Live data from Hacker News

Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

letsencrypt.org

91–100 of 404 posts

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#92
post #71

Earlier quoted context omitted.

love thought-terminating cliches. really helps keep from actually thinking ever.

Your comment reads like a thought-terminating cliché. If Russia occupied your city, killed your family and friends and left you homeless, you might reconsider giving freedom to those who take it away from others. Unfortunately, sanctions are often very easy to evade.

This is a reasonable point, if "enemies of freedom" and "enemies of America" are synonymous...

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#93
post #71

Earlier quoted context omitted.

love thought-terminating cliches. really helps keep from actually thinking ever.

Your comment reads like a thought-terminating cliché. If Russia occupied your city, killed your family and friends and left you homeless, you might reconsider giving freedom to those who take it away from others. Unfortunately, sanctions are often very easy to evade.

[dead]

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#94
To be put in perspective with their push for very short live certificates, like 7 days, with the argument that anyone can easily get certificate from at any time.

But in fact, little by little you have all the stacks needed to be able to isolate some entities from internet at the us request in a very short time

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#95

Earlier quoted context omitted.

Your comment reads like a thought-terminating cliché. If Russia occupied your city, killed your family and friends and left you homeless, you might reconsider giving freedom to those who take it away from others. Unfortunately, sanctions are often very easy to evade.

Now imagine the USA did that to the city you live in...

it can't happen, they only attack civilians in countries that have weapons of mass destruction or have a evil economic system of socialized healthcare and labor market

They also don't like states that threaten business by turning workers into a commodity that you have to compensate each month ; Spain sunk the Maine ; and they had manifest destiny given from God to get rid of natives

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#98
post #58

Earlier quoted context omitted.

Pretty much any big government has a CA they can exert direct control over whenever needed.

Maybe, but then can only do it once. Then they get caught, and their CA is distrusted. See Diginotar [0] for example. And things only gotten better since - we now have CT logs, and browsers require them, so any mis-issuance can be detected automatically, by any interested third party. If we go to DANE, we lose this all. "Oops, our CT uploader process failed, we will fix Real Soon(tm) we promise" - and what are browse…

Side note: “DigiNotar BV was a Dutch certificate authority from 1998 to 2011. It was acquired in January 2011 by VASCO and subsequently declared bankrupt in September of the same year” [1].

I didn’t realize the slapped their face on the pavement right after being acquired.

[1] https://en.wikipedia.org/wiki/DigiNotar

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#99
post #50

Earlier quoted context omitted.

Jumping in here since we’ve been seeing more mentions of ZeroSSL lately, likely related to the recent CA/B Forum discussions around 1‑year certificates and ACME automation. - We’re based in Austria (ZeroSSL GmbH). The company was acquired by HID in 2024, which is part of Assa Abloy (Sweden). - We’re not positioning ourselves as a purely EU-based CA substitute, and we generally don’t market it that way. - For DV certs…

Any plans on becoming an independent CA? Would certificates issued in your name also risk being affected by US sanctions trough sentigo?

If they do business in the US they will be expected to comply with US law - this includes their stock being traded on US stock exchanges.

If they don’t have any business in the US and any financial ties to the US they won’t be subject to the sanctions. But I believe it will create issues if they want to enter the US market.

Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

#100
post #4

Has anyone got any experience with Zero SSL? https://zerossl.com/ It seems like a good EU alternative.

I use them in some cases to avoid the rate limits on LetsEncrypt, and they have better support for some older platforms (like ancient Android versions), and I'm pretty happy so far. I have a paid account to support them, but it's not a requirement for ACME certs. It works without issue with Kubernetes Certbot, and seamless to switch between ZeroSSL and LetsEncrypt.

I can't comment on the EU part though - not that relevant in my case.

Post reply on HN