That would be just a nuisance until a new certificate is generated with another vendor (possibly not for free, but cheap enough).
Comment on Letsencrypt is under US jurisdiction. Is there a free-er alternative?
Sibbo@sopuli.xyz 7 hours agoLetsencrypt can be directly forced to revoke certificates by the US. Organisations outside of the US are less vulnerable against that.
IpsumLauren@lemmy.world 2 hours ago
pdl@social.tchncs.de 6 hours ago
@Sibbo Of course. Actually, there are 200 million active certificates issued by Letsencrypt. Revoking them, 200 million websites would be down. 200 million websites all over the world, including US. I don't think this is a realistic scenario.
If you are worried about that, you should avoid any software developed in US. You should avoid any software which itself or its sources are hosted in US. Mastodon is available on Github, this is Microsoft. US authorities may force Github to shutdown or infiltrate the hosted sources with spyware.
slazer2au@lemmy.world 6 hours ago
And ICAAN can hand your domain over to US law enforcement regardless of the TLD and your register.
Is that also part of your decision tree?
Pika@sh.itjust.works 4 hours ago
Is this accurate? Like, I know what you’re meaning, but I’m pretty sure it’s not ICANN doing it, and more so your domain registrar handing it over to the US government.
I think the most control that ICANN has over it is they could theoretically, if they wanted to, delete an entire top level domain. Since they do control the DNS root, but that is the most that they control from what I understand.
I don’t know if they have the ability to delete or transfer control over an individual domain on legal request. I think that’s outside of what their actual system allows for.
libewa@feddit.org 6 hours ago
ICANN can (theoretically) not force anyone to deregister your domain. If your stack is all outside the US, and everyone collectively decided to disobey the US, the Internet’s decentralization would be true.
For the Internet, the centralization is hidden in the IP block and DNS Zone delegation. After this is done, that region is decentralized. A/I’s problem was that the registry for .org is a subsidiary of IANA. With EU servers, EU DNS and a EU domain, EU clients cannot be prevented from connecting solely from the outside. The US would need a collaborator.
slazer2au@lemmy.world 6 hours ago
That is all well and good, but we have many instances of domains being pulled from people because of court ruling and your register is not going to defy a court ruling for your €17/year domain.
Auli@lemmy.ca 5 hours ago
Aren’t the .country domains managed by the countries?
slazer2au@lemmy.world 15 minutes ago
Who all get that authority from ICAAN
veniasilente@lemmy.dbzer0.com 5 hours ago
Maybe it should be! We need non-fascis-adjacent DNS roots.
frongt@lemmy.zip 3 hours ago
opennic.org
eleitl@lemmy.zip 4 hours ago
There are authorityless blockchain-backed name registration services. In general, it is important whether you can localize a resource. If you can easily find it, it doesn’t have to human-readable.
WhyJiffie@sh.itjust.works 1 hour ago
if its not human readable, how will people know its the place they want to go to? I don’t think bookmarked onionsites is a particularly good idea