8 ms·
Is this a canary? What's gonna happen if I were to begin or continue using one letsencrypt certificate from ... Greenland? Cuba? The EU? Has letsencrypt been
by m2f2 3mo ago
Is this a canary?
What's gonna happen if I were to begin or continue using one letsencrypt certificate from ... Greenland? Cuba? The EU?
Has letsencrypt been served with a subpoena?
- rafram 3mo agoNeither Greenland nor the EU has been sanctioned by the US.
- nitwit005 3mo agoThey haven't been sanctioned, yet, but we live in a time where that's a real possibility.
- malfist 3mo agoSo far
- tempfile 3mo agoIt is not exactly an outlandish suggestion that this may happen.
- _ache_ 3mo agoYet.
- deleted 3mo ago[deleted]
- piskov 3mo agoHave you heard about the judge from international court or whatever it is called? https://www.france24.com/en/americas/20250820-us-hits-icc-with-more-sanctions-targets-french-judge-involved-in-netanyahu-arrest-warrant https://www.france24.com/en/americas/20250820-us-hits-icc-wi...
- tialaramex 3mo ago> Has letsencrypt been served with a subpoena? While it's certainly possible that ISRG has been served a subpoena because it appears the US DOJ is now a mix of hacks and incompetent buffoons, it wouldn't matter because the whole point is that they don't know anything - what you told them is literally logged publicly for everybody to see without even knowing how to spell "subpoena" let alone issue one. Some people have this insane idea that somehow the CA has some secret which either they minted and sent to the CA, or the CA minted and gave them a copy and so the US government could get this secret with a subpoena - but the whole fucking point of a Public Key Infrastructure is that we're using Public Key Encryption, if we were OK with everybody having secrets all over the place this entire thing wouldn't be needed.
- basilikum 3mo agoThey have the secret of the private keys used to sign certificates. Looking at LavaBit^1 I really would not be so comfortable. The world and especially the US has not gotten more free since then. [1]https://en.wikipedia.org/wiki/Lavabit https://en.wikipedia.org/wiki/Lavabit
- tialaramex 3mo agoThey could mint certificates, for / about any name. But, those certificates won't work in popular applications unless the certificates include proof of logging. So to be effective this means a hypothetical bad actor (maybe the US government or anybody else) issues bogus certificates, then either logs them - making a permanent record for everybody to see, or also subverts two or more logs, so that they issue bogus proofs. This is a very expensive one shot attack on whatever the target would be, I guess it's not stupider than "Let's bomb Iran for no good reason" but it's up there.
- basilikum 3mo agoFor the vast majority of cases, would anyone notice these malicious certificates being created and logged?