4 ms·
Shouldn't we be worried about the internet being centralized to depend on LetsEncrypt? Imagine the shit show if the US government stopped LetsEncrypt from issui
by o_m 1y ago
Shouldn't we be worried about the internet being centralized to depend on LetsEncrypt? Imagine the shit show if the US government stopped LetsEncrypt from issuing certificates to every country outside of the US.
- toomuchtodo 1y agoHow much would Lets Encrypt need to deploy an entirely separate legal and technical stack in Europe? Durable distributed foundational infrastructure is important.
- matharmin 1y agoLuckily there are still other options out there. ZeroSSL is one I quite like: Free ACME-based certificates just like LetsEncrypt, without the rate limits, and does have paid plans if you need support. It also has better legacy client compatibility than LetsEncrypt as far as I know.
- mattashii 1y agoI hope that ZeroSSL has improved their policies and procedures in the past years so they're more safe and robust. Four and a half years ago, there were some significant oversights in certificate lifecycle management, TOS, and handling of key material, which needed external parties to notify them of those issues before they fixed them. To me that was an indication of limited awareness of WebPKI and security principles. See e.g. https://bugzilla.mozilla.org/show_bug.cgi?id=1698936 https://bugzilla.mozilla.org/show_bug.cgi?id=1698936, https://bugzilla.mozilla.org/show_bug.cgi?id=1699756 https://bugzilla.mozilla.org/show_bug.cgi?id=1699756
- michaelt 1y agoI'm kinda worried, personally. The CA/Browser Forum gets to set requirements for anyone who wants to run a website. If they decide website operators should renew their certificates monthly, website operators don't much choice in the matter. I worry that some day members of the forum will realise how much power that actually is. If there's a trade embargo on Country A, or a genocide going on in Country B, that perhaps 24-month certificates aren't the only sin they should use their power to correct.
- makkes 1y agoFrom what I can see on the CA/Browser Forum's website (https://cabforum.org/about/membership/members/ https://cabforum.org/about/membership/members/), there is enough diversity in the forum to represent the Web community as a whole. Trade embargoes issued by a single country would likely not be represented by enough CA/B members to be pushed through the Forum. I personally sleep much better knowing that e.g. all major browser vendors cooperate on the CA/B (and elsewhere, e.g. the IETF, W3C, ECMA) instead of the biggest one dictating the rules (which, to be fair, happens to a certain degree, e.g. with Chrome leading the way for certain technologies).
- michaelt 1y ago> From what I can see on the CA/Browser Forum's website [...], there is enough diversity in the forum to represent the Web community as a whole. While I agree there are an astonishing number of CAs listed, it seems to me there's no representation of website operators, or website users.
- nubinetwork 1y agoEveryone said that about cloudflare, and nothing has changed on that front.
- Bad_CRC 1y agoI was just trying buypass for exactly that reason when I found out that they are ending it :(
- rvnx 1y agoThey will not stop Letsencrypt abroad, it is clearly an asset for the US gov, the same way that Cloudflare is a worldwide MITM, it would be absurd to shut it down. If you are a letsencrypt user, then it is nearly impossible to see (even with CT logs) that there was a malicious interception. From a website operator it looks like a pretty standard renewal as Letsencrypt has a short validity duration anyway. Add on top of that in the US they have access to easy and non-BGP entry points to reroute traffic (Google DNS, Cloudflare DNS). They can intercept in practice all Cloudflare and all Letsencrypt sites (except the Letsencrypt they also need cooperation of a friendly DNS and have a very theoretical little risk to get caught in CT logs). Big sites like Meta or Google or Amazon already have to cooperate and intercept internally so in practice almost all western internet is interceptable rather easily. There is zero world where US gov would want to stop that. The tech guys working for the NSA are from being idiots, and it would be insulting to even consider that. They would fight to protect Letsencrypt
- actionfromafar 1y agoGood thing they never do any absurd things nowadays.
- hdgvhicv 1y ago> They will not stop Letsencrypt abroad, it is clearly an asset for the US gov, the same way that Cloudflare is a worldwide MITM, it would be absurd to shut it down. That’s does not mean they wouldn’t shut it down.
- ayende 1y agoSure you can, you know what your public key _should_ look like
- crtasm 1y agoExcatly. There must be tools to automate checking newly issued certificates against your own copy, could anyone recommend a self-hosted one?
- 1y ago
- darkwater 1y agoI think we should, as we should every time there is one single big player. Obviously the ACME protocol is open but currently there are just 5 "free" providers using it (3 from the US and 2 from EU) and nothing blocks anyone to have a US adversary implementing a Letsencrypt-like issuer. Although I have some doubts on whether that CA would get global trust in every browser. Is the Browser Forum following US sanctions? Can a CA managed by the Cuban or Iranian government enter the CA list trusted by Chrome, Safari or Firefox? I'm genuinely asking.