Comment on Letsencrypt is under US jurisdiction. Is there a free-er alternative?
thericofactor@sh.itjust.works 1 day agoThat the U.S. government can arbitrarily take down websites by revoking certificates issued by let’s encrypt? How obvious can it be? I wondered the same thing as OP months ago. We need european alternatives. I think there are some, have some bookmarked somewhere.
Passerby6497@lemmy.world 1 day ago
Certificate revocation is a joke and has been for over a decade
Randelung@lemmy.world 1 day ago
Huh, FF on Android doesn’t care.
Passerby6497@lemmy.world 1 day ago
Most browsers don’t, hence my calling revocation a joke.
So many in this thread are up in arms about something the majority of browsers don’t care about and have actively ignored for as long as I can recall
Randelung@lemmy.world 1 day ago
Yeah, I was just surprised bc the page explicitly lauds FF for checking revocation.
DegradationDenial@feddit.nl 1 day ago
If the certificate only lasts two months revocation isn’t necessary, just deny recertification.
Viceversa@lemmy.world 1 day ago
And what if you need to get a new certificate?
possiblylinux127@lemmy.zip 1 day ago
You go to a different CA
Alfredolin@sopuli.xyz 1 day ago
Aren’t we back at OP’s question?
That’s the question of this thread. Yes.
T4V0@lemmy.pt 1 day ago
Orion browser (maybe safari?) on iOS detected the revoked certificate, and asked me to confirm before accessing the website while warning about the dangers.
Passerby6497@lemmy.world 1 day ago
Does regular safari show the same prompt? Afaik, browsers on iOS are safari reskins, so I’m curious if they added his cert in directly, or if the onion browser actually follows standards the os browser doesn’t.
T4V0@lemmy.pt 21 hours ago
Yes, but safari doesn’t even let me ignore the warning, it has a explanation in detail, and only allows closing the website.