Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • This seems like a poor choice. Missing the point of sanctions, possible long term negative second order effects.
  • It's bizarre that there isn't yet a total separation of certificate-and-state.
  • Utterly moronic. We support the freedom of the Iranian people by forcing them to install a local government root CA in every browser. I mean at this rate they won't even have to buy their monitoring tech from China any more, just an old PC and a late 90s tarball of Squid
  • Nobody gives a damn about the freedom of the Iranian people. They are a problem for Israel [1], so the US bombs them. The rest is just post-hoc justification.

    [1] Note that every civilised country should be a problem for Israel- but Iran is the only one that actually dares opposing it.

  • I mean, we very clearly do not support the freedom of the Iranian people. We deposed their democratically-elected leader in the 50s in favor of someone more pliable to Western interests, and when they rose up against their current government early in the year we went "Good luck! We're with you all the way!", then stood there when 30,000 of them were massacred. The well-being of ordinary Iranians has never been part of the calculus, so there's not really any actual hypocrisy.
  • What's stopping them from using a CA from any other sphere of influence though?

    I feel like not being able to use US CAs is just a cheap excuse to enact what they've wanted for a while. Same in Russia.

  • This seems like a bad idea.
  • SSl certificates for websites probably should be out of scope for sanctions
  • I may speak from ignorance, but why do SSL certificates depend on centralized CA?

    If I'm an entity such as a bank, I should be able to sign my own certificate and provide the public keys to my clients which then can use it to both encrypt communications and to make sure you are talking with the entity you want to talk to. Am I missing anything?

  • So you're OK with your bank website being invisible until people visit in person to get the certificates?
  • I think it would be a good idea. TLS and X.509 would work better that way. Actually, both sides should have a certificate (the bank might issue a certificate to the customer).

    It won't do for all circumstances (as some other comments mention), but when it is possible, it would be a good idea.

  • > provide the public keys to my clients

    How does this part happen? How does the client know that the entity providing them with that public key is who they claim to be?

  • It doesn't load for me, but I have read the other comments.

    There is the problem of TLS and X.509 being used with centralized authorities like this, even though it is not inherent to TLS nor to X.509 (although they were designed to be used in this way). In some circumstances, you can get a copy of the certificate (which might be self-signed) from somewhere else and then check that it matches in this circumstances. In other circumstances there are other things that can be done (e.g. TOFU, which has a different set of problems, but also has advantages in a different set of circumstances). What the security requirements are will depend on the circumstances, which can also depend on the user's intentions; they should not have to depend on a centralized authority.

    (There is the issue that a single X.509 certificate cannot have multiple issuers, though. There is also the issue that X.509 certificates cannot contain unsigned extensions (they could be added after the signature, but an implementation might check for additional fields after the signature and reject a certificate that has any). Although an alternative schema can be made (I have done so), it would not work with the existing protocols.)

  • The same applies to Russian banks. Russian banks have switched to internal Ministry of Digital Development CA which is not trusted in common browsers.

    https://crt.sh/?id=22899279066 (Revoked: privilegeWithdrawn)

  • It is a reminder to go back to cash, ATMs and machines where you can enter you transactions instead of using the Internet.

    There is no reason to give money to US middlemen for everything you do.

    The whole of the EU should do this, too. I stopped using Internet banking after my bank moved from SMS Tan to hardware Tan generator (one of which didn't work) to forced mobile app. No thanks.

  • Cryptocurrency actually works and doesn't involve US middlemen under governmental oppression. It's a fact.

    Also, they stopped capitalizing the "i" in "internet" some time ago. Wake up from the year 2000 already.

  • Wait but...if you use an ATM, you're going to be hit by ATM (read: middleman) fees every single time. Also, you massively increase your risk of getting hit by identity theft via compromised ATM.
  • Also: please use a credit union and use mutually-owned insurance agencies. As a general statement, you'll be in way better hands.
  • The problem is not online banking. The problem is the banks we use.

    Accounting cash is extremely complicated and whether you like it or not, you will be forced to do an online transaction at some point.

    Are you going to be wiring money across the country to buy stuff?

    Instead of going back we should stop centralizing everything.

    We are centralizing the internet with Cloudfare. We are centralizing mobile compute with Android/Apple

    I don't want to be dependent on any of those platforms to access my bank

  • How exactly do I use cash for online payments?
    by lxgr
  • Forcing their customers to install government-affiliated alternative CAs, in turn allowing the government to spy on its citizens more easily via mis-issued certs? Great, that'll show them.
    by lxgr
  • CAs is the problem. Not who runs them...
  • Just like in russia and exactly because of sanctions. Excellent job, dear west.
  • > Forcing their customers to install government-affiliated alternative CAs, in turn allowing the government to spy on its citizens more easily via mis-issued certs?

    How's the support for X.509 "Name Constraints" these days:

    * https://datatracker.ietf.org/doc/html/rfc5280#section-4.2.1....

    Would restricting it to only dot-ir domains be a mitigation?

    * https://en.wikipedia.org/wiki/.ir

  • This was the most anti-colonialist move America had ever made, but you can’t keep tiptoeing around your enemy forever.
  • This seems like the kind of thing that the USA will explicitly grant an exception to.

    It is clearly bad if the whole of Iran gets their own CA infrastructure which the NSA can't as easily spy on.

  • Yeah now the NSA only contains the code of the browsers Iranians use, right down to the os and even firmware. Clearly a big loss ...

    I guess you could say a loss is a loss ...

  • They could stand up their own version of Let's Encrypt with less than 20 people and $5M/year. It is inevitable. Let's Encrypt had a budget of $3.6M and 13 employees as of 2019 [1], but I don't have recent funding and staff figures as of this comment (replies with context welcome!). Probably spread the cost across the BRICS to make it US sanction resistant.

    [1] https://news.ycombinator.com/item?id=24085559 (citations)

  • Sanctions on Iran are justified. But I worry this kind of action will just lead to the eventual rise of an alternative tech ecosystem in the long term, probably led by china and Russia. It will be bad for us, bad for people living under those regimes, but good for the regimes themselves because they will have the fullest control over their technology, without having to compromise with the West.

    Another example of why maximalist political hostility can be counterproductive. Leave an olive branch in sight, and you may work towards a mutually beneficial resolution, like the previous Iran nuclear deals. If push your opponent into a corner, then don't get upset when they jump over the wall into the wild where you can't catch them anymore. See also Chinese chips and AI.

  • > But I worry this kind of action will just lead to the eventual rise of an alternative tech ecosystem in the long term, probably led by china and Russia. It will be bad for us, bad for people living under those regimes, but good for the regimes themselves because they will have the fullest control over their technology, without having to compromise with the West.

    I'm not sure that isolating Iran in particular has much of an effect because countries don't want to be in Russia's orbit, China's orbit is Only Good for China, and so aside from a European-only/led system the best option would still be the current state/system.

    The best solution to all of these problems is for Iran to just behave like pretty much all other countries, but in lieu of that and in lieu of us having a desire to really go to war in Iran, we're just going to have to take actions like this because we can't have this regime opposed to us and western values and pursuing nuclear weapons (prior to, during, and after JCPOA) but then enjoying the benefits of the American-led financial system.

    If Iran, China, North Korea, and Russia want to get together and create their own crappy Intranet that nobody uses, well, more power to them. Hope they have fun.

    > If push your opponent into a corner, then don't get upset when they jump over the wall into the wild where you can't catch them anymore. See also Chinese chips and AI.

    I think this is a gross mischaracterization of the evolution of these arrangements. There's a lot of nuance here, but the United States helped get China into the WTO based on the premise that they'd liberalize and then what happened? State-directed investment, banning of competitor products, subsidized over-capacity to deindustrialize other countries, artificially cheap currency to boost exports. Russia? They were part of the The NATO-Russia Founding Act and then decided they'd rather do war and stuff. Iran? Won't stop pursuing nuclear weapons for no reason (among other things), so now their economy is going to tank. So it's really the opposite. Even when you think about the JCPOA, let's say it wasn't torn up. Why was/is Iran still funding militant groups that are destabilizing other countries in the region? The west, not just the US mind you, did its damned best to include these specific countries into the western rules-based order, allowed gross injustices and breaches of good conduct, and still tried only to now itself be backed into a corner (Iran, Russia invading Ukraine, Chinese economic destruction) and has to finally respond.

    As a civilization, and yes that includes folks in the EU even if you are mad at the current president, we need to stop assuming we're the problem or we're the bad guys by default and start holding other countries to account.