Live data from Hacker News

Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

letsencrypt.org

391–400 of 404 posts

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#391
post #378

Earlier quoted context omitted.

Unfortunately the CA/B Forum has high requirements for constrained subordinate CA certificates[1], which to me sounds a lot like regulatory capture. [1] https://community.letsencrypt.org/t/sub-ca-with-wildcard-cer...

It's not that high of a requirement. The sub-CA is allowed to self audit. But the original CA does have to check a percentage of certificates issued by the sub-CA. So that's not going to be free. But it might be possible to do it if you were big enough to pay for it. I have dreams of having my private CA also signed off on by webpki so apps and browsers could use the same servers without having to include webpki in m…

I also started going down this rabbit hole when I wanted my homelab to just work in any device, and for advanced use cases Let's Encrypt isn't enough. I tried long and hard to get a sub-CA certificate, but apparently that's in the realm of «if you need to ask, you can't afford it».

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#392

Earlier quoted context omitted.

" Try to prevent"? What does that mean?

It means they prevent, unless you perform several undocumented arcane rituals.

In this case, you have to compile the OS yourself and patch the trusted certificate store.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#393
post #177

Earlier quoted context omitted.

Let's encrypt is not some code or even a company that you can split into different branches. Their existence is one based on trust relations that let's encrypt has with browsers and operative systems. It is in one part similar to both domain names and IP address space, in that the technical aspects of creating alternative roots is almost trivial in comparison to getting the trust that is required for an alternative r…

Russia already has its own root CA, the issue is that state-owned root CAs are by definition not safe from MITM attacks by the same government.

It is a lunacy, complete delusion to think that privately owned (by oligarchy) root CA that trusted by every web browser and OS on the planet is somehow superiorly safer from the point of state actor attack than those explicitly state owned root CA. You must be livin in fairyland.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#394
It was a great hack, but it was always just that: a hack. We all always knew that the "certificate authority"-hierarchy is broken and can easily be abused by the ones in power. I appreciate everything that the let's encrypt peeps have done for the world, but the cert authority system really needs an overhaul.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#395

Couldn't LE have a branch in Europe or anywhere outside the USA and its minions? Because they're betraying their own goals, as stated in their About page: “It is a service run for the public’s benefit. [...] Anyone who owns a domain name can use Let’s Encrypt to obtain a trusted certificate at zero cost. [...] Let’s Encrypt is a joint effort to benefit the community, beyond the control of any one organization.” Now t…

They could, but if the branch didn’t follow these laws, the main US branch would still be liable.

It depends on the legal structure.

If they set up a subsidiary in Europe, they could be held liable for actions of European subsidiary.

If an independent org is stood up in Europe, with European directors, staff and funding, legally independent of US org, and the US org just provides advice/assistance to Europe org without ability to control it-legal liability for US org for Europe org’s decisions is less likely. Of course, ask a lawyer-but if you openly say “we are doing this to work around US sanctions” you could still be liable; if you say “this has nothing to do with sanctions this is about resilience of global digital infrastructure and European digital sovereignty” then under what legal theory is the US org liable?

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#396
post #378

Earlier quoted context omitted.

It's not that high of a requirement. The sub-CA is allowed to self audit. But the original CA does have to check a percentage of certificates issued by the sub-CA. So that's not going to be free. But it might be possible to do it if you were big enough to pay for it. I have dreams of having my private CA also signed off on by webpki so apps and browsers could use the same servers without having to include webpki in m…

I also started going down this rabbit hole when I wanted my homelab to just work in any device, and for advanced use cases Let's Encrypt isn't enough. I tried long and hard to get a sub-CA certificate, but apparently that's in the realm of «if you need to ask, you can't afford it».

Yeah, not gonna happen for a homelab. Need to be a big company so that it might be worth spending the money.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#397

Earlier quoted context omitted.

This is incredible. How did you find these certs?

I only noticed the star net one (not sure if it’s even in use) when writing this. I noticed the Pyongyang Zoo (which shares an IP with the Architects Society—one on 443 and one on 80 lmao) first, just from flipping through their very small IP space on Shodan. You can see them all on crt.sh, because LE has to upload them to a CT log for browsers to trust them. (That’s how most of those subdomain finder websites work t…

Thank you. Had to go looking for these magazines.

http://www.koreanarchitecture.gov.kp/index.php?kt=TWFnYXppbm...

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#398

Iran is blocking internet for months, US ...bans creation of secure connections - that'll show 'em! Russian quasi-government structures are spending quadrillion of rubles on a TSPU (censorship system) to spy on Russian residents, US ...helps them by making snooping on what is currently encrypted traffic possible by banning accessible encryption!

You could look at it equally as the USA saving those citizens because if the authoritarian discover they are using LE they could suffer imprisonment

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#399
post #239

Let's Encrypt’s mission is to create a more secure and privacy-respecting web, except for people residing in countries with the most need for a more secure and privacy-respecting web. Sure, that's great. That said, pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries. I'm sure some of y'all are old enough to remember when web browsers came in "international fr…

Let's Encrypt continues to be available to almost every vulnerable population in the world, including those that need it most. I say almost as I'm hesitant to speak in absolutes regarding a topic as complex as this. Most of our sanctions-related blocks apply only to the governments of certain sanctioned countries, not their general population. This subscriber agreement update was intended to better reflect our legal…

> Let's Encrypt continues to be available to almost every vulnerable population in the world, including those that need it most. I say almost as I'm hesitant to speak in absolutes regarding a topic as complex as this.

> Most of our sanctions-related blocks apply only to the governments of certain sanctioned countries, not their general population.

It doesn't work that way.

Blocking governments from getting certs doesn't hurt them in the slightest. The government can just create their own pki.

But it hurts the general population instead. People do not live in vacuum, they still need to access government sites. And thus people are forced to install root certificates of questionable trust.

When Let's Encrypt blocks government entities, it instead puts respective vulnerable population in even less secure environment.

Although, given the current events, I am not sure Let's Encrypt continues to deserve the trust it had.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#400
post #328

Earlier quoted context omitted.

The problem is that finding a root source of trust aren't easy this days. LE was neutral, now nobody is. Russian government issued their new root certificate years ago. Nobody trusted it enough to request a certificate from them or install it on their computers. Including almost all of the russian residents. If Let's Encrypt enforces the rules, as written in pdf, a lot of people would lose a choice. Frankly, even pub…

> Nobody trusted it Let's be real here… 99.99999999999999% of internet users have no idea what root CAs even are. It's the browser vendor mafia that makes the decision.

Force the people and then give them simple instructions to install certificate. And it's done.

Forcing is as easy, as blocking access to important services behind the certificate wall.

Post reply on HN