Iranian banks' SSL certificates are being revoked due to OFAC sanctions

82 pointsposted 7 hours ago
by misano

155 Comments

pibaker

6 hours ago

Sanctions on Iran are justified. But I worry this kind of action will just lead to the eventual rise of an alternative tech ecosystem in the long term, probably led by china and Russia. It will be bad for us, bad for people living under those regimes, but good for the regimes themselves because they will have the fullest control over their technology, without having to compromise with the West.

Another example of why maximalist political hostility can be counterproductive. Leave an olive branch in sight, and you may work towards a mutually beneficial resolution, like the previous Iran nuclear deals. If push your opponent into a corner, then don't get upset when they jump over the wall into the wild where you can't catch them anymore. See also Chinese chips and AI.

LudwigNagasena

6 hours ago

Russia recently moved to its own SSL certificates due to sanctions. Now you cannot use a bank without allowing the government to MITM you.

sam_lowry_

6 hours ago

Can't US government MITM all of us, even with certificate transparency logs?

throwaway89201

an hour ago

They can only do that through an "SSL added and removed here ;-)"-like 'cooperation' and not through passive listening because with forward secrecy a certificate key doesn't secure the transport encryption directly. They could actively MITM outside the perimeter of the target by issuing a new certificate, but that would show up on CT logs.

hiciu

3 hours ago

some of us voluntarily mitm ourselves via cloudflare ;)

theginger

5 hours ago

Not without leaving potential proof that it happened behind

SSLy

4 hours ago

metadata is juicier anyway.

hammock

6 hours ago

> Sanctions on Iran are justified

For what?

pibaker

6 hours ago

For human rights violations at home and sponsorship of extremism aboard.

I also believe many of our current "allies" in the region should face similar sanctions in case you are wondering.

swat535

5 hours ago

> I also believe many of our current "allies" in the region should face similar sanctions in case you are wondering.

Interesting take, coming from a nation that has caused:

- 210,296 violent civilian deaths in IRAQ

- 500,000 civilians killed om Japan

- 70,000 civilians killed in Vietnam

- 46,000 civilians killed in Afghanistan

- 3,000 civilians killed in IRAN

- Threatened to exterminate Persians civilization, blown up bridges, killed children and destroyed civilian infrastructure

I think United States should be sanctioned.

ericmay

5 hours ago

> - Threatened to exterminate Persians civilization, blown up bridges, killed children and destroyed civilian infrastructure

Iran threatens that all the time "Death to America" so if they don't like someone saying it back to them maybe they should stop?

If you want to make these kinds of body count claims, well for starters Iran killed over 30,000 of its own people recently (who knows maybe they've killed tens of thousands more over the years).

Iran also made the Iraq war worse by funding insurgents, which opposed the US and the government of Iraq (which is doing much better now as a country than it was under Saddam anyway) so they are partially responsible for some of those deaths.

But let's continue with this logic. While we're at it why don't we sanction China? Common estimates suggest 10s of millions dead from the Great Leap Forward (no it's not any different when you kill your own people, arguably much worse). Dramatic repression in places like Hong Kong, and continuing to threaten democratic Taiwan.

Why aren't you clamoring to sanction China if you're going to bring up Japan and Vietnam? Well that's because your logic is unsound, never mind the continued hyper-focus on being critical of the United States only. Maybe all of these deaths are actually on the hands of Europeans who partitioned these gulf states in the first place. Why was France in Vietnam? Why was the UN in Korea?

fzn7

4 hours ago

Your reply is pure, distilled whataboutism.

ericmay

3 hours ago

The premise of the OP is whataboutism.

But you can take a step back and ask, well, what's the guiding framework here?

Is it arbitrarily picking certain time periods to make a point? Why do we go back to "Japan" and World War II when Japan started the war and was massacring and colonizing people throughout east Asia?

Why wasn't Germany mentioned in the body count? Dresden is a popular one that comes to mind.

Why do we only focus on lives lost? Maybe America saved 10,000,000 Chinese from Japanese occupation so on balance we're saving lives?

Hikikomori

2 hours ago

Yeah lets take a step back to 1953 when the British overthrew their government for wanting more profits from their oil. This lead directly to the revolution in 79, in the meantime the western "aligned" leader had suppressed all opposition except religions leaders so they were able to take over.

Now you know why they shout death to America. Would you also like to know that al qaeda didn't just hate american "freedom"?

ericmay

2 hours ago

Why stop there? Why not go back to when the Greeks made Darius mad and started the Greco-Persian wars?

If you want the Iranian people to engage in a forever war against the West, this is the kind of attitude you must hold.

“Some arbitrary injustice done by dead people forever justifies us to do whatever we want” isn’t a viable political or culturally progressive route to go down. Vietnam got over it. Why can’t Iran? Do they need a nuclear bomb to get over it? Will they stop hanging gay people, helping Russia, and providing militia support to destabilize Arab countries once they get what they want (whatever that is)? What date or specific thing do they need?

Can anyone say?

Of course not. Because totalitarian regimes always have to obsess over past injustices, perceived or real, to drum up support for the regime so that it can continue to hold power against the best interests of their people. It masks their own failures, like Tehran running out of water because their government spent all their money bombing innocent people.

user

5 hours ago

[deleted]

FactolSarin

6 hours ago

I don't disagree, but that's not why they're being sanctioned

applfanboysbgon

6 hours ago

The US itself should be sanctioned by your listed metric.

hammock

6 hours ago

Isn’t that what they say the tariffs are?

edoceo

6 hours ago

USA sanctioned themselves?

adrian_b

5 hours ago

Sanctions for human rights violations would be justified only if they would be applied equally towards any country where certain human rights violations happen.

Unfortunately, USA has never applied any sanctions equally against countries with equivalent human rights violations, which proves that "human rights violations" have never been the true reason for those sanctions, but only a cover story.

When I was young and I was listening the US propaganda emitted through "Voice of America", I actually believed a good part of it. Unfortunately, history has proven that practically none of it was true and many listeners like myself were too naive if they believed any of it.

Moreover, the so-called "sanctions" of USA are not true sanctions. True sanctions would identify a precise behavior of the sanctioned country that is the cause of the sanctions and USA would promise that the sanctions would be terminated whenever the sanctioned country would stop those actions. Those would be true "sanctions" because they would have a chance to alter the behavior of the sanctioned countries.

As it is now, no sanctioned country would change anything in what they do, even when they are "sanctioned", because they know very well that the official reasons for the sanctions are not the true reasons and whatever they do about "human rights violations" and the like will not influence in any way whether the sanctions will be terminated or not.

Many of the official reasons for various US sanctions are so ridiculous that I wonder how the US politicians are able to utter them with a straight face.

For instance, there are many Chinese companies which are sanctioned because they might provide services or products for the Chinese Army or for the Chinese government.

??? Of course they do that. Any US company that makes anything of value will also provide services or products to the US military and government. The same will do any company in any country for their military and government.

In reality, the sanctioned Chinese companies have always been those which make consumer products that provided too much competition for US companies, like those that make DRAM modules and SSDs, so we have to thank the US sanctions for the huge price increases that have stolen money from people all over the world.

Regarding "sponsorship of extremism abroad", that is also questionable. Iran has supported various organizations which want to fight against Israel, but Israel has remained at war since its creation and the reason why they are still at war and they have never made peace with their enemies is because this was the wish of the Israeli government, who prefers to be at war than at peace.

There have existed opportunities of peace for Israel, but whenever there were chances for peace the forces within Israel that are against peace have prevented it, e.g. by the murder of the prime-minister Yitzhak Rabin in 1995 or by the sabotage of the prime-minister Ehud Barak by Ariel Sharon and Likud in 2000.

As long as Israel will not implement an acceptable closure for the events from its creation and for their consequences, there will be people willing to fight against it, and because Israel has a crushing military superiority, the only form of fight are the "terrorist" actions. The existence of the "terrorists" is a choice made by Israel, more precisely by certain elites from Israel, for whom the continuous state of never-ending war has been extremely profitable.

I have worked for many years in Israel and more than 90% of the people that I encountered there were very nice people, but I have also seen some very bad people, who of course, like in any country, were concentrated in the government and in the management of companies, so they had much more influence than the majority.

I pitied a lot my Israeli co-workers, because they were exploited to a degree that would not be possible in most countries. Only USA might come close with its "employment at will", which gives disproportionate power to the employer.

In Israel, employees have to work much harder than in most other countries and nobody could protest against that, because that would be considered as unpatriotic, i.e. the priority for everybody is to work as hard as possible, to maintain the technological and military superiority of Israel, for fear that otherwise their neighbors would come and cut their throats. This kind of work discipline is of course very desirable for the owners of the companies, so for them it is good that Israel is permanently at war and under the menace of "terrorist" attacks.

The term "terrorist" is just an euphemism for enemies with which Israel is at war and with which it desires no peace. Moreover, even if there have been a lot of more or less innocent Israeli victims (but all have chosen willingly to be part of a military conflict), Israel has always succeeded to kill a much greater number of "terrorists" or persons related to them or persons who just happened to be close to them. Israel does not want to make any concessions for peace, because it reckons that peace will be obtained eventually, over the dead bodies of all enemies, but there is no hurry for that, because war is good for the economy.

In these circumstances, applying "sanctions" against countries who "support terrorists" has no legal basis, but it is just joining the conflict between Israel and its enemies, as an ally of Israel.

Of course any sovereign country may do this, but they should present it as what it is, i.e. as taking sides in a conflict, and not as something which has any legal or ethical reasons.

Razengan

5 hours ago

> For human rights violations at home

reddit.com/r/2020PoliceBrutality

reddit.com/r/PoliceBrutality

Oh yeah sorry this is "wHaTaBoUtIsM" so it makes our shit okay

misano

5 hours ago

The difference is that in America, they don't torture and imprison the mother of a murder victim for an Instagram post on charges of disturbing national security and public unrest.

Razengan

4 hours ago

> The difference is that

we eat eggs from the little end and they eat from the big end.

_djo_

5 hours ago

Human rights violations, violations of the Non-Proliferation Treaty, violations of related UNSC Resolutions, sponsorship of terrorism, and many others.

We can wholeheartedly disagree with the US's war on Iran without pretending Iran is a 'good' international actor. It's a rogue state and has been for decades.

crabbone

5 hours ago

This is not a good question to ask. It's not for what. It's to prevent what.

Even if you don't care about how Iran treats its own population, you should care about how it treats others because one day it might be you.

Iran's ideology is expansionalist. They want to export their ideas far and wide. While also physically suppressing their opponents.

Since the emergence of two global superpowers after WW2, most armed conflicts were, essentially, between those two. Directly or indirectly. If the two could find a peaceful solution, the world at large had a good day. And for a while it seemed like we might be left with just one superpower, and so no conflicts at all. Only policing.

The whole "multipolar" spiel you might hear from powers that challenge this policing is what is going to result in a long and bloody struggle for world domination. It won't be like the world wars we remember, where most of the world had to choose one of the two sides. It will be a quagmire of more local conflicts with very volatile alliances and a lot more casualties overall. More like Italian city states.

It's necessary to police Iran and similar bad countries because if their challenge of the power monopoly succeeds, the world will be hurled into anarchy equipped with very deadly weapons...

hammock

an hour ago

Your comment is so bizarre I don’t know quite how to respond and I’m left wondering what your news feed looks like.

There is only one country in the Middle East with an aggressive expansionist mentality, and it’s not Iran.

And what’s with the superpower commentary, you neglected to connect it to Iran and are you saying Russia is bigger than China?

jst1fthsdys

an hour ago

It's what uncritically consuming propaganda does to a person. A whole world view and belief system that has no relation to reality.

iamnothere

3 hours ago

Multipolarity is inevitable. You can’t forcefully hold most of the world’s population down, especially when you already shipped off your manufacturing capacity to earn a few bucks.

As always, the question for the declining hegemon is whether a new order can arise peacefully or not. The UK managed to go peacefully in the end, but only after two brutal and deadly world wars sapped them of their remaining strength. Still, their acquiescence allowed them to retain an outsized seat at the table.

China doesn’t seem interested in becoming a unipolar hegemon, at least based on public statements and openly published policy/position papers, so perhaps they have learned that it’s bad to be the hegemon from watching both the UK and the US take it on the chin. Rather than the Yuan becoming the default international currency, it’s possible that Keynes’s Bancor (or something like it) may finally replace the notion of a singular reserve currency, which always fails in predictable ways.

fragmede

an hour ago

How can something "always fail" if it's never been tried? Negativity much?

iamnothere

an hour ago

Maybe I wasn’t clear, I mean that singular, nation-state issued (but internationally held) reserve currencies always fail, whether they are backed by “hard” currency or not. Keynes’s idea is an attempt to solve the problem, and as you mentioned it has not been tested.

ImHereToVote

6 hours ago

For retaliating against they president being assassinated and their country attacked. This is strictly against the rules based order.

stickfigure

6 hours ago

It's not "their" president, Iranians didn't elect him. Khomeini was a religious extremist who only months ago presided over the murder of ten thousand protesters and we should shed not one tear.

misano

6 hours ago

Because the fascist mullahs’ regime wants the entire world to act according to its wishes. We’re lucky that North Korea doesn’t control any straits.

krunck

5 hours ago

s/mullah/American/

yassermzh

3 hours ago

the whole point of economic sanctions, as besset himself said, is to make people frustrated in order to create chaos and uprisings, people fighting each other, having a failed nation, and ready to be targeted by US/israel to turn it into all other israel neighbors. since israel existence is only through killing and destruction. stealing its oil like Venezuela is another goal. human rights is just an excuse. how many millions US has killed in west asia you think? good news is that nothing last forever. one day it gets back to you.

fitman339

2 hours ago

> all other israel neighbors

Israel’s neighbors Jordan and Egypt have made peace with Israel and have had no issues since then.

You may have been misled by anti-Israel propaganda.

nharziro

6 hours ago

They are not justified in the least bit.

lxgr

6 hours ago

Much worse, this will greatly improve their position with regards to wiretapping their own citizens.

Depending on who you are, Western CAs can come with some availability problems, but thanks to certificate transparency, you don't even have to trust the CA if you mostly care about security. Take a wild guess as to whether an Iranian CA will support that...

d0mine

6 hours ago

Is the implication that those who impose these sanctions can MITM anybody in the world except for countries under sanctions (which have to use their own root CAs)?

ericmay

6 hours ago

> But I worry this kind of action will just lead to the eventual rise of an alternative tech ecosystem in the long term, probably led by china and Russia. It will be bad for us, bad for people living under those regimes, but good for the regimes themselves because they will have the fullest control over their technology, without having to compromise with the West.

I'm not sure that isolating Iran in particular has much of an effect because countries don't want to be in Russia's orbit, China's orbit is Only Good for China, and so aside from a European-only/led system the best option would still be the current state/system.

The best solution to all of these problems is for Iran to just behave like pretty much all other countries, but in lieu of that and in lieu of us having a desire to really go to war in Iran, we're just going to have to take actions like this because we can't have this regime opposed to us and western values and pursuing nuclear weapons (prior to, during, and after JCPOA) but then enjoying the benefits of the American-led financial system.

If Iran, China, North Korea, and Russia want to get together and create their own crappy Intranet that nobody uses, well, more power to them. Hope they have fun.

> If push your opponent into a corner, then don't get upset when they jump over the wall into the wild where you can't catch them anymore. See also Chinese chips and AI.

I think this is a gross mischaracterization of the evolution of these arrangements. There's a lot of nuance here, but the United States helped get China into the WTO based on the premise that they'd liberalize and then what happened? State-directed investment, banning of competitor products, subsidized over-capacity to deindustrialize other countries, artificially cheap currency to boost exports. Russia? They were part of the The NATO-Russia Founding Act and then decided they'd rather do war and stuff. Iran? Won't stop pursuing nuclear weapons for no reason (among other things), so now their economy is going to tank. So it's really the opposite. Even when you think about the JCPOA, let's say it wasn't torn up. Why was/is Iran still funding militant groups that are destabilizing other countries in the region? The west, not just the US mind you, did its damned best to include these specific countries into the western rules-based order, allowed gross injustices and breaches of good conduct, and still tried only to now itself be backed into a corner (Iran, Russia invading Ukraine, Chinese economic destruction) and has to finally respond.

As a civilization, and yes that includes folks in the EU even if you are mad at the current president, we need to stop assuming we're the problem or we're the bad guys by default and start holding other countries to account.

pibaker

5 hours ago

> As a civilization, and yes that includes folks in the EU even if you are mad at the current president, we need to stop assuming we're the problem or we're the bad guys by default and start holding other countries to account.

I remember your handle, ericmay, because you have been showing up in almost every thread about the tariffs or Iran and following this logic. Something Must Be Done, therefore Anything That Is Being Done Is Good. How dare you question if the Thing Being Done is actually against our interests? Do you not feel the warm fuzzy feeling of Something Being Done?

It's a frankly childish view of politics where virtue is all you need no matter the outcome. Time to grow up.

ericmay

5 hours ago

I'm highly interested in the topic, and folks continue to write and respond to things that I disagree with. That's why you see my posts. This site (and life) shouldn't be an echo chamber.

nekusar

6 hours ago

> China's orbit is Only Good for China

BRICS begs to dffer.

BRICS = Brazil, Russia, India, China, South Africa.

ericmay

5 hours ago

> BRICS begs to dffer.

Why would that matter?

MadrasTh0rn

6 hours ago

Justified but extremely short sighted

egorfine

6 hours ago

> Sanctions on Iran are justified

The main problem with sanctions is that it's the wrong people on the receiving end. Russian oligarchs and military businessmen have exactly zero problems managing their money, while ordinary people who flew russia into the EU - they face unsurmountable piles of unsolvable problems due to sanctions.

pibaker

6 hours ago

No disagreement. It is very unfortunate that our policymakers seem to like the spectacle hurting the average person who happened to have been born in the wrong country more than going after the ones actually holding power.

egorfine

6 hours ago

The average person is available, helpless and most importantly - their suffering is clearly visible to the voters.

2asg-qwwt

5 hours ago

Yes, Russian oligarchs use London and Dubai for laundering. Ironically, Iranians elites use Dubai, too while launching occasional missiles at UAE.

The only thing that would work is bribing the Iranian military (perhaps the non-IRGC part) like they did in Syria. Exile Iranians of course won't fight but they rather talk and demand that others fight.

tclover

5 hours ago

Then USA should also sanction USA, or Israel at least.

2OEH8eoCRo0

6 hours ago

Maybe it will force competition. One of America's best strengths is competitive dynamism which we have gotten away from.

londons_explore

6 hours ago

This seems like the kind of thing that the USA will explicitly grant an exception to.

It is clearly bad if the whole of Iran gets their own CA infrastructure which the NSA can't as easily spy on.

toomuchtodo

6 hours ago

They could stand up their own version of Let's Encrypt with less than 20 people and $5M/year. It is inevitable. Let's Encrypt had a budget of $3.6M and 13 employees as of 2019 [1], but I don't have recent funding and staff figures as of this comment (replies with context welcome!). Probably spread the cost across the BRICS to make it US sanction resistant.

[1] https://news.ycombinator.com/item?id=24085559 (citations)

misano

6 hours ago

It’s not merely about setting up a CA. The CA certificates would have to be added to the trust stores of every operating system, browser, framework, and application, creating a sea of security risks for the public. It’s an isolated, privacy-invasive process.

toomuchtodo

6 hours ago

Do you not believe the rest of the world will not move in this direction to decouple from the US? If not, you should consider it is more likely than before. Countries will mandate it if they want it done badly enough, and there is enough open source to own the entire stack (OS, browser, CLIs, etc). It is simply a matter of will, resources, and time, in that order. "You eat an elephant one bite at a time" as the saying goes. Can it be done? Yes. Will it be done? We can only watch to find out.

https://news.ycombinator.com/item?id=49225112 (citations)

(sysadmin/network admin/devops/infra engineer a lifetime ago, mostly familiar with what bootstrapping this looks like)

lxgr

6 hours ago

Sure they can, but very importantly, so far the US has not forced them to for extremely good reasons.

As just one example, you can take a guess as to whether such a CA will support certificate transparency...

spwa4

5 hours ago

Yeah now the NSA only contains the code of the browsers Iranians use, right down to the os and even firmware. Clearly a big loss ...

I guess you could say a loss is a loss ...

lxgr

6 hours ago

Forcing their customers to install government-affiliated alternative CAs, in turn allowing the government to spy on its citizens more easily via mis-issued certs? Great, that'll show them.

misano

6 hours ago

This was the most anti-colonialist move America had ever made, but you can’t keep tiptoeing around your enemy forever.

Waterluvian

6 hours ago

As an amateur student of history and a professional watcher of television, I think one possible conclusion I've drawn is that the happy state is tiptoeing around your enemy forever. Or rather, tiptoeing with your enemy. That there is no "and the enemy was defeated and we returned to the Shire and the galaxy is finally at peace." Quietness, even if it's not called peace, is the virtuous state we should endeavour to preserve.

user

an hour ago

[deleted]

lxgr

6 hours ago

> [...] you can’t keep tiptoeing around your enemy forever.

If it doesn't cost the US anything and is strategically in their favor (via weakening an opponent), I really don't see why they couldn't have.

On top of that, it'll make others find alternatives quickly, as has already been happening with e.g. payments and other critical infrastructures. What an incredible waste of soft power built over decades.

throw0101d

6 hours ago

> Forcing their customers to install government-affiliated alternative CAs, in turn allowing the government to spy on its citizens more easily via mis-issued certs?

How's the support for X.509 "Name Constraints" these days:

* https://datatracker.ietf.org/doc/html/rfc5280#section-4.2.1....

Would restricting it to only dot-ir domains be a mitigation?

* https://en.wikipedia.org/wiki/.ir

Hizonner

6 hours ago

Why would the Iranian government put such a constraint in its own root certificate?

lxgr

6 hours ago

I guess now would be a great time for browsers/OSes to ship a "trust this CA, but only for this TLD/list of domains" feature.

zzo38computer

5 hours ago

One possible alternative might be to add the ability for user configuration to substitute one certificate for another one (both will need the same public key and subject name, but the substitute will not be self-signed (since you do not have the private key)), and to use the data in the substitute certificate instead of the original. If the name constraints extension is implemented, then it would make this and other things possible. Since the substitute certificate will be considered trusted, it is not necessary for the substitute certificate to have a signature (if it does (e.g. because you got it from somewhere else instead of making it yourself), then the signature can be ignored), nor is it necessary for the substitute certificate to be issued by anyone (this applies even if it is the end certificate being substituted).

I think some servers do not send a copy of the root certificate to the client. In this case, what I described above might already be possible even if that feature has not already been added to existing implementations, as long as it does not require the installed certificate to be self-signed.

mcpherrinm

5 hours ago

This exists in Firefox at least, but I don’t think it’s easily exposed in the UI

AtNightWeCode

5 hours ago

It would be simple today to abolish the use of CAs but it just a big cargo biz that makes money on nothing as usual based on peoples incompetence. For 99% of all sites today security would be handled better without CAs. People simply don't understand how it works.

lxgr

3 hours ago

All that was true until fairly recently. Today, you can get certificates for free and there’s more transparency than ever thanks to CT.

What would you suggest as an alternative? TOFU?

I could see that for local applications (e.g. making mDNS/.local and private IP certs TOFU capable by default would be amazing, and maybe even for some explicit hobbyist public TLDs?), but I don’t think I’d love it for my bank or email provider.

throw0101d

5 hours ago

> It would be simple today to abolish the use of CAs […]

The main technical way I know of doing this would be by putting TLS public keys in DNS (DANE, RFC 6698), but then you have to make sure that DNS packets are not fiddled with, so you need to bring in DNSSEC.

lxgr

3 hours ago

Exactly, and in some ways, DNS is even more centralized. At least there’s a choice of CAs independent of TLDs.

Hizonner

3 hours ago

That's a false concern, because the names the CAs are certifying are still DNS names. If your TLD reasssigns your DNS name out from under you, or even if your TLD starts returning false data on only selected queries, the CAs will be happy to issue a cert to the new holder.

It would be great to have a widely-recognizable pseudodomain out there where the names were key hashes. It would actually graft really easily into DNSSEC. The zone format doesn't have to change at all; you just declare that if the KSK hash matches the domain label under this specific TLD, you don't need to check upstream of that. Then you add a P2P protocol for getting the actual data, and start slowly pushing that protocol down the resolver tree to incrementally decentralize everything.

Hizonner

6 hours ago

20 years ago would have been a great time for that one.

AtNightWeCode

6 hours ago

The whole point with a CA is that you have a neutral third party participant. Kinda broken no matter how you look at it. Especially in this case.

egorfine

6 hours ago

Just like in russia and exactly because of sanctions. Excellent job, dear west.

zzo38computer

4 hours ago

It doesn't load for me, but I have read the other comments.

There is the problem of TLS and X.509 being used with centralized authorities like this, even though it is not inherent to TLS nor to X.509 (although they were designed to be used in this way). In some circumstances, you can get a copy of the certificate (which might be self-signed) from somewhere else and then check that it matches in this circumstances. In other circumstances there are other things that can be done (e.g. TOFU, which has a different set of problems, but also has advantages in a different set of circumstances). What the security requirements are will depend on the circumstances, which can also depend on the user's intentions; they should not have to depend on a centralized authority.

(There is the issue that a single X.509 certificate cannot have multiple issuers, though. There is also the issue that X.509 certificates cannot contain unsigned extensions (they could be added after the signature, but an implementation might check for additional fields after the signature and reject a certificate that has any). Although an alternative schema can be made (I have done so), it would not work with the existing protocols.)

128471599

6 hours ago

It is a reminder to go back to cash, ATMs and machines where you can enter you transactions instead of using the Internet.

There is no reason to give money to US middlemen for everything you do.

The whole of the EU should do this, too. I stopped using Internet banking after my bank moved from SMS Tan to hardware Tan generator (one of which didn't work) to forced mobile app. No thanks.

lxgr

6 hours ago

How exactly do I use cash for online payments?

missedthecue

6 hours ago

Commonly available in Latin America

www.pagoefectivo.la

You select 'pay in cash' in the online checkout, walk to your neighborhood convenience mart, and they scan a QR code (or you give them a code if you don't have a smartphone) linked to your checkout session. It rings up the total, and you pay the clerk in cash. Once you hand over the cash and the clerk hits confirm in their POS system, the online store is notified instantly that you have paid, and your order moves directly into processing or shipping.

lxgr

5 hours ago

That's great for people that don't have any online-capable payment method, but I'd consider it a huge step backwards for those that do and are comfortable using it.

missedthecue

an hour ago

Naturally, it is one of several payment options at checkout. Never the only option.

user

6 hours ago

[deleted]

gonzalohm

6 hours ago

The problem is not online banking. The problem is the banks we use.

Accounting cash is extremely complicated and whether you like it or not, you will be forced to do an online transaction at some point.

Are you going to be wiring money across the country to buy stuff?

Instead of going back we should stop centralizing everything.

We are centralizing the internet with Cloudfare. We are centralizing mobile compute with Android/Apple

I don't want to be dependent on any of those platforms to access my bank

jadbox

6 hours ago

Also: please use a credit union and use mutually-owned insurance agencies. As a general statement, you'll be in way better hands.

jimbob45

6 hours ago

Wait but...if you use an ATM, you're going to be hit by ATM (read: middleman) fees every single time. Also, you massively increase your risk of getting hit by identity theft via compromised ATM.

lxgr

6 hours ago

> you're going to be hit by ATM (read: middleman) fees every single time.

This is highly country specific. In many countries, (at least domestic) ATM withdrawals are still free.

> you massively increase your risk of getting hit by identity theft via compromised ATM.

What exactly does a compromised ATM do in terms of identity theft that a POS terminal can't do? Both can read your card, which today is not a big problem anymore, and certainly not yours or your bank's.

OutOfHere

6 hours ago

Cryptocurrency actually works and doesn't involve US middlemen under governmental oppression. It's a fact.

Also, they stopped capitalizing the "i" in "internet" some time ago. Wake up from the year 2000 already.

Toynbeeidea

6 hours ago

It works to buy darknet drugs, sure. Wake me up when I can go to the grocery store and buy some peaches. "Don't worry, cashier-bro, the transaction will only take 20 minutes to go through, trust me!"

lxgr

6 hours ago

There are so many valid criticisms of crypto, but transaction confirmation time has been solved a long time ago.

OutOfHere

6 hours ago

It does work for groceries, although not at a physical store, because the store is controlled by government henchmen wrt to their payments. Fwiw, one can trivially by an Amazon gift card using cryptocurrency, using which one can then pay for online groceries.

As for transaction confirmation times, there are cryptocurrencies in common use that confirm nearly immediately. The lack of your knowledge shows.

Toynbeeidea

6 hours ago

Sure, good plan. I'll just walk into thr local CVS to buy a gift card and... oh, wait, no. Exact same issue.

OutOfHere

6 hours ago

It is a working means. The gift card is exclusively bought online. It's not usable in store anyway since there is no physical card. There is no issue with online purchases.

user

5 hours ago

[deleted]

LoganDark

5 hours ago

Nothing stops a physical store from accepting cryptocurrency, unless they need to also make agreements with the payment card networks.

CookieCrisp

6 hours ago

Hahaha, that’s a good joke

OutOfHere

6 hours ago

It's not a joke. It's 100% true. People tend to be extremely uneducated wrt crypto, also favoring to dwell in their ignorance.

gonzalohm

6 hours ago

I may speak from ignorance, but why do SSL certificates depend on centralized CA?

If I'm an entity such as a bank, I should be able to sign my own certificate and provide the public keys to my clients which then can use it to both encrypt communications and to make sure you are talking with the entity you want to talk to. Am I missing anything?

coldpie

6 hours ago

> provide the public keys to my clients

How does this part happen? How does the client know that the entity providing them with that public key is who they claim to be?

gonzalohm

5 hours ago

You visit the bank in person and the bank gives you the keys in a flash drive, QR code, printed paper, ... Then you go home and install the keys

mahboi

an hour ago

People don't really know how to install SSL certs, it's intentionally not easy especially on phones, and it's not clear that what they're installing only affects the bank. But yeah, the industry could make this semi-easy if there were a real need.

coldpie

5 hours ago

So, you're right that this does work in theory, but it obviously doesn't scale, right? We can't have every person physically go to every storefront they want to purchase something from and then drive home with a USB stick. What if I in Minnesota want to buy something from Florida or France?

The role CAs play is to be a trusted identity verifier so we don't have to have millions of people driving around to do key exchanges in person.

gonzalohm

4 hours ago

That makes sense. The downside is that now if said CA has some interests in whether to re-issue a certificate or not, we have a problem. Imagine that Cloudfare decides you are a bot and doesn't allow you to visit pages. You are going to have a problem because a lot of websites use it

I think the idea of a CA is good but it should be distributed somehow

coldpie

an hour ago

Yeah, of course. Every solution has pros and cons, you gotta settle on the best one for the world you live in.

CAs are quite distributed already. You probably have a couple dozen or even a hundred different root CAs installed right now, and you can install whatever ones you like if necessary.

sam_lowry_

6 hours ago

How do I know what certificates come with my browser?

coldpie

5 hours ago

You can go look at them. In Firefox, head to "about:certificate" and click the Authorities tab.

gonzalohm

5 hours ago

You could also install a hypothetical bank certificate that way

megous

6 hours ago

they can fetch the key or its hash from DNS. it's not like the current system is that much more involved. current system is basically a third party signed cache of such ownership claims validated based on ability of someone to modify DNS records.

All caches are just functionally useless layers..., so that's that.

coldpie

5 hours ago

How do I know that the DNS record is owned by the entity they are claiming to be? CAs have nothing to do with caching.

megous

5 hours ago

You don't know that even with DNS validated certificates. There's no separate "entity" claim other than "anybody with DNS record modification rights for a given domain".

You can give out the same claim over DNS directly without any extra third party involvement in the form of CA.

coldpie

4 hours ago

Huh, wow. I kind of thought the whole point of CAs was to do identity verification. It they have dropped that entirely, what is the point?

mirashii

5 hours ago

DNS can be trivially MITM'd as well, it's certainly not a secure mechanism for distributing keys.

megous

5 hours ago

You just taken down the whole business of dns validated CA issued certificates. Go claim your bounty. :)

zzo38computer

5 hours ago

I think it would be a good idea. TLS and X.509 would work better that way. Actually, both sides should have a certificate (the bank might issue a certificate to the customer).

It won't do for all circumstances (as some other comments mention), but when it is possible, it would be a good idea.

ValdikSS

6 hours ago

The same applies to Russian banks. Russian banks have switched to internal Ministry of Digital Development CA which is not trusted in common browsers.

https://crt.sh/?id=22899279066 (Revoked: privilegeWithdrawn)

cestith

6 hours ago

This seems like a bad idea.

badatnames

6 hours ago

Utterly moronic. We support the freedom of the Iranian people by forcing them to install a local government root CA in every browser. I mean at this rate they won't even have to buy their monitoring tech from China any more, just an old PC and a late 90s tarball of Squid

Avamander

6 hours ago

What's stopping them from using a CA from any other sphere of influence though?

I feel like not being able to use US CAs is just a cheap excuse to enact what they've wanted for a while. Same in Russia.

Analemma_

6 hours ago

I mean, we very clearly do not support the freedom of the Iranian people. We deposed their democratically-elected leader in the 50s in favor of someone more pliable to Western interests, and when they rose up against their current government early in the year we went "Good luck! We're with you all the way!", then stood there when 30,000 of them were massacred. The well-being of ordinary Iranians has never been part of the calculus, so there's not really any actual hypocrisy.

mahboi

30 minutes ago

It's not impossible that the US got rid of the last shah too. He had turned against western interests at some point.

throw310822

6 hours ago

Nobody gives a damn about the freedom of the Iranian people. They are a problem for Israel [1], so the US bombs them. The rest is just post-hoc justification.

[1] Note that every civilised country should be a problem for Israel- but Iran is the only one that actually dares opposing it.

misano

6 hours ago

These remarks are antisemitic. The people of Iran aren’t seeking a fight against imperialism. We want to live like ordinary people in the U.S., Europe, and Israel, and be allied with them. The fascist Shiite regime has taken everyone hostage, and it’s leading us toward a collective suicide.

mahboi

41 minutes ago

I don't care what Iran, Iranians, or Israel wants. I'm American. The fact is, Israel somehow pushed our executive branch to start a war over there.

throw310822

6 hours ago

> These remarks are antisemitic

So it would be fine if they were against any other country engaged in genocide, but not against Israel because it's Jewish? Is that your defense of Israel?

> We want to live like ordinary people in the U.S., Europe, and Israel, and be allied with them

You want to be allied with a genocidal state and the country that has forced you into poverty for the last decades?

catch310688

5 hours ago

In 2026 in Gaza there were about 1000 deaths - many of them combatants officially mourned by Hamas and Islamic Jihad.

In the same year:

Iran killed at-least 5000 civilian protesters.

Russia killed around 1,800 Ukrainian civilians.

5000 were killed in Sudan. 3000 in Haiti.

You are fine will all that (or will deny it), because you only care when the Jews are involved.

megous

5 hours ago

People don't have memory capacity of mayflies. That's your primary mistaken assumption.

jMyles

6 hours ago

It's bizarre that there isn't yet a total separation of certificate-and-state.

borschtplease

6 hours ago

One more technical challenge. The whole ssl infrastructure is incompatible with a state current planet moves forward to.

zoobab

6 hours ago

It's not as if SSL critics warned about this ponzi pyramid, prone to censorship.

cyberax

6 hours ago

This is super-dumb. The same thing is happening with Russian banks.

Their answer? They're now asking users to install root certs from the Russian ministry of communications. So it can now MITM all the encrypted traffic in Russia.

Avamander

6 hours ago

China and many others run their own CAs, I'd presume Russians could use those if they wanted?

throw-the-towel

5 hours ago

Russians didn't want to use those, until the West made it inevitable.

Avamander

2 hours ago

And why is that?

It's not that hard to find a CA in a more aligned regime.

Rolling your own MITM CA as a replacement just looks like something that was waiting for an excuse.

cyberax

an hour ago

Violating the OFCOM restrictions will result in losing access to VISA/MC payments. No company wants this.

axus

6 hours ago

Dumb for the US: if US were currently MITM with certs copied by its agencies, US won't be able to do that for Iranian / Russian certs.

misano

6 hours ago

SSL MITM also requires hijacking the network and redirecting the traffic.

Daishiman

6 hours ago

So now that SSL certificates are being weaponized it now becomes a matter of national security for any country to have their own independent CA infra.

Another win for the US.

bradly

6 hours ago

It already was. Stuxnet used trusted, signed Windows drivers to destroy Iran’s centrifuges back in 2010 and afaik we still don’t know exactly how the attackers did this.

bigbuppo

6 hours ago

Better yet, don't rely on a central trust authority that can't be trusted.

fhejfnenjdcn

6 hours ago

[flagged]

azinman2

6 hours ago

How could you possibly label the Iranian war so far a genocide?

sdsd

6 hours ago

The word genocide is currently undergoing semantic bleaching (https://www.merriam-webster.com/grammar/very-actually-and-ot...). It's too powerful a word for propagandists/activists to resist beating it into oblivion in the service of their causes.

fhejfnenjdcn

6 hours ago

Targeting civilians, hospitals, and food distribution networks is just normal warfare! Israel has a right to defend itself! Their land was promised to us thousands of years ago, and they have no right living on it!

fhejfnenjdcn

6 hours ago

"Time for bridge and powerplant day! A whole civilization dies tonight!"

azinman2

6 hours ago

That’s fair as a very troubling threat. So far it hasn’t materialized. Seems to be the boy who cried wolf.

MadrasTh0rn

6 hours ago

Trump Vance Johnson Elon and Thiel are removing US institutions globally by force

Trump is intentionally playing into Chinese, Russian Noth Korean, Iranian hands

They must be impeached/removed regardless of intent

Nobody voted for this