🚨 Let’s Encrypt at risk from Trump cuts to OTF: “Let’s Encrypt received around $800,000 in funding from the OTF”
Dear @EUCommission, get your heads out of your arses and let’s find @letsencrypt €1M/year (a rounding error in EU finances) and have them move to the EU.
If Let’s Encrypt is fucked, the web is fucked, and the Small Web is fucked too. So how about we don’t let that happen, yeah?
(In the meanwhile, if the Let’s Encrypt folks want to make a point about how essential they are, it might be an idea to refuse certificates to republican politicians. See how they like their donation systems breaking in real time…)
CC @nlnet @NGIZero@mastodon.xyz
#USA #fascism #OpenTechFund #LetsEncrypt #SSL #TLS #encryption #EU #web #tech #SmallWeb #SmallTech mastodon.social/@publictorsten…
publictorsten (@publictorsten@mastodon.social)
Wenn Let’s Encrypt plötzlich nicht mehr klappt, wird das halbe Internet aus Zertifikatsfehlern bestehen. https://www.heise.de/news/Nach-Trump-Dekret-Kampf-um-US-Foerdermittel-fuer-Tor-F-Droid-und-Let-s-Encrypt-10328226.htmlMastodon
reshared this
Alexandre Dulaunoy
in reply to Aral Balkan • • •The main problem is the bureaucracy associated for this. Another issue is the ownership control of the organisation (DEP Cybersecurity), the organisation needs to be controlled by EU citizen and located in EU.
@EUCommission @letsencrypt @nlnet
Aral Balkan
in reply to Alexandre Dulaunoy • • •Alexandre Dulaunoy
in reply to Aral Balkan • • •I really would like to share your optimism too.
If I can help in some ways, let me know. I was tracking the RFA budget withdraw and wondering how long OTF can survive without the funding.
@EUCommission @letsencrypt @nlnet
Jens Finkhäuser
in reply to Alexandre Dulaunoy • • •@a We don't need to move Let's Encrypt to the EU. We need to run a EU-based equivalent, and make it so that the infrastructure they run is easily replicated.
As this development clearly demonstrates, Let's Encrypt is a single point of failure. It was never a good idea. It was just a less bad idea than others.
And no, that's absolutely not suggesting they didn't do great work. This is about designing for resilience.
@EUCommission @letsencrypt @nlnet
Aral Balkan
in reply to Jens Finkhäuser • • •@jens @a @letsencrypt Agree. mastodon.ar.al/@aral/114228345…
Aral Balkan
2025-03-26 10:50:21
Job
in reply to Aral Balkan • • •Jeroen van Tol 🍋
in reply to Aral Balkan • • •Aral Balkan
in reply to Jeroen van Tol 🍋 • • •adison verlice
in reply to Aral Balkan • • •they can't. that'd completely go against their values.
this is like asking them to refuse letsencrypt in Russia, they can't. it's an automated certificate system, they can't just prevent the issuing certificates simply because of their party.
even big websites, like the national security agency, and even whitehouse.gov use letsencrypt as well, so it wouldn't be a good sign for anyone.
adison verlice
in reply to Aral Balkan • • •Aral Balkan
Unknown parent • • •adison verlice
in reply to Aral Balkan • • •google trust services also issues automated I believe.
so simply doing that to letsencrypt wouldn't exactly, hurt, politicians. they have money we don't, so issuing digicert, sectigo or even entrust is something they can absolutely do
BenBen
in reply to Aral Balkan • • •Aral Balkan
in reply to BenBen • • •Stefan Ritter
in reply to Aral Balkan • • •Tom
in reply to Aral Balkan • • •GitHub - tdelmas/Let-s-Clone: How to spread Certificates Authorities like Let's Encrypt
GitHubAral Balkan reshared this.
Aral Balkan
in reply to Tom • • •Nice + yep, we could have an EU-based provider and regulate so that browsers must accept them.
And have it work with OpenNIC so we can decouple domain names from the artificial scarcity of the commercial ICAAN.
Tom
in reply to Tom • • •Imposing Sanctions on the International Criminal Court – The White House
The White HouseAral Balkan
in reply to Tom • • •Joachim Ziebs
in reply to Aral Balkan • • •josemanuel
in reply to Aral Balkan • • •I'm not a big fan of Let's Encrypt. I'd rather have the @EUCommission fund real grassroots efforts like @cacert
@letsencrypt @nlnet
Aral Balkan
in reply to josemanuel • • •Saupreiss #Präparat500
in reply to Aral Balkan • • •LE is not the only Provider of free ACME-Issued certificates and some of the alternatives are even based in the EU.
@EUCommission @letsencrypt @nlnet
Aral Balkan
in reply to Saupreiss #Präparat500 • • •@letsencrypt These folks? They seem very commercial. What’s to stop them offering the free certs tomorrow? There’s value in having a noncommercial EU alternative funded with taxpayer money.
buypass.com/products/tls-ssl-c…
Buy Norwegian SSL certificates
Buypass.comSaupreiss #Präparat500
in reply to Aral Balkan • • •ZeroSSL is also around (Austrian company).
But yes, indeed: They’re Both commercial, so not complete replacements. Still better than a monoculture under US jurisdiction.
@EUCommission @letsencrypt @nlnet
Aral Balkan
in reply to Saupreiss #Präparat500 • • •Saupreiss #Präparat500
in reply to Aral Balkan • • •Of course. And with commercial, I envy rather things like Cooperatives, a Model that I believe we all should be looking into when it comes to European Clouds.
(Not without tech examples; the German NIC is for example organized like that.)
en.wikipedia.org/wiki/Cooperat…
@EUCommission @letsencrypt @nlnet
autonomous association of persons or organizations
Contributors to Wikimedia projects (Wikimedia Foundation, Inc.)Gharbeia, Ⓐ
in reply to Aral Balkan • • •Haven't they been acquired by a Canadian company?
Jørn
in reply to Aral Balkan • • •@letsencrypt @dalias Last time I checked, every public CA must log in the CT log, and they must at least log into Google’s log.
So if Google refuses your log entry, doesn’t matter if your CA is European, the certificate won’t be valid.
EU had an initiative for European CA, with eIDAS, but instead of improving it we were just very much against it. We get the future we voted for.
blog.mozilla.org/en/security/m…
Mozilla and the EFF publish letter about the danger of Article 45.2
Eric Rescorla (The Mozilla Blog)Momo
in reply to Aral Balkan • • •Let's Encrypt states they are protecting 550M websites with their certificates. Imagine everyone would donate 1 cent per certificate per year. Yeah I know, payment processor fees, but hear me out: If Let's Encrypt would end up with 1 cent per certificate... this would mean 5.5 million Dollars per year. For each one of us it's just a few cents plus fees. But for them it would be about 7 times the amount they are endangered to loose now.
Yes, the EU could chip in for the US...
But so can we.
@EUCommission @letsencrypt @nlnet @dickenhobelix
Alan
in reply to Aral Balkan • • •@letsencrypt
EU really needs to take charge here. Let's Encrypt is essential.
Achim provides a bit more context about this move and the dubious legalities of cutting off OTF here:
eupolicy.social/@achimkla/1142…
Unfortunately it seems a number of Small Web/FOSS projects are affected by this.
Achim Klabunde
2025-03-23 13:24:53
Guill.Jones, Honorary Canadian
in reply to Aral Balkan • • •en.m.wikipedia.org/wiki/Open_T…
American non-profit corporation
Contributors to Wikimedia projects (Wikimedia Foundation, Inc.)darq
in reply to Aral Balkan • • •zerossl.com/letsencrypt-altern…
Just saying
Yeah it would suck but it wouldn't be the end
Let's Encrypt Alternative - ZeroSSL
zerossl.comdarq
in reply to Aral Balkan • • •Klaus Frank
in reply to Aral Balkan • • •We already have multiple European alternatives to @letsencrypt
We have ZeroSSL (Austria) and Buypass Go SSL (Norway).
So no problem here.
#LetsEncrypt
𝚜𝚎𝚕𝚎𝚊
in reply to Aral Balkan • • •We need CACert more than ever now
cacert.org/
Welcome to CAcert.org
www.cacert.orgmotofix
in reply to Aral Balkan • • •After Trump's decree: fight for US funding for Tor, F-Droid and Let's Encrypt
Sven Festag (heise online)Farooq | فاروق
in reply to Aral Balkan • • •These happenings affected us too. @delta could not get a fund from OTF, causing disturbances in DC's development.
Alli
in reply to Aral Balkan • • •@kimvsparrentak
Something to bring on the table?
Martin Frost
in reply to Aral Balkan • • •European ACME SSL certificate providers | European Alternatives
European AlternativesAral Balkan
in reply to Martin Frost • • •Martin Frost
in reply to Aral Balkan • • •Aral Balkan
Unknown parent • • •Aral Balkan
Unknown parent • • •@opalfrost @letsencrypt The thread’s broken. This was meant to be a reply to the four freedoms post?
Let’s Encrypr runs Boulder, released under MPL: github.com/letsencrypt/boulder
Afaik, everything they do is released under an open source license.
GitHub - letsencrypt/boulder: An ACME-based certificate authority, written in Go.
GitHubchrysn
in reply to Aral Balkan • • •Why move? They publish their tools, and the legal framework needs to be done again anyway. Let's set up a parallel one here.
There are 13 DNS root servers, I think we should have at least two free public certificate authorities. (Or, dun'no, maybe one per continent if the others want to do it too).
🐧DaveNull🐧 ☣️pResident Evil☣
in reply to Aral Balkan • • •"But what about funding IA-based innovation" (technofascism)…
EU probably doesn't give a flying fuck about small web…
@EUCommission @letsencrypt @nlnet
Aral Balkan
in reply to 🐧DaveNull🐧 ☣️pResident Evil☣ • • •🐧DaveNull🐧 ☣️pResident Evil☣
in reply to Aral Balkan • • •I wasn't even being sarcastic.
Giving a shitton of public money to technofascists 'because insert some bullshit about Artificial Stupidity" (according to people who don't know shit about computers but suddently decided "IA is the future/wijl improve everything cause marketing people said so") is actually one of the EU goals…
ec.europa.eu/commission/pressc…
@EUCommission @letsencrypt @nlnet
EU launches InvestAI initiative to mobilise €200 billion of investment in artificial intelligence
European Commission - European CommissionKevin Karhan
in reply to Aral Balkan • • •call me weird but the developments of @letsencrypt vs. @cacert shows everything wrong with the way #SSL works.
We would've had a superior alternative to #LetsEncrypt if #GAFAMs weren't able or even allowed to cockblock #CACert by refusing to import it's ROOT-CA, whilst every commercial #CA gets their keys imported, no matter how shit they are or that they are essentially a hostile state actor!
Aral Balkan
in reply to Kevin Karhan • • •Paul Campbell
in reply to Aral Balkan • • •acme_ca https://acme.zerossl.com/v2/DV90
to myCaddyfile
. Should be just as simple for other servers.Aral Balkan
in reply to Paul Campbell • • •