to the extent that the data are processed[0] while they are in the EU.

It also applies to the personal data of anybody anywhere in the world if the data controllers are based in the EU.

The reason why it's different to US sanctions/export controls is that the GDPR doesn't say you can't work with certain people in certain circumstances because of who they are in order to punish those people for whatever reason. It's fundamentally to protect the data subjects.

[0] which includes collection of said data

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#368
post #239

Earlier quoted context omitted.

Let's Encrypt continues to be available to almost every vulnerable population in the world, including those that need it most. I say almost as I'm hesitant to speak in absolutes regarding a topic as complex as this. Most of our sanctions-related blocks apply only to the governments of certain sanctioned countries, not their general population. This subscriber agreement update was intended to better reflect our legal…

You issued a certificate for North Korea's email infrastructure as recently as six days ago : https://crt.sh/?id=26878583197 (06/04/2026 smtp.star-co.net.kp) https://crt.sh/?id=20256841119 (08/11/2025 *.star.net.kp) Star Joint Venture is the manager of the .kp TLD and one of DPRK's two email providers (the other is silibank.net.kp) [1], used as the official email for various government bodies ex. ipa817@star-co.net.k…

This is incredible. How did you find these certs?

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#370

Earlier quoted context omitted.

Yes actually you still could've. But it would require a pass through the IETF to stabdaddize a DNS record type, and that would delay Netscape's release.

Any DNS-based solution needs something like DNSSEC to work. I believe DNSSEC didn't exist yet when HTTPS was being developed and even if it did, it wasn't anywhere near ubiquitous enough. Is it even these days?

That's kind of like saying that any CA-based solution needs something like a root program. Sure, but that would just be part of creating a DANE-like solution. Both the current CA solution and DANE or another hypothetical DNS-based solution are fundamentally similar on a technical level: hierarchical delegation of authorization backed by public key crypto. The main difference is where on the delegation chain you limit authority for further delegation and who controls the root. The DNS-based approach has the crypto system reflect real ownership while the CA-based approach has browsers makers at the top and whoever pays enough money and hasn't publicly fucked up yet at the middle with delegated authority to sign literally everything.
Post reply on HN