I know that I can simply make my own private certificate authority that only I and my family trust. But is there some public provider like letsencrypt that is in a free-er part of the world than the US?

  • thericofactor@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    31
    arrow-down
    3
    ·
    2 days ago

    That the U.S. government can arbitrarily take down websites by revoking certificates issued by let’s encrypt? How obvious can it be? I wondered the same thing as OP months ago. We need european alternatives. I think there are some, have some bookmarked somewhere.

        • Passerby6497@lemmy.world
          link
          fedilink
          English
          arrow-up
          7
          arrow-down
          1
          ·
          1 day ago

          Most browsers don’t, hence my calling revocation a joke.

          So many in this thread are up in arms about something the majority of browsers don’t care about and have actively ignored for as long as I can recall

            • Passerby6497@lemmy.world
              link
              fedilink
              English
              arrow-up
              1
              ·
              1 day ago

              It may only be the desktop version, most mobile browsers aren’t as feature complete as their desktop counterparts.

              But, given Google ripped revocation checking out of chromium, I wouldn’t be surprised if they nerfed it in Android too…

      • T4V0@lemmy.pt
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 day ago

        Orion browser (maybe safari?) on iOS detected the revoked certificate, and asked me to confirm before accessing the website while warning about the dangers.

        • Passerby6497@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          edit-2
          1 day ago

          Does regular safari show the same prompt? Afaik, browsers on iOS are safari reskins, so I’m curious if they added his cert in directly again, or if the onion browser actually follows standards the os browser doesn’t.

          • T4V0@lemmy.pt
            link
            fedilink
            English
            arrow-up
            2
            ·
            1 day ago

            Yes, but safari doesn’t even let me ignore the warning, it has a explanation in detail, and only allows closing the website.

              • T4V0@lemmy.pt
                link
                fedilink
                English
                arrow-up
                2
                ·
                edit-2
                22 hours ago

                Maybe there’s a special case for local subnets?

                Here’s what shows up for me (in portuguese):

                Safari browser invalid certificate warning page.

                Clicking on more details, only allows me to check the certificate:

                Safari browser detailed information for invalid certificate warning.

                Here’s the translated details:

                Safari warns you when a website has an invalid certificate. This can happen if an attacker has compromised your connection. For your protection, you cannot visit this site. You can check later to see if the problem has been solved. You can also contact the site owner to report this error.

                To learn more, you can see the certificate.

                Said certificate:

                iOS invalid certificate information.

                Edit: on the latest iOS version (27) btw.

                • dogdeanafternoon@lemmy.ca
                  link
                  fedilink
                  English
                  arrow-up
                  2
                  ·
                  20 hours ago

                  Thanks for the proof! I stand corrected! I see basically the same but after the view link there is another think that bypasses it.

                  Must be difference between expired vs compromised cert.