I know that I can simply make my own private certificate authority that only I and my family trust. But is there some public provider like letsencrypt that is in a free-er part of the world than the US?

  • Possibly linux@lemmy.zip
    link
    fedilink
    English
    arrow-up
    40
    arrow-down
    7
    ·
    1 day ago

    Let’s encrypt is very transparent and has been designed to be auditable. What are you worried about exactly?

    • arthurpizza@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      2 hours ago

      I think Let’s Encrypt will stay safe for quite a while, but unfortunately because of the political climate we’re in right now, it may not stay safe in the future.

    • flandish@lemmy.world
      link
      fedilink
      English
      arrow-up
      9
      arrow-down
      3
      ·
      13 hours ago

      uncle sam. audit away. until sam says “give me the keys” and then sam has the keys

      • Possibly linux@lemmy.zip
        link
        fedilink
        English
        arrow-up
        7
        ·
        10 hours ago

        The transparency logs would mean that any rouge certificates created would leave a paper trail not to mention there is nothing stopping them from issuing a certificate for any domain of their choosing

      • pdl@social.tchncs.de
        link
        fedilink
        arrow-up
        10
        ·
        12 hours ago

        @flandish @possiblylinux127 Letsencrypt just has the public keys, no private keys. If Letsencrypt gives my public keys to sam, it does not matter, because public keys are public. My private key is under my administration only.

          • pdl@social.tchncs.de
            link
            fedilink
            arrow-up
            8
            ·
            11 hours ago

            @flandish Which backdoor? When I request a CA for a certificate, I send the public key to the CA. The CA does a validation and signs the certificate.
            The CA does not see any traffic from my server. A man-in-the-middle needs my private key, which is under my administration. If I loose my private key, it does not matter if the certificate is signed by a US based CA or an European CA.

            • pdl@social.tchncs.de
              link
              fedilink
              arrow-up
              8
              ·
              11 hours ago

              @flandish If US authorities want to fake my server, they can use any CA, regardless which CA I originally used.
              Of course, US authorities can force Letsencrypt to revoke my certificates and block any renewing. This is very unlikely to happen. If it happens, I have to change my CA. There would be a downtime for my private services, but there is no data corruption or data loss on my servers.

                • pdl@social.tchncs.de
                  link
                  fedilink
                  arrow-up
                  6
                  ·
                  10 hours ago

                  @flandish This is no backdoor. This is an denial of service. It’s a big difference. I have to estimate the risk and decide if I want to take it. ZeroSSL uses the infrastructure of Sectigo, an US company. Sectigo can pull the plug very easily. So it is no alternative. Maybe Actalis or Certum are good alternatives. But the government of Poland has not been unproblematic in the past.

                • Pika@sh.itjust.works
                  link
                  fedilink
                  English
                  arrow-up
                  4
                  ·
                  10 hours ago

                  Said backdoor isn’t possible with the current day key exchange process. Without the servers in use private key, the most law agencies can do without acquiring the private key is force the CA to revoke a cert, which will disallow properly configured clients from accessing and transferring data with the server.

                  LE doesn’t have enough information to recreate the private key based off the public key, the only key distributed during the CSR process is the servers public key via a certificate signing request which is signed using your private key, which the CA then signs with it’s own intermediate key (which is signed by it’s root server certificate) and hands back to the private server.

                  The CA doesn’t have the ability to create that private key, and as such doesn’t have a way to decrypt traffic that is using that key. There is no concern for a backdoor in that process.

                  In order for the “backdoor” to exist, they would need to either copy the private key as part of the signing process (which it doesn’t), or somehow force the server admin to use a new private key (that the CA also holds) or somehow compromise the servers key generation process to allow for an escrow on the private key when it was generated which would allow the CA to be able to recreate the private key using the master & public key.

                  Now don’t take me wrong, you can still have a MiTM impersonation attack or a full impersonation bypass by the CA issuing a new certificate and having the DNS registrar have the web address go to a new server that is using the new key but, that’s not something the CA alone has the capability of doing, and any traffic that is issued to the original server still wouldn’t be compromised, its just clients visiting your site will end up at the other site and as such will end up using keys that the other side generated instead of your own keys and additionally said new keys would also be appearing in Certificate transparency logs, or modern day clients would refuse to use them.

      • Fedditor385@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        arrow-down
        1
        ·
        13 hours ago

        Are you trying to solve a technica, or political/moral problem? Let’s Encrypt doesn’t create, see, store or log your private cerficates. So, even if they are in the US, I don’t see a risk, and otherwise, the other parts you use in general are probably vulnerable to the problem even if non-US.

        For ex. the US could simply order browsers stop validating any certificates not issues by US companies in browsers. And whoosh. Having a non-US certificate won’t help much there either.

    • thericofactor@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      32
      arrow-down
      3
      ·
      1 day ago

      That the U.S. government can arbitrarily take down websites by revoking certificates issued by let’s encrypt? How obvious can it be? I wondered the same thing as OP months ago. We need european alternatives. I think there are some, have some bookmarked somewhere.

          • Passerby6497@lemmy.world
            link
            fedilink
            English
            arrow-up
            6
            arrow-down
            1
            ·
            15 hours ago

            Most browsers don’t, hence my calling revocation a joke.

            So many in this thread are up in arms about something the majority of browsers don’t care about and have actively ignored for as long as I can recall

              • Passerby6497@lemmy.world
                link
                fedilink
                English
                arrow-up
                1
                ·
                15 hours ago

                It may only be the desktop version, most mobile browsers aren’t as feature complete as their desktop counterparts.

                But, given Google ripped revocation checking out of chromium, I wouldn’t be surprised if they nerfed it in Android too…

        • T4V0@lemmy.pt
          link
          fedilink
          English
          arrow-up
          1
          ·
          13 hours ago

          Orion browser (maybe safari?) on iOS detected the revoked certificate, and asked me to confirm before accessing the website while warning about the dangers.

          • Passerby6497@lemmy.world
            link
            fedilink
            English
            arrow-up
            2
            ·
            11 hours ago

            Does regular safari show the same prompt? Afaik, browsers on iOS are safari reskins, so I’m curious if they added his cert in directly again, or if the onion browser actually follows standards the os browser doesn’t.

            • T4V0@lemmy.pt
              link
              fedilink
              English
              arrow-up
              2
              ·
              8 hours ago

              Yes, but safari doesn’t even let me ignore the warning, it has a explanation in detail, and only allows closing the website.

                • T4V0@lemmy.pt
                  link
                  fedilink
                  English
                  arrow-up
                  2
                  ·
                  4 hours ago

                  Maybe there’s a special case for local subnets?

                  Here’s what shows up for me (in portuguese):

                  Safari browser invalid certificate warning page.

                  Clicking on more details, only allows me to check the certificate:

                  Safari browser detailed information for invalid certificate warning.

                  Here’s the translated details:

                  Safari warns you when a website has an invalid certificate. This can happen if an attacker has compromised your connection. For your protection, you cannot visit this site. You can check later to see if the problem has been solved. You can also contact the site owner to report this error.

                  To learn more, you can see the certificate.

                  Said certificate:

                  iOS invalid certificate information.

                  Edit: on the latest iOS version (27) btw.

                  • dogdeanafternoon@lemmy.ca
                    link
                    fedilink
                    English
                    arrow-up
                    2
                    ·
                    2 hours ago

                    Thanks for the proof! I stand corrected! I see basically the same but after the view link there is another think that bypasses it.

                    Must be difference between expired vs compromised cert.