5 ms·
Iranian banks' SSL certificates are being revoked due to OFAC sanctions
- yieldcrv 19d agopetty
- londons_explore 19d agoThis seems like the kind of thing that the USA will explicitly grant an exception to. It is clearly bad if the whole of Iran gets their own CA infrastructure which the NSA can't as easily spy on.
- toomuchtodo 19d agoThey could stand up their own version of Let's Encrypt with less than 20 people and $5M/year. It is inevitable. Let's Encrypt had a budget of $3.6M and 13 employees as of 2019 [1], but I don't have recent funding and staff figures as of this comment (replies with context welcome!). Probably spread the cost across the BRICS to make it US sanction resistant. [1] https://news.ycombinator.com/item?id=24085559 https://news.ycombinator.com/item?id=24085559 (citations)
- misano 19d agoIt’s not merely about setting up a CA. The CA certificates would have to be added to the trust stores of every operating system, browser, framework, and application, creating a sea of security risks for the public. It’s an isolated, privacy-invasive process.
- toomuchtodo 19d agoDo you not believe the rest of the world will not move in this direction to decouple from the US? If not, you should consider it is more likely than before. Countries will mandate it if they want it done badly enough, and there is enough open source to own the entire stack (OS, browser, CLIs, etc). It is simply a matter of will, resources, and time, in that order. "You eat an elephant one bite at a time" as the saying goes. Can it be done? Yes. Will it be done? We can only watch to find out. https://news.ycombinator.com/item?id=49225112 https://news.ycombinator.com/item?id=49225112 (citations) (sysadmin/network admin/devops/infra engineer a lifetime ago, mostly familiar with what bootstrapping this looks like)
- AlecSchueler 18d ago> Do you not believe the rest of the world will not move in this direction to decouple from the US? Sure, but that will require more than 20 people, 5 million USD and the sole will of the Iranian government.
- toomuchtodo 18d agoDifferent contexts. It is cheap to build your own Let's Encrypt, it takes more time and effort for the world to decouple. Both can be true.
- hulitu 18d ago> The CA certificates would have to be added to the trust stores of every operating system, browser, framework, and application, creating a sea of security risks for the public Finaly one that acknowledges...
- lxgr 19d agoSure they can, but very importantly, so far the US has not forced them to for extremely good reasons. As just one example, you can take a guess as to whether such a CA will support certificate transparency...
- spwa4 19d agoYeah now the NSA only contains the code of the browsers Iranians use, right down to the os and even firmware. Clearly a big loss ... I guess you could say a loss is a loss ...
- Daishiman 19d agoSo now that SSL certificates are being weaponized it now becomes a matter of national security for any country to have their own independent CA infra. Another win for the US.
- bigbuppo 19d agoBetter yet, don't rely on a central trust authority that can't be trusted.
- general1465 18d agoI mean if you have ever tried to get Code signing certificate, it is absurd theater to get it working and your choice is like 3 different US certificate authorities.
- bradly 19d agoIt already was. Stuxnet used trusted, signed Windows drivers to destroy Iran’s centrifuges back in 2010 and afaik we still don’t know exactly how the attackers did this.
- fhejfnenjdcn 19d ago[flagged]
- azinman2 19d agoHow could you possibly label the Iranian war so far a genocide?
- fhejfnenjdcn 19d ago"Time for bridge and powerplant day! A whole civilization dies tonight!"
- azinman2 19d agoThat’s fair as a very troubling threat. So far it hasn’t materialized. Seems to be the boy who cried wolf.
- kg 19d agoI think you picked the wrong analogy. The US threatened unjustifiable acts targeting civilian population & infrastructure, and to a degree has followed through - for example bombing water facilities: https://www.yahoo.com/news/politics/articles/us-bombs-iran-water-facilities-132727966.html https://www.yahoo.com/news/politics/articles/us-bombs-iran-w...
- fhejfnenjdcn 19d ago[flagged]
- sdsd 19d agoThe word genocide is currently undergoing semantic bleaching (https://www.merriam-webster.com/grammar/very-actually-and-other-examples-of-semantic-bleaching https://www.merriam-webster.com/grammar/very-actually-and-ot...). It's too powerful a word for propagandists/activists to resist beating it into oblivion in the service of their causes.
- 128471599 19d agoIt is a reminder to go back to cash, ATMs and machines where you can enter you transactions instead of using the Internet. There is no reason to give money to US middlemen for everything you do. The whole of the EU should do this, too. I stopped using Internet banking after my bank moved from SMS Tan to hardware Tan generator (one of which didn't work) to forced mobile app. No thanks.
- OutOfHere 19d agoCryptocurrency actually works and doesn't involve US middlemen under governmental oppression. It's a fact. Also, they stopped capitalizing the "i" in "internet" some time ago. Wake up from the year 2000 already.
- CookieCrisp 19d agoHahaha, that’s a good joke
- OutOfHere 19d agoIt's not a joke. It's 100% true. People tend to be extremely uneducated wrt crypto, also favoring to dwell in their ignorance.
- robocat 19d agoI spent months in South America and tried to use crypto in Chile, Argentina, Uruguay and Brazil. I was motivated because of this pro-crypto article: https://devonzuegel.com/inside-argentina-s-currency-exchange-black-markets https://devonzuegel.com/inside-argentina-s-currency-exchange... People in many South American countries should be highly motivated to use crypto because fiat is usually damn shit. I was motivated because cash machines were extremely crappy for a tourist (when you could find an ATM that even had any money in its cassettes). Argentina was a USD8 withdrawal fee plus the super shitty official exchange rate and half the time you could only withdraw maybe USD30 maximum so you maybe needed to do multiple transactions. I also had NZD bank fees and poor exchange rates from my own NZ bank added. It was a total shitshow trying to use crypto. I would honestly have been better wandering around with gold in my pockets. Crypto was high risk: dangerously unsafe. Also mostly unavailable unless you were really lucky. Complex. Massively taxed for recipients if they used anything that officially supported crypto. Arbolitos (street money changers) would take a 10-15% cut and it always felt super effing dodgy (felt like a risk of getting kidnapped). I can't recommend it. There was no way to learn how to do crypto transactions safely, even though I have conversational Spanish. Scary as all fuck. My kind of holiday, but I couldn't recommend anyone take those risks unless they're as stupid an idiot as me. I'm mostly relaxed about countries taking advantage of me (or other tourists), but South America was so OTT that I mostly wouldn't go back. That said, I loved Brazil even though I can't speak a word of Portuguese. That's the only place I would make an effort to return to from my 3 months travelling in South America.
- jMyles 19d agoIt's bizarre that there isn't yet a total separation of certificate-and-state.
- badatnames 19d agoUtterly moronic. We support the freedom of the Iranian people by forcing them to install a local government root CA in every browser. I mean at this rate they won't even have to buy their monitoring tech from China any more, just an old PC and a late 90s tarball of Squid
- throw310822 19d agoNobody gives a damn about the freedom of the Iranian people. They are a problem for Israel [1], so the US bombs them. The rest is just post-hoc justification. [1] Note that every civilised country should be a problem for Israel- but Iran is the only one that actually dares opposing it.
- misano 19d agoThese remarks are antisemitic. The people of Iran aren’t seeking a fight against imperialism. We want to live like ordinary people in the U.S., Europe, and Israel, and be allied with them. The fascist Shiite regime has taken everyone hostage, and it’s leading us toward a collective suicide.
- throw310822 19d ago> These remarks are antisemitic So it would be fine if they were against any other country engaged in genocide, but not against Israel because it's Jewish? Is that your defense of Israel? > We want to live like ordinary people in the U.S., Europe, and Israel, and be allied with them You want to be allied with a genocidal state and the country that has forced you into poverty for the last decades?
- catch310688 19d agoIn 2026 in Gaza there were about 1000 deaths - many of them combatants officially mourned by Hamas and Islamic Jihad. In the same year: Iran killed at-least 5000 civilian protesters. Russia killed around 1,800 Ukrainian civilians. 5000 were killed in Sudan. 3000 in Haiti. You are fine will all that (or will deny it), because you only care when the Jews are involved.
- lxgr 19d agoForcing their customers to install government-affiliated alternative CAs, in turn allowing the government to spy on its citizens more easily via mis-issued certs? Great, that'll show them.
- misano 19d agoThis was the most anti-colonialist move America had ever made, but you can’t keep tiptoeing around your enemy forever.
- lxgr 19d ago> [...] you can’t keep tiptoeing around your enemy forever. If it doesn't cost the US anything and is strategically in their favor (via weakening an opponent), I really don't see why they couldn't have. On top of that, it'll make others find alternatives quickly, as has already been happening with e.g. payments and other critical infrastructures. What an incredible waste of soft power built over decades.
- Waterluvian 19d agoAs an amateur student of history and a professional watcher of television, I think one possible conclusion I've drawn is that the happy state is tiptoeing around your enemy forever. Or rather, tiptoeing with your enemy. That there is no "and the enemy was defeated and we returned to the Shire and the galaxy is finally at peace." Quietness, even if it's not called peace, is the virtuous state we should endeavour to preserve.
- deleted 19d ago[deleted]
- AtNightWeCode 19d agoCAs is the problem. Not who runs them...
- throw0101d 19d ago> Forcing their customers to install government-affiliated alternative CAs, in turn allowing the government to spy on its citizens more easily via mis-issued certs? How's the support for X.509 "Name Constraints" these days: * https://datatracker.ietf.org/doc/html/rfc5280#section-4.2.1.10 https://datatracker.ietf.org/doc/html/rfc5280#section-4.2.1.... Would restricting it to only dot-ir domains be a mitigation? * https://en.wikipedia.org/wiki/.ir https://en.wikipedia.org/wiki/.ir
- cyberax 19d agoThis is super-dumb. The same thing is happening with Russian banks. Their answer? They're now asking users to install root certs from the Russian ministry of communications. So it can now MITM all the encrypted traffic in Russia.
- axus 19d agoDumb for the US: if US were currently MITM with certs copied by its agencies, US won't be able to do that for Iranian / Russian certs.
- misano 19d agoSSL MITM also requires hijacking the network and redirecting the traffic.
- Avamander 19d agoChina and many others run their own CAs, I'd presume Russians could use those if they wanted?
- throw-the-towel 19d agoRussians didn't want to use those, until the West made it inevitable.
- Avamander 19d agoAnd why is that? It's not that hard to find a CA in a more aligned regime. Rolling your own MITM CA as a replacement just looks like something that was waiting for an excuse.
- cyberax 19d agoViolating the OFCOM restrictions will result in losing access to VISA/MC payments. No company wants this.
- pibaker 19d agoSanctions on Iran are justified. But I worry this kind of action will just lead to the eventual rise of an alternative tech ecosystem in the long term, probably led by china and Russia. It will be bad for us, bad for people living under those regimes, but good for the regimes themselves because they will have the fullest control over their technology, without having to compromise with the West. Another example of why maximalist political hostility can be counterproductive. Leave an olive branch in sight, and you may work towards a mutually beneficial resolution, like the previous Iran nuclear deals. If push your opponent into a corner, then don't get upset when they jump over the wall into the wild where you can't catch them anymore. See also Chinese chips and AI.
- hammock 19d ago> Sanctions on Iran are justified For what?
- ImHereToVote 19d agoFor retaliating against they president being assassinated and their country attacked. This is strictly against the rules based order.
- stickfigure 19d agoIt's not "their" president, Iranians didn't elect him. Khomeini was a religious extremist who only months ago presided over the murder of ten thousand protesters and we should shed not one tear.
- Mikhail_Edoshin 18d agoHe was elected by a so-called council of experts. Those experts are elected by the people, although screened by the council of constitutional guards. The council consists of six lawyers assigned by the leader and six lawyers elected by the parliament. (There's a parliament and a civil president.) Iran is a republic. It became a republic in 1979 on a national referendum. Before that it was a monarchy. That monarchy used to be limited since 1941, but in 1953 it was restored as a result of an overthrow backed by US and Britain. The cause of that was that the civil government tried to nationalize oil companies. The last monarch is in exile but, apparently, hopes to return to power if the US wins. The West is a fantastic liar and a tremendous used car salesman. There's a short story by Mark Twain how he tried to run for a governor. Satirical, but truthful. Yet somehow the West managed to sell the idea that a regular shitshow of this kind is a pinnacle of state development, that states who do not run it are, of course, oppressors and oppressed, and that any means against them are thus justified.
- dayyan 19d agoGood.
- zoobab 19d agoIt's not as if SSL critics warned about this ponzi pyramid, prone to censorship.
- MadrasTh0rn 19d agoTrump Vance Johnson Elon and Thiel are removing US institutions globally by force Trump is intentionally playing into Chinese, Russian Noth Korean, Iranian hands They must be impeached/removed regardless of intent Nobody voted for this
- cestith 19d agoThis seems like a bad idea.
- borschtplease 19d agoOne more technical challenge. The whole ssl infrastructure is incompatible with a state current planet moves forward to.
- ValdikSS 19d agoThe same applies to Russian banks. Russian banks have switched to internal Ministry of Digital Development CA which is not trusted in common browsers. https://crt.sh/?id=22899279066 https://crt.sh/?id=22899279066 (Revoked: privilegeWithdrawn)
- gonzalohm 19d agoI may speak from ignorance, but why do SSL certificates depend on centralized CA? If I'm an entity such as a bank, I should be able to sign my own certificate and provide the public keys to my clients which then can use it to both encrypt communications and to make sure you are talking with the entity you want to talk to. Am I missing anything?
- coldpie 19d ago> provide the public keys to my clients How does this part happen? How does the client know that the entity providing them with that public key is who they claim to be?
- sam_lowry_ 19d agoHow do I know what certificates come with my browser?
- megous 19d agothey can fetch the key or its hash from DNS. it's not like the current system is that much more involved. current system is basically a third party signed cache of such ownership claims validated based on ability of someone to modify DNS records. All caches are just functionally useless layers..., so that's that.
- coldpie 19d ago
- zzo38computer 19d agoIt doesn't load for me, but I have read the other comments. There is the problem of TLS and X.509 being used with centralized authorities like this, even though it is not inherent to TLS nor to X.509 (although they were designed to be used in this way). In some circumstances, you can get a copy of the certificate (which might be self-signed) from somewhere else and then check that it matches in this circumstances. In other circumstances there are other things that can be done (e.g. TOFU, which has a different set of problems, but also has advantages in a different set of circumstances). What the security requirements are will depend on the circumstances, which can also depend on the user's intentions; they should not have to depend on a centralized authority. (There is the issue that a single X.509 certificate cannot have multiple issuers, though. There is also the issue that X.509 certificates cannot contain unsigned extensions (they could be added after the signature, but an implementation might check for additional fields after the signature and reject a certificate that has any). Although an alternative schema can be made (I have done so), it would not work with the existing protocols.)
- duxup 19d agoThis seems like a poor choice. Missing the point of sanctions, possible long term negative second order effects.
- Zenul_Abidin 19d agoSSl certificates for websites probably should be out of scope for sanctions