I know that I can simply make my own private certificate authority that only I and my family trust. But is there some public provider like letsencrypt that is in a free-er part of the world than the US?

  • pdl@social.tchncs.de
    link
    fedilink
    arrow-up
    0
    ·
    4 days ago

    @Sibbo I do not see any problem with Letsencrypt. Any CA which is widely trusted has to follow the same rules. This rules are set up by the CA Browser Forum. Which metadata does LE collect? My server’s IP address, domain and subdomain, mail address. These are logged in the CT logs. Every CA has to log all certificates in a public CT log. Regardless which CA I choose, these data are public. There are not any critical data or metadata that LE can collect.

    • WhyJiffie@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      0
      ·
      4 days ago

      Actually the problem is that they are too widespread. if something happened, and they started creating fake certificates, for outside force or otherwise, they can’t just be blocked because literally half of the internet or more breaks. what’s worse, if browser vendors trued that, people would be downgrading their browser to the last version accepting it, and become exposed to publicly revealed security vulnerabilities. not all because its a bit complicated, but enough would do to have it cause an even greater problem.

      • Possibly linux@lemmy.zip
        link
        fedilink
        English
        arrow-up
        0
        arrow-down
        1
        ·
        4 days ago

        You do make a good point. However, Let’s encrypt is run by the IRSG which is a non profit focused on improving internet security. They are the ones who are pushing for shorter certificate lifetimes among other things.

    • Sibbo@sopuli.xyzOP
      link
      fedilink
      English
      arrow-up
      0
      ·
      4 days ago

      Letsencrypt can be directly forced to revoke certificates by the US. Organisations outside of the US are less vulnerable against that.

      • slazer2au@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        4 days ago

        And ICAAN can hand your domain over to US law enforcement regardless of the TLD and your register.

        Is that also part of your decision tree?