15 ms·
Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
- Panzerschrek 4mo agoDoes it mean that russian/iranian web-sites using letsencrypt stop working and need to change their certificate provider?
- leosarev 4mo agoI hope not. We don't have any alternatives yet.
- CaliforniaKarl 4mo agohttps://www.actalis.com/activate-free-plan https://www.actalis.com/activate-free-plan maybe?
- leosarev 4mo agoThis page is blocked for me from server's end. I'll try later using VPN, but looks like it won't work :-)
- altairprime 4mo agoDepends on whether LE is compelled to terminate service to BGP AS numbers hosted in U.S.-sanctioned countries, and whether LE continues operating out of the U.S..
- trumpdong 4mo agoIt works like this. The US gov sends LE a nastygram saying they must terminate service to sanctioned entities. LE either does that or several people go to jail. The USgov doesn't care how it happens, as long as they can't find any evidence that any sanctioned entities are LE customers.
- piskov 4mo agoThey already revoced certificates for some russian sites
- pratyahava 4mo agoany details on that? links to people reporting it?
- piskov 4mo agomax.ru — Russian messenger https://community.letsencrypt.org/t/why-issue-certificate-for-max-ru-forbidden-by-policy/248143 https://community.letsencrypt.org/t/why-issue-certificate-fo...
- account42 4mo agoDepending on how you are supposed to read "You agree to use Let’s Encrypt Certificates and any services provided by or on behalf of ISRG in compliance with applicable U.S. export control and sanctions laws and regulations." it could mean that you are not even allowed to use LE certificate to provide services to sanctioned entities as a random non-US company/person.
- aussieguy1234 4mo agoDictators love it when their citizens can't use encryption. It makes them much easier to control and monitor.
- ysmoradi 4mo agoPLEASE DON'T DO THIS )":
- piskov 4mo ago> You are not a person or entity that is: (a) located in, organized under the laws of, or ordinarily resident in any country or territory that is the target of comprehensive U.S. sanctions; (b) a prohibited or restricted party under U.S. or other applicable sanctions and export control laws and regulations; or (c) owned or controlled by or acting on behalf of anyone described in (a) or (b). You agree to use Let’s Encrypt Certificates and any services provided by or on behalf of ISRG in compliance with applicable U.S. export control and sanctions laws and regulations
- theamk 4mo agoMakes sense, they are US company. I am surprised it took them that long.
- rwmj 4mo ago"US company must obey US law" doesn't make for a very interesting headline.
- ceeam 4mo ago"The world should stop trusting the US companies" OTOH...
- cyanydeez 4mo agomore optimistic would be "World should decentralize America's trust"
- ohmg 4mo agoThe headline is more « US law is batshit and extends well beyond its borders with real world consequences »
- ezbie 4mo agoExactly. Ever since I was a kid I never understood how the US has jurisdiction way beyond their borders. Then I graduated in International Relations and understood that the hole is much deeper than that. Now it's pretty obvious with all the shit that trump has been doing, but back then me and much of the people I know were oblivious to what US power really means.
- pavon 4mo agoThis is not an example of that. It is perfectly within US jurisdiction to prevent US companies from doing business with sanctioned countries. That is the point of a sanction, and US is in good company in choosing to use sanctions as a diplomatic tool. It is more of an example of how the internet/software industry is too consolidated to the US, and thus other countries are too dependent on the US in those areas. If the internet infrastructure was well distributed, then people in sanction countries could simply get certificates issued by a different CA, and in some cases they can. However, this is complicated by the fact that the list of trusted CAs is dominated by US organizations (Google, Mozilla, Apple, Microsoft). If you want to reach western audience you must use certs from a CA approved by them.
- 42droids 4mo agoHas anyone got any experience with Zero SSL? https://zerossl.com/ https://zerossl.com/ It seems like a good EU alternative.
- 47282847 4mo agoEU? There’s almost zero information on the company, no privacy policy? The only place I found any mention is the footer, “HID Global Corporation, part of ASSA ABLOY”. Assa Abloy seems Swedish but HID Global is a US company as far as a quick search goes. But without a proper company info page and privacy policy I wouldn’t consider it anywhere near a “good alternative” regardless.
- slau 4mo agoHID was originally American and Scottish, but became fully American in 1994. HID was acquired by Assa Abloy in 2000. No idea whether that means we now consider it Swedish. ZeroSSL used to be Austrian until their acquisition in 2024. I used to work for a company that got acquired by HID. It looks like HID has retained their original offices in some form.
- nomadwastaken 4mo agoThe privacy policy is under legal in the footer, exactly where I'd expect it to be honest. It also gives the company registration: > 1.1. We, ZeroSSL GmbH, FN 443956b (the “Company“) and below that the company address (registered in Austria). Don't get me wrong, I agree that there is some lack of "who actually runs/controls this", especially on the about page where I expect such things to be. At the very least it's not as transparent as I'd wish from a CA. E.g their Certificate Agreement is from Sectigo, so are they involved? No mention anywhere else from what I can see.
- 47282847 4mo agoI don’t see “legal” in the footer on mobile. Or any other link. Or a link to an About page in the main nav. There’s nothing.
- m2f2 4mo agoIs this a canary? What's gonna happen if I were to begin or continue using one letsencrypt certificate from ... Greenland? Cuba? The EU? Has letsencrypt been served with a subpoena?
- rafram 4mo agoNeither Greenland nor the EU has been sanctioned by the US.
- nitwit005 4mo agoThey haven't been sanctioned, yet, but we live in a time where that's a real possibility.
- malfist 4mo agoSo far
- tempfile 4mo agoIt is not exactly an outlandish suggestion that this may happen.
- _ache_ 4mo agoYet.
- deleted 4mo ago[deleted]
- piskov 4mo agoHave you heard about the judge from international court or whatever it is called? https://www.france24.com/en/americas/20250820-us-hits-icc-with-more-sanctions-targets-french-judge-involved-in-netanyahu-arrest-warrant https://www.france24.com/en/americas/20250820-us-hits-icc-wi...
- rafram 4mo agoAre you saying the ICC is the EU? Or that it's Greenland?
- RyeCombinator 4mo agoActalis https://actalis.com/ https://actalis.com/ is a good EU alternative.
- gapan 4mo agoNo it isn't. Not unless it's free. This is the main reason letsencrypt is so popular.
- crote 4mo agoThey do have a free plan with unlimited ACME DV certs, though! Not marketed very well and no wildcard certs, but it does exist.
- RyeCombinator 4mo agoThere is a free offering.
- DoctorOetker 4mo ago> active eavesdropping (e.g., monster-in-the-middle attacks) is this standard MitM, or is it some crucially distinct variation?
- thephyber 4mo agoMan in the Middle Wiki: > Also known as a monster-in-the-middle,[1][2] machine-in-the-middle,[3] meddler-in-the-middle,[4] manipulator-in-the-middle,[5][6] person-in-the-middle[7] (PITM), or adversary-in-the-middle[8] (AITM) attack.
- walletdrainer 4mo agoThose sources feel more than slightly contrived.
- walletdrainer 4mo ago[flagged]
- cassianoleal 4mo agoI kinda like this framing. It effectively classifies companies such as Zscaler and CloudFlare as monsters.
- walletdrainer 4mo agoIt's particularly funny because "monster-in-the-middle" appears to be a deliberately quirky marketing term invented by cloudflare.
- wofo 4mo agoFun fact: some older articles were originally written using the term man-in-the-middle, but at some point were updated... except that the diagrams still use man-in-the-middle because search-and-replace doesn't work on images.
- Towaway69 4mo agoSanctioned has a double meaning here[1]: > 2. officially or formally ratified or confirmed. > 3. penalized, especially by way of discipline or to force compliance with legal obligations. So who can use lets encrypt? Those that are penalised or those that are confirmed. [1] https://www.dictionary.com/browse/sanctioned https://www.dictionary.com/browse/sanctioned
- thephyber 4mo agoIf you click the link… > [You certify to LetsEncrypt that] … > You are not a person or entity that is: (a) located in, organized under the laws of, or ordinarily resident in any country or territory that is the target of comprehensive U.S. sanctions; (b) a prohibited or restricted party under U.S. or other applicable sanctions and export control laws and regulations; or (c) owned or controlled by or acting on behalf of anyone described in (a) or (b). You agree to use Let’s Encrypt Certificates and any services provided by or on behalf of ISRG in compliance with applicable U.S. export control and sanctions laws and regulations.
- gossamer 4mo agoIt took me a minute to understand the original post because the verb sanction means both itself and basically the opposite of itself. It would be better to say "any territory that the US has levied sanctions against". I thought LetsEncrypt had banned its usage in the US! The word for words like sanction is contronym.
- idoubtit 4mo agoCouldn't LE have a branch in Europe or anywhere outside the USA and its minions? Because they're betraying their own goals, as stated in their About page: “It is a service run for the public’s benefit. [...] Anyone who owns a domain name can use Let’s Encrypt to obtain a trusted certificate at zero cost. [...] Let’s Encrypt is a joint effort to benefit the community, beyond the control of any one organization.” Now they own they are under the control of a political organization. Here is the paragraph Let's Encrypt added to their Subscription Agreement on 2026-06-04: > You are not a person or entity that is: > (a) located in, organized under the laws of, or ordinarily resident in any country or territory that is the target of comprehensive U.S. sanctions; > (b) a prohibited or restricted party under U.S. or other applicable sanctions and export control laws and regulations; > or (c) owned or controlled by or acting on behalf of anyone described in (a) or (b). > You agree to use Let’s Encrypt Certificates and any services provided by or on behalf of ISRG in compliance with applicable U.S. export control and sanctions laws and regulations.
- cassianoleal 4mo agoThey could, but if the branch didn’t follow these laws, the main US branch would still be liable.
- cromka 4mo agoIt's about time SOME entities start moving from US entirely.
- mikeyouse 4mo agoRISC-V Foundation did.. though they go out of their way to talk about it in terms that try not to piss anyone off.. > "Across 2018-2019, the RISC-V community has reflected on the geo-political landscape and we have heard concerns from around the world that investment in RISC-V must come with IP access continuity to ensure a long-term strategic investment. We first mentioned our intentions to move at the December 2018 summit. Incorporation in Switzerland has the effect of calming concerns of political disruption to the open collaboration model. RISC-V International does not maintain any commercial interest in products or services as a non-profit, membership organization. There have not been any export restrictions on RISC-V in the US and we have complied with all US laws. The move does not circumvent any existing restrictions, but rather alleviates uncertainty going forward. > In March 2020, the RISC-V International Association was incorporated in Switzerland. Along with this, we shifted to a new, more inclusive membership structure. Members of RISC-V International have access to and participate in the development of the RISC-V ISA specification and extensions as well as related hardware and software. RISC-V has a Board of Directors composed of member representatives as well as a Technical Committee of work group leaders." > RISC-V International has not incorporated in Switzerland based on any one country, company, government, or event. This move is reflective of community concern and managing strategic risk for our community investing in RISC-V for the next 50+ years. > The IP contributed and produced by RISC-V International is held under industry and global standard licenses that are already open to leverage by any company regardless of jurisdiction. This licensing is a common open source approach to foster collaboration that is not tied to any geographic regulation. IP in the public domain has not been subject to export control. https://riscv.org/about/ https://riscv.org/about/
- pxeger1 4mo agoHow are they going to enforce this?
- nickf 4mo agoI would imagine, as a CA that issues only DV certs, they'd disallow issuance to various ccTLDs, and perhaps stop newAccount registrations with email addresses at those ccTLDs. That's about as much as they could do - IP-blocking by region is ineffective and crude at best.
- morpheuskafka 4mo agoThe question is, will that be enough? If OFAC can demonstrate that even with such restrictions, sanctioned entities are frequently obtaining certificates, they may be forced to require account creation or something else as a means of limiting that. They also likely would have to implement some kind of domain name screening, just like banks have to block transfers that mention "Havana" or "Tehran". They are currently not doing anything, even ccTLD blocks. They have issued certificates for .kp domains this month and in August of last year.
- Igrom 4mo agoIt seems that, as soon as you transact with a sanctioned entity, you are globally in breach of the agreement and risking the revocation of all your certificates — also the ones for non-sanctioned countries. Front matter: - it is called a "Subscriber Agreement" and not anything that suggests that its scope is a single certificate - it's a "contract [...] regarding Your [...] rights and duties relating to [...] Certificates" - plural 2.1 "Term": - "[the agreement] will remain in force during the entire period during which *any* of Your Certificates are valid" - plural 3.1 "Warranties": - "[by] requesting, accepting, or using *a* Let’s Encrypt Certificate" - plural
- trumpdong 4mo agoI said hi to an Iranian today. Lets see if LE revokes my website.
- diimdeep 4mo agothe reach is by rough estimates ~2.5–6 million websites globally, 2–5 million of those in Russia and 0.3-1 million in Iran Whatever USofA, it's not hard to have their own cosmodrome and certificates. Tangential, in 2026 website certificates feel like nothing, disposable automation artifact, toxic max-security[1], vehicle for those who rent seek, fingerprint. [1] https://tom7.org/httpv/httpv.pdf https://tom7.org/httpv/httpv.pdf
- ale42 4mo agoTime for a non-US equivalent of Let's Encrypt?
- trumpdong 4mo agoHow will you get Mozilla and Google to trust it? Especially since sanctions are transitive. Mozilla and Google, being US companies, are actually not allowed to trust any entity whose purpose is to work around sanctions. Their members could go to jail for that.
- axiologist 4mo agoThis somehow confirms my gut feeling that digital certificates are mainly a means to enforce exclusion on behalf of the certificate authority ownership. It is a tool to prevent people from taking full ownership and control of whatever is affected by digital certificates, be it software, firmware, hardware, or as in this case SSL/TLS. That's digital tyranny in disguise.
- MarleTangible 4mo agoI always saw it as a trust-chain and think that anyone is welcomed to create a root certificate and distribute it to whomever trusts them. Most simple services may not need TLS, but with the ISPs eavesdropping on our communication, a form of secure communication is required and the currently best solution we have requires a trust-chain to be built.
- Parodper 4mo agoWe could, and should, switch to DANE. Or else, switch to how X.509 was supposed to be used, with each country running a CA for their nationals.
- theamk 4mo agoI trust governments much less that a conglomerate of competing corporations. With all the problems with Web PKI, at least the bad actors are getting distrusted, and this provides a very strong enforcement on the rest. And Certificate Transparency makes sure the mis-issuance would be caught. It is not perfect by any means, but things are getting better. With DANE (or other country-issued certificates), every government will absolutely double-issue certificates to police, secret service and friends of goverment, and no one will have any recourse. (In the past I'd say that only countries like Russia would do it.. but with today's climate, I am sure both US and many European countries will do that too)
- account42 4mo agoPretty much any big government has a CA they can exert direct control over whenever needed.
- phoe-krk 4mo agoAnd now imagine that one of the Trump tantrums contains an announcement of sanctions against the European Union.
- marcosdumay 4mo agoHe already announced sanctions against Spain. And took them back when Germany announced that sanctions against one EU country meant sanctions against them all.
- karteum 4mo agoCan anyone explain me what went wrong with http://www.cacert.org/ http://www.cacert.org/ and why they are not supported by any major browser ?
- em-bee 4mo agothe wikipedia page has links to projects that removed CAcert where reasons are stated. the main one being that CAcert didn't complete a security audit or because they were not yet accepted by mozilla (because of the lack of an audit, but also because CAcert actually withdrew the request to be included). one group removed it because CAcert has a strict root redistribtion license that they can't follow. LWN has a good writeup on the audit situation as of 2014: https://lwn.net/Articles/590879/ https://lwn.net/Articles/590879/
- ezbie 4mo agoWhat in the actual fuck?
- cynicalsecurity 4mo agoThis actually makes sense. No freedom for the enemies of freedom.
- mswphd 4mo agolove thought-terminating cliches. really helps keep from actually thinking ever.
- cynicalsecurity 4mo agoYour comment reads like a thought-terminating cliché. If Russia occupied your city, killed your family and friends and left you homeless, you might reconsider giving freedom to those who take it away from others. Unfortunately, sanctions are often very easy to evade.
- contagiousflow 4mo agoNow imagine the USA did that to the city you live in...
- hinata08 4mo agoit can't happen, they only attack civilians in countries that have weapons of mass destruction or have a evil economic system of socialized healthcare and labor market They also don't like states that threaten business by turning workers into a commodity that you have to compensate each month ; Spain sunk the Maine ; and they had manifest destiny given from God to get rid of natives
- Shish2k 4mo agoThis is a reasonable point, if "enemies of freedom" and "enemies of America" are synonymous...
- greyface- 4mo ago[dead]
- 4mo ago
- jalospinoso 4mo agoThe uninteresting version of this is “US entity follows US law.” The interesting version is that Web PKI is not just cryptographic infrastructure. It is also a policy distribution system. A browser trust store, a CA, a subscriber agreement, revocation rules, export controls, and sanctions law all end up in the request path of "can this site speak HTTPS to normal users?" That does not make Let’s Encrypt uniquely bad. Any CA has some jurisdiction, owners, contracts, root-program obligations, abuse process, and legal exposure. Moving the CA changes the governance surface; it does not remove governance. But it does mean "just use Let’s Encrypt" is not a neutral answer when protocols, browsers, APIs, app stores, or regulators effectively require TLS. The operational dependency is not only ACME uptime and certificate issuance. It is also jurisdictional continuity. The hard product question is what failure mode we want: 1. Web PKI: power concentrates in CAs, browsers, and root programs. 2. DANE/DNSSEC: power shifts toward DNS operators, registries, registrars, and governments. 3. Self-signed / TOFU / pinning: power shifts toward application-specific trust and worse UX. 4. Multiple CAs: better resilience, but still bounded by browser trust stores and legal chokepoints. There is no apolitical trust system here. There are only different control planes with different failure modes. The practical ask from Let’s Encrypt should be clarity: issuance vs renewal vs revocation, existing certs vs future certs, domain location vs subscriber location, hosting location vs user location, and how they interpret “use” of a certificate. Without that, operators are left guessing whether this is a narrow compliance clause or a broad infrastructure-risk event.
- psy0p 4mo ago[dead]
- Insimwytim 4mo agoIran is blocking internet for months, US ...bans creation of secure connections - that'll show 'em! Russian quasi-government structures are spending quadrillion of rubles on a TSPU (censorship system) to spy on Russian residents, US ...helps them by making snooping on what is currently encrypted traffic possible by banning accessible encryption!
- gnerd00 4mo agowait until you find out about Facebook!
- jaas 4mo agoLet's Encrypt certificates continue to be available in both Iran and Russia, just not for the Iranian and Russian governments. The terms of service update to clarify what we have always done, comply with relevant law, has not changed the situation for either country.
- joshuaissac 4mo ago> Let's Encrypt certificates continue to be available in both Iran and Russia, just not for the Iranian and Russian governments. According to https://news.ycombinator.com/item?id=48457280 https://news.ycombinator.com/item?id=48457280 it affects all people ordinarily resident in those territories, not just their governments: > You are not a person or entity that is: > (a) located in, organized under the laws of, or ordinarily resident in any country or territory that is the target of comprehensive U.S. sanctions; > [other 'or' conditions]
- lioeters 4mo agoI wonder what "ordinarily resident" means legally. Like has a permanent address there, even if they don't live there physically..?
- deleted 4mo ago[deleted]
- ComputerGuru 4mo agoThis is bullshit on par with the Chinese firewall, meant to effectively prevent the (entire!) western world from information by parties deemed persona non-grata. SSL certificates are supposed to be about security, not geopolitics. I'm pretty sure a LE server hitting an Iranian or North Korean endpoint and validating a crypto challenge does not break any OFAC or EAR rules, and no money changes hands. And if a non-US entity wants to do it, the US would just sanction them. Microsoft and Mozilla are certainly not going to include a North Korean or Russian state CA in the root trusted certs (and if they did, the US government could just threaten them with sanctions, too). Hard not to say "we warned you" about making self-signed certs completely unusable in favor of a very centralized approach.
- wnevets 4mo agoMaybe consolidating ~60% of the web's certificates on to a single provider was a mistake.
- patmorgan23 4mo agoWell good thing everyone using the provider is using an open protocol and it's stupid easy to switch
- wnevets 4mo agoWhich free CA should I use instead of lets encrypt that has same browser support?
- gruez 4mo agoZeroSSL / BuyPass
- ygjb 4mo agoBuypass no longer issues TLS certs since last year.
- ygjb 4mo agoActalis, based in Italy offers a free tier, with ACME https://www.actalis.com/subscription https://www.actalis.com/subscription ZeroSSL from Austria also has a limited free tier. https://zerossl.com/pricing/ https://zerossl.com/pricing/ I mean really, if you use lets encrypt for anything that runs in a production environment, the responsible thing to do is build a fallback to switch to another provider in case LE has a bad day (or hits a brick wall and needs to say, enforce export restrictions).
- daneel_w 4mo agoWorth noting that Actalis requires you to register an account with them in order to acquire the necessary authorization token for their ACME API. This poses a privacy/anonymity issue for some users. Last I checked, Actalis' free tier didn't support SAN either. Add.: I created an account just now to see "what's what" and also found the notice, "Activate your free 90 days certificates. At the end of the free year, the services associated with the certificates will expire." which sort of sounds like it's just a 1-year free trial.
- greatgib 4mo agoTo be put in perspective with their push for very short live certificates, like 7 days, with the argument that anyone can easily get certificate from at any time. But in fact, little by little you have all the stacks needed to be able to isolate some entities from internet at the us request in a very short time
- CobrastanJorji 4mo agoLet's Encrypt’s mission is to create a more secure and privacy-respecting web, except for people residing in countries with the most need for a more secure and privacy-respecting web. Sure, that's great. That said, pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries. I'm sure some of y'all are old enough to remember when web browsers came in "international friendly" versions that supported 40 bit encryption, or "fancy secure" versions with 128 bit encryption.
- rzerowan 4mo agoSeems in all thing tech at the moment the US legal system is accelearting a great split and erectinga digital iron curtain, from AI models to the more mundane like TLS certs. Its been standard for a while for many Linux distros based in the US to toe the party line - like RedHat having notices pretty similar to this one by LE. Seems any meaningful Open Projects will have to choose what path they want to take, be like RISC-V and relocate or LE and others and enforce the divide.
- xxpor 4mo agoThe RISC-V move was laughable. It’s still US tech, developed largely with DARPA funds.
- mschuster91 4mo agoSo what? If I disagree with the direction any FOSS project (or its maintainers) is taking... I can just fork it. People have done that countless times in the history of FOSS, most notably in the xOffice schism.
- xxpor 4mo agoNo remotely western company will risk US sanctions violations or whatever other regulatory burden by using US technology where it can't be used. Even Chinese companies depending on how state backed they are might not be willing to risk it.
- nikolay 4mo agoYeah, let everybody build and use their own services, and then the US will end up having less control and visibility. Great tactics!
- deleted 4mo ago[deleted]
- niemandhier 4mo agoIt their right to do that. But can we still trust them? I am not well versed in how their systemwide certificate issuance works: If they have to add this to their terms to comply with their government, could the same government use pressure to leverage let’s encrypt to do harm.
- trumpdong 4mo agoYes, of course it could and it will. I don't think the US government has ever missed an opportunity to be corrupt and break shit for stupid reasons.
- OutOfHere 4mo agoI had the parent organization of LetsEncrypt (Internet Security Research Group) in my Will, but after reading this, I will remove it immediately. US sanctions harm too many innocent people.
- VortexLain 4mo agoNow this is very bad, as bad as it can get. As soon as all local services will stop working in sanctioned countries, those countries' governments will force all users to either install a root certificate or lose access to all local services and websites. And then it will be possible to use that root certificate for MITM attacks. In the worst case scenario, after the majority of users will install the root certificate, state DPIs will MITM all traffic and will block all un-MITMable traffic.
- mrweasel 4mo agoThis should be one of those things that should be an quick EU win. Running Let's Encrypt is $3-4mill a year, the EU probably uses that on pencils. The EU could easily bootstrap a Let's Encrypt competitor if it truly cared about removing dependencies on US based entities.
- xxpor 4mo agoDo you really think the EU wants to sign up for PR that’s essentially “the US is being too mean to Russia” right now?
- flumpcakes 4mo agoI think the EU should do it regardless of Russia. The EU should invest in its own technology and not depend so much on an increasingly undependable ally.
- nozzlegear 4mo agoThe EU is more likely to issue fines to the ISRG and all involved parties.
- zajio1am 4mo agoYes, but EU would have to convince Google and Apple to get a new root certificate to browsers.
- toast0 4mo agoNot really. They just have to convince an existing CA that cross-signing their CA won't make Google and Apple mad. Cross-signed roots are common. Just takes money and maybe audits, but it's the same audit they'd need to get in the browser root stores anyway.
- joemi 4mo agoIs Let's Encrypt the only provider of SSL certificates? Genuine question! Because I assumed there were other places you could get a SSL certificate, but people in this thread seem to be implying that without Let's Encrypt, there's no way for people in those sanctioned territories to get a cert.
- herbst 4mo agoIf nothing has changed it's still the only one that's free and instant. Back in the day you'd had to pay $10/y and install manually
- kube-system 4mo agohttps://zerossl.com/ https://zerossl.com/
- Fnoord 4mo ago> Is Let's Encrypt the only provider of SSL certificates? No.
- nicce 4mo agoThere are some options. actalis.com is European alternative but free tier is a bit less than Let's Encrypt.
- hinata08 4mo agoIf it was a genuine question, the genuine answer is it's the provider that democratised streamlined ACME certificate verification and made it for free No account, no payment, a single bash command or a certbot that runs regularly and you have your own globally recognised certificate Historically, providers used to make the most frictions so that they could justify absolutely crazy fees for signing any certificates. It doesn't goes down well in DevOps, it doesn't work with indies who don't have 3 to 4 digits figures to blow in httpS, everyone including organisations ended up making certificates authorities of their own to sign stuff... and let's encrypt was successful at making certificates easy, free and actually secure
- snowflaxxx 4mo ago[flagged]
- misano 4mo ago[dead]
- cyounkins 4mo agoGotta love the word 'sanction'. It is it's own antonym! "The committee sanctioned the new policy." (approved it) "The committee sanctioned the rogue nation." (penalized it)
- lmm 4mo agoThere are many autoantonyms in traditional English, e.g. cleave.
- rerdavies 4mo agoIs this actually new? Looks like a standard US export restriction for encryption technology to me. These sorts of restrictions have been around since the '90s. Let's Encrypt becomes subject to US export restrictions on cryptography if they are a US company, or if they post anything to github or post anything to major app stores. Every app I have ever posted to Google Play has had to submit a form to the US government declaring what use they make of cryptography. These restrictions have been in force since that late 1950s (with a long and complicated history with respect to computer cryptography). This particular text looks like a boilerplate restriction, that's required to comply with US EAR export requirements to me.
- lmm 4mo agoOrganisations that are serious about promoting privacy should have been avoiding the US since the '90s and/or '50s, but the second best time to reincorporate in a safe jurisdiction is today.
- fluoridation 4mo agoA certificate is not cryptography, though, it's a number. The entity requesting the certificate already has the cryptographic software installed on their servers, as do the clients trying to connect to them. There's nothing technologically special about the number, it's all in the realm of the social contract, in that it has been blessed by a chain of trust.
- yreg 4mo agoEverything is a number.
- fluoridation 4mo agoYou can represent arbitrary data as a string of numbers, but a certificate is quite literally a number. It's a secret solution to a mathematical equation.
- mollydzy 4mo ago[dead]
- mollydzy 4mo ago[dead]
- mollydzy 4mo ago[dead]
- markhahn 4mo agohuh? the linked document shows that bullet item as deleted.
- mollydzy 4mo ago[flagged]
- ebiederm 4mo agoWeird. The copy I read says they have just deleted that section of their user agreement.
- jldugger 4mo agoTook me a minute to parse the headline -- Sanctioned as as in "imposed penalty" (ie "sanctions"), not as in dictionary definition #2 "official permission or approval". Perhaps because "US territories" are a thing, perhaps because it's way more newsworthy if LE bans the US, or perhaps im just a dummie.
- guhcampos 4mo agoThe title was a bit misleading. When I read it, I interpreted it as "let's encrypt bans certificate usage in - any territories endorsed by the US". Took me reading a couple comments to understand it actually meant "territories under US sanctions".
- trumpdong 4mo agoWe all knew something like this was coming when we decided to centralise the web around Let's Encrypt. In reality of course you can probably just ignore this as long as you request the certificate from a proxy in a nonsanctioned country and you don't stick out to the government.
- Dibby053 4mo agoAll they can do is disable support for certain ccTLDs, but other than that, it's unenforceable. That's why many tech companies echo these laws overtly and with a lot of fanfare... They know they have no real control over who uses their services, so this is a way to signal their good faith and best effort in advance, in case they end up caught up in some foreign cyberbullshit.
- morpheuskafka 4mo agoI had been meaning to post somewhere that they issued a certificate to kza.org.kp a few months ago but didn't really seem worthy of its own thread. I am no lawyer, but while there do appear to be some exemptions for communication related services, it's not clear that this qualifies as LE isn't actually providing telecommunications, just a certificate file. And it's not even an issue of the encryption itself, North Korea is under a general embargo so any exports or trade whatsoever is restricted by default. As an aside, many of North Korea's web servers appear to be old enough to have Heartbleed based on their banner versions, but most don't actually have HTTPS in the first place.
- rswail 4mo agoFor all the people commenting, the ITAR rules still apply for TLS, if you want to use TLS in an app for iOS/Android, one of the requirements is to get an ITAR exemption as part of the app review [1]. The US sanctions are imposed on entire nations (eg Iran), so LetsEncrypt have no option but to state in their conditions that their service is not available. They don't have a choice as a US organization operating under US law. Whether they choose to enforce that through technical means (eg blocking IPs etc) is up to them. [1] https://developer.apple.com/documentation/security/complying-with-encryption-export-regulations https://developer.apple.com/documentation/security/complying...
- mrsssnake 4mo agoWhy when connecting to a TLS website service that does not have a CA signed certificate, I am welcomed with "Secure connection failed, browser not trusting the ceritifate. Do you want to continue?", without showing me the actual certificate fingerprint? On desktops browser displaying the fingerprint/hash requires clicks, on mobile is not implemented and on native apps practically not existing. The keys should be shown, so they could be verified manually in person or via other channel. Just like the SSH do. Someone say people would just click "accept" without a thought, but the button is already here, just no information what actually is accepted.
- someguyornotidk 4mo agoA lot of the pushback browser vendors got for locking APIs behind so-called "secure contexts" was because everyone (including them) knew this would happen. If there is a centralized system, some politician will manage to find a way to fuck with it. Iran and other tyrannical governments can easily set up their own CAs and force their citizens to use them. Iran likely already has this infra in place. This ban does nothing but highlights LE as the liability it is. The decades-old certificate authority scheme is no longer fit for purpose and needs to go. If you're a web developer, consider offering your site through public key-addressable networks. Reticulum and Tor are good options that work today.
- cekanoni 4mo agothis is big blow to the Internet society very disappointing to read this..
- boomlinde 4mo agoWhat other CAs implement ACME? Are there any free alternatives outside the US?
- gnunicorn 4mo agoIt was a great hack, but it was always just that: a hack. We all always knew that the "certificate authority"-hierarchy is broken and can easily be abused by the ones in power. I appreciate everything that the let's encrypt peeps have done for the world, but the cert authority system really needs an overhaul.
- rurban 4mo agoHello! The US is the enemy of democracy. If someone should be banned, then them.