I know that I can simply make my own private certificate authority that only I and my family trust. But is there some public provider like letsencrypt that is in a free-er part of the world than the US?

  • pdl@social.tchncs.de
    link
    fedilink
    arrow-up
    28
    arrow-down
    5
    ·
    1 day ago

    @Sibbo I do not see any problem with Letsencrypt. Any CA which is widely trusted has to follow the same rules. This rules are set up by the CA Browser Forum. Which metadata does LE collect? My server’s IP address, domain and subdomain, mail address. These are logged in the CT logs. Every CA has to log all certificates in a public CT log. Regardless which CA I choose, these data are public. There are not any critical data or metadata that LE can collect.

    • Sibbo@sopuli.xyzOP
      link
      fedilink
      English
      arrow-up
      31
      arrow-down
      6
      ·
      1 day ago

      Letsencrypt can be directly forced to revoke certificates by the US. Organisations outside of the US are less vulnerable against that.

      • slazer2au@lemmy.world
        link
        fedilink
        English
        arrow-up
        33
        arrow-down
        1
        ·
        1 day ago

        And ICAAN can hand your domain over to US law enforcement regardless of the TLD and your register.

        Is that also part of your decision tree?

        • pdl@social.tchncs.de
          link
          fedilink
          arrow-up
          1
          ·
          43 minutes ago

          @slazer2au @Sibbo The administration of domain names is not done by ICANN. ICANN is responsible for managing IP addresses, ports, AS numbers. There are local registries for the administration of domain names. My .de domains are administered by DENIC in Germany. .net and .com are administered by US companies. This domains eventually can be shutdown by US authorities.

        • Pika@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          10
          ·
          1 day ago

          Is this accurate? Like, I know what you’re meaning, but I’m pretty sure it’s not ICANN doing it, and more so your domain registrar handing it over to the US government.

          I think the most control that ICANN has over it is they could theoretically, if they wanted to, delete an entire top level domain. Since they do control the DNS root, but that is the most that they control from what I understand.

          I don’t know if they have the ability to delete or transfer control over an individual domain on legal request. I think that’s outside of what their actual system allows for.

        • libewa@feddit.org
          link
          fedilink
          English
          arrow-up
          13
          arrow-down
          2
          ·
          1 day ago

          ICANN can (theoretically) not force anyone to deregister your domain. If your stack is all outside the US, and everyone collectively decided to disobey the US, the Internet’s decentralization would be true.

          The hard part about building a decentralized network is finding out where to hide the centralization.

          For the Internet, the centralization is hidden in the IP block and DNS Zone delegation. After this is done, that region is decentralized. A/I’s problem was that the registry for .org is a subsidiary of IANA. With EU servers, EU DNS and a EU domain, EU clients cannot be prevented from connecting solely from the outside. The US would need a collaborator.

          • slazer2au@lemmy.world
            link
            fedilink
            English
            arrow-up
            19
            ·
            1 day ago

            That is all well and good, but we have many instances of domains being pulled from people because of court ruling and your register is not going to defy a court ruling for your €17/year domain.

          • NotEasyBeingGreen@slrpnk.net
            link
            fedilink
            English
            arrow-up
            1
            ·
            20 hours ago

            I worked on the Yeti Project a while ago, which showed that an independent group of operators can run root servers.

            Managing the contents of the root zone was out of scope… we used the ICANN root.

          • eleitl@lemmy.zip
            link
            fedilink
            English
            arrow-up
            2
            arrow-down
            4
            ·
            1 day ago

            There are authorityless blockchain-backed name registration services. In general, it is important whether you can localize a resource. If you can easily find it, the name doesn’t have to human-readable.

            • Venia Silente@lemmy.dbzer0.com
              link
              fedilink
              English
              arrow-up
              2
              ·
              17 hours ago

              The root (haha) of needing better DNSes is because the ones that are are tied to technofascists and their ilk: techbros, nazis, psycopaths. So using something with blockchain sounds quite missing the point.

              • eleitl@lemmy.zip
                link
                fedilink
                English
                arrow-up
                1
                ·
                11 hours ago

                You do understand that a P2P proof of work backed global store is just infrastructure? And as egalitarian as DNS servers? And it doesn’t have the storage/compute footprint of a full bitcoin node.

                The space of human-readable names is quite small, so proof of work is needed to protect it from being flooded. An alternative is to have your servers have names to be or derived from their public keys, or dissolve content from its location. Which brings its own problems.

            • WhyJiffie@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              4
              ·
              23 hours ago

              if its not human readable, how will people know its the place they want to go to? I don’t think bookmarked onionsites is a particularly good idea

              • eleitl@lemmy.zip
                link
                fedilink
                English
                arrow-up
                1
                ·
                10 hours ago

                In order to find content, we used to have webrings, directory services, and then search engines. Most people don’t enter URLs by hand.

      • IpsumLauren@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        24 hours ago

        That would be just a nuisance until a new certificate is generated with another vendor (possibly not for free, but cheap enough).

      • pdl@social.tchncs.de
        link
        fedilink
        arrow-up
        1
        arrow-down
        5
        ·
        1 day ago

        @Sibbo Of course. Actually, there are 200 million active certificates issued by Letsencrypt. Revoking them, 200 million websites would be down. 200 million websites all over the world, including US. I don’t think this is a realistic scenario.
        If you are worried about that, you should avoid any software developed in US. You should avoid any software which itself or its sources are hosted in US. Mastodon is available on Github, this is Microsoft. US authorities may force Github to shutdown or infiltrate the hosted sources with spyware.

    • WhyJiffie@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      2
      ·
      24 hours ago

      Actually the problem is that they are too widespread. if something happened, and they started creating fake certificates, for outside force or otherwise, they can’t just be blocked because literally half of the internet or more breaks. what’s worse, if browser vendors trued that, people would be downgrading their browser to the last version accepting it, and become exposed to publicly revealed security vulnerabilities. not all because its a bit complicated, but enough would do to have it cause an even greater problem.

      • Possibly linux@lemmy.zip
        link
        fedilink
        English
        arrow-up
        2
        ·
        23 hours ago

        You do make a good point. However, Let’s encrypt is run by the IRSG which is a non profit focused on improving internet security. They are the ones who are pushing for shorter certificate lifetimes among other things.