Still American. de-Americanizing the tech stack is a good idea.
Comment on Letsencrypt is under US jurisdiction. Is there a free-er alternative?
possiblylinux127@lemmy.zip 1 day ago
Let’s encrypt is very transparent and has been designed to be auditable. What are you worried about exactly?
herseycokguzelolacak@lemmy.ml 1 day ago
Fedditor385@lemmy.world 1 day ago
Are you trying to solve a technica, or political/moral problem? Let’s Encrypt doesn’t create, see, store or log your private cerficates. So, even if they are in the US, I don’t see a risk, and otherwise, the other parts you use in general are probably vulnerable to the problem even if non-US.
For ex. the US could simply order browsers stop validating any certificates not issues by US companies in browsers. And whoosh. Having a non-US certificate won’t help much there either.
flandish@lemmy.world 23 hours ago
uncle sam. audit away. until sam says “give me the keys” and then sam has the keys
pdl@social.tchncs.de 23 hours ago
@flandish @possiblylinux127 Letsencrypt just has the public keys, no private keys. If Letsencrypt gives my public keys to sam, it does not matter, because public keys are public. My private key is under my administration only.
flandish@lemmy.world 23 hours ago
and the backdoor?
pdl@social.tchncs.de 22 hours ago
@flandish Which backdoor? When I request a CA for a certificate, I send the public key to the CA. The CA does a validation and signs the certificate.
The CA does not see any traffic from my server. A man-in-the-middle needs my private key, which is under my administration. If I loose my private key, it does not matter if the certificate is signed by a US based CA or an European CA.
possiblylinux127@lemmy.zip 20 hours ago
The transparency logs would mean that any rouge certificates created would leave a paper trail not to mention there is nothing stopping them from issuing a certificate for any domain of there choosing
art@lemmy.world 13 hours ago I think Let’s Encrypt will stay safe for quite a while, but unfortunately because of the political climate we’re in right now, it may not stay safe in the future.
thericofactor@sh.itjust.works 1 day ago
That the U.S. government can arbitrarily take down websites by revoking certificates issued by let’s encrypt? How obvious can it be? I wondered the same thing as OP months ago. We need european alternatives. I think there are some, have some bookmarked somewhere.
Passerby6497@lemmy.world 1 day ago
Certificate revocation is a joke and has been for over a decade
Randelung@lemmy.world 1 day ago
Huh, FF on Android doesn’t care.
Passerby6497@lemmy.world 1 day ago
Most browsers don’t, hence my calling revocation a joke.
So many in this thread are up in arms about something the majority of browsers don’t care about and have actively ignored for as long as I can recall
DegradationDenial@feddit.nl 1 day ago
If the certificate only lasts two months revocation isn’t necessary, just deny recertification.
Viceversa@lemmy.world 1 day ago
And what if you need to get a new certificate?
possiblylinux127@lemmy.zip 1 day ago
You go to a different CA
T4V0@lemmy.pt 1 day ago
Orion browser (maybe safari?) on iOS detected the revoked certificate, and asked me to confirm before accessing the website while warning about the dangers.
Passerby6497@lemmy.world 21 hours ago
Does regular safari show the same prompt? Afaik, browsers on iOS are safari reskins, so I’m curious if they added his cert in directly, or if the onion browser actually follows standards the os browser doesn’t.