Bonum Certa Men Certa

Let's Encrypt is Garbage, Albeit It's Disguised as 'Free' Privacy

Earlier this year (an unexplained incident, still): Techrights Urges Readers to Ask the Linux Foundation's Let's Encrypt (Backed by Companies That Give the NSA Back Doors) Some Hard But Legitimate Questions

Let's Encrypt address

Let's Encrypt LF connection

Let's Encrypt and LF

The signature for Let's Encrypt

Source: The latest-available IRS filing. See the IRS filing in full [PDF] for a lot more.

Summary: The 'Linux' Foundation in 'privacy' clothing is more like a monopoly disguised as non-profit while taking money from monopolies (to do their biddings in the most surveillance-intensive country in the entire world)

Yesterday we asserted (and then explained why) today's Linux Foundation -- or LF for short (one way to avoid the misleading name) -- works for monopolies, not Linux. It uses the "Linux" brand to market itself.



One thing that came from LF is a CA that issues loads and loads of certificates which expire after 3 months.

"The aspect nobody wishes to talk about is that the Let's Encrypt monopoly is reinforcing monopoly and monopolies (Let's Encrypt itself is fast becoming a monopoly and it helps large companies further monpolise and thus centralise the Web)."Look who backs this. Look who funds this. Look where the code is hosted (proprietary Microsoft GitHub). Even the site itself is outsourced to proprietary Microsoft GitHub...

Let's Encrypt is partly funded by Microsoft/GitHub and various other unsavoury companies notorious for their back doors (we can name more than a handful).

So much for security, considering how close Microsoft and the NSA have long been.

But that's not the point. That's not the most important thing.

The aspect nobody wishes to talk about is that the Let's Encrypt monopoly is reinforcing monopoly and monopolies (Let's Encrypt itself is fast becoming a monopoly and it helps large companies further monpolise and thus centralise the Web).

It may sound peculiar at first, but considering the FIDO situation we've seen it elsewhere as well. Much power can be gained -- sometimes money follows -- by making oneself the de facto standard. Then abuse and chaos may ensue, as monopolies need not compete and appease/please anyboby.

Yesterday the Let's Encrypt site published a blog post which bears a rather meaningless if not misleading headline (because a suitable headline would likely upset people right from the get-go).

Put in simple terms, sites that adopt HTTPS with the 'free' (so-called, hence scare quotes) Let's Encrypt will become inaccessible to a lot of visitors. In the name of fake 'privacy', which does nothing about spying at the endpoints (like data sales to brokers). People who think HTTPS 'means privacy' should remind themselves that companies like Facebook -- a Let's Encrypt sponsor -- use HTTPS and it does nothing to prevent Facebook from assaulting privacy like Microsoft assaults love itself. HTTPS helps secure things not at the endpoints but during transit.

LWN's headline was vastly more informative than the waffle from Let's Encrypt and it said:

Fallout from upcoming Let's Encrypt certificate changes



As described in this Let's Encrypt blog entry, certificates issued by Let's Encrypt will soon be signed solely by that organization's own root certificate, which is accepted by all modern browsers. There is one little catch, though: versions of Android prior to 7.1.1 (released in late 2016) do not recognize that certificate and will start throwing errors. "Currently, 66.2% of Android devices are running version 7.1 or above. The remaining 33.8% of Android devices will eventually start getting certificate errors when users visit sites that have a Let’s Encrypt certificate. In our communications with large integrators, we have found that this represents around 1-5% of traffic to their sites." There appears to be little to be done about this problem other than to encourage owners of older Android devices to install Firefox.


It quotes part of what Jacob Hoffman-Andrews said, followed by: "Hopefully these numbers will be lower by the time DST Root X3 expires next year, but the change may not be very significant."

Next year?

Let's Encrypt moneyJust one year? Hardly anything would change by then. See the comments in LWN. One person said: "Rooting old phones requires erasing them. I'd hazard that the users of those phones would be cautious about that (data loss), as opposed to current phones (loss of access to baking and game apps)."

They're pushing people to buy new so-called 'phones' (spying devices). And further down it says: "Plausibly deniable way to send users up the upgrade treadmill. C'mon, Android users! Throw away your devices, again!"

Why would anyone wish to turn away users in the name of fake 'privacy' or dubious levels of confidentiality? If the Let's Encrypt folks somehow hand over keys to the government (e.g. under Trump NSLs), then what good is it really? It not only helps monopolies but also militant empires.

Let's Encrypt may claim to be a liberating and democratising force, but that's assuming it does what it says on the tin.

An encrypted systems specialist elaborated on this. "Trust should only exist between the provider of data and the consumer," he said to us. "Any other third party introduced into the system is an attack against privacy, security, and autonomy. Don't let quacks convince you otherwise."

"The discussion should lead the user to devices and browsers that let them have a local list of public keys they trust. That's the basic function of TLS anyways. The concept of a CA needs to be binned altogether. You can still trust certs yourself on Firefox. Just ignore the browser warnings."

He added that "what [we] should tell users is to start trusting self-signed certificates in favour of certs provided by CAs. Let's Encrypt is a vehicle for maintaining the trust monopoly. It's free so people blindly just use it, without realising they're just further entrenching the trust monopoly. Anyone can generate TLS certs with openssl (or even more secure libressl; libressl is by the OpenBSD team. It's the best TLS software around. There's nothing magical about TLS certificates. If someone has something like WordPress, you can just use libressl to generate your own certs and then put a banner on the top of your info page on your website asking users to trust whichever cert you generated and hasn't expired [and] what we really need in a truly security-and-privacy respecting Web browser is one that rejects all TLS certificates by default and only accepts certs the user agrees to accept. Right now the situation is the opposite of what it should be. Users have monopolised "trust providers" dictate which certs they accept. Kind of how you do when you set up SSH. You block all public keys by default and only allow ones you trust yourself. And you, the user, have full control of your trust system. Delegation of trust mechanisms to third parties is flagrant stupidity in any security system. In summary: right now you, the user, have a dictator ordering you whom you can and cannot trust. This is absurd. Your devices and software shouldn't stop functioning when you want to take back control over your trust. The current system is a dictatorship of CAs forcing people to give up control over their trust (and by extension, their security and privacy). These are abuses against articles 12 and 19 of the Universal Declaration of Human Rights."

Don't forget that Let's Encrypt is US-based and monopolies-backed. They're not a charity, not a nonprofit either. They have motivations that aren't altruistic and we know who pays the salaries (not friends and allies of privacy, sometimes foes of it). They call themselves "[a] nonprofit Certificate Authority providing TLS certificates to 225 million websites." The Linux Foundation also calls itself "nonprofit", but we know that's a lie.

The encrypted systems specialist said he "[had] forgot[ten] to mention one other big point. The fact you can't block CAs in your browser and certain certificates is evidence enough of the malice behind the design and implementation of the web today."

The incidents of March (earlier this year) could be seen as an eye-opener. They never bothered explaining why they had issued millions of bad certificates, which they later revoked; they didn't explain what actually caused this incident and what was done about it.

As a side note, the SELinux project of Red Hat (now IBM) used to issue monthly declarations about no government interventions/involvement. Those stopped years ago. What is it they say about canaries?

"I have never seen any letsencrypt documentation say they have canaries," oiaohm wrote this morning, "and if you know USA law on the matter canaries is basically false. One of the USA encrypted email systems that is shutdown now had canaries and when the NSA with NSL stepped in they were forbid from using them. So their end users knew nothing."

A lot more discussion regarding this issue can be found in tomorrow's IRC logs.

Comments

Recent Techrights' Posts

Legal Attacks on Techrights Have Made Techrights More Popular and More Widely Read
The misogynists will have plenty of work to do this summer
SLAPP Censorship - Part 142 Out of 200: GemText is Not a Webpage, Gemini Protocol is Not the Web, and Capsules Are Not Websites
our intention to appeal (escalate to the Court of Appeal)
What We Said About Red Hat's Fate Under IBM Turned Out to be Right on the Money (That IBM Lacks)
There are no layoffs at IBM
At Clacton by-election Hustings Event Daniel Pocock Says "Social [Control] Media Has Contributed to Some of the Anti Social Behaviour."
No doubt many problems in society are caused or at least amplified/accentuated by this horrible phenomenon
Over at Tux Machines...
GNU/Linux news for the past day
 
Microsoft Uses Slop to Find Defects and Then Uses Slop to Replace Code, What Could Go Wrong?
Botspam is the problem, it's not a constructive approach in any shape or form
analytics.usa.gov: GNU/Linux Up Some More This Week
Days ago it said 6.4%, now it's up to 6.8%
RA-pocalypse: IBM Tells Workers "Taking a Hike" is Their "Next Step" ('Voluntary' Layoffs), Now It Prepares to Sack Lots of Contractors
There definitely is something going on
Kai Stephens (Barkley Walsh) & British Democrats in Clacton by-election hustings
Reprinted with permission from Daniel Pocock
Daniel Pocock 'Punching' Nazis in the UK
The so-called "cult" of so-called "Debianism" was left with nothing but massive legal bills
Microsoft: Our August 2026 Layoffs Are Not Layoffs Because... Reasons
That's like IBM making "spin-offs", then pretending that no layoffs are happening
Links 07/08/2026: UMG and Anthropic in Trouble Over Copyright Infringements Sold as "Training" (Slop)
Links for the day
Links 07/08/2026: "BMW Is Showing Commercials On Their Car's Dash Screens And They Want You To Think It's A Treat", Software Patents on Drones
Links for the day
IRC Networks Show No Signs of Going Away, IRC Enters Its 39th Year
That IRC daemons are still actively developed and patched in summer of 2026 (over 38 years after IRC was born) says a lot about IRC's importance
Social [Control] Media Needs to Die
I am a bit shocked to recall that I wasted a lot of time on it
Some Malware is Legal Because It's Made and Distributed by Politically-Connected GAFAM
In reality, the security non-experts 'championed' (and salaried) by GAFAM are anti-security people who advocate back doors
The GNU/Linux Anniversary is Next Month, Not This Month
It'll turn 43
IBM Insiders Explain Why IBM is in Very Serious Trouble
Will IBM last long enough for any "quantum" deliverables to become a reality?
The Register MS Took Money From Broadcom to Publish Fake 'News' With "AI" Mentioned 35 Times
not legitimate or authentic journalism.
GNU/Linux Approaching 20% in Georgia (the Country)
Usage of GNU/Linux was near 0%, as measured by statCounter, several years ago
IRC Proceedings: Thursday, August 06, 2026
IRC logs for Thursday, August 06, 2026
Gemini Links 07/08/2026: Radio Amateurism, Summer Updates, and Programming "Taste"
Links for the day
Links 06/08/2026: Billboard Chart Contaminated by Slop Plagiarists, Sheinbaum Blasts Social Control Media
Links for the day
A Long Break and What's Coming Next Year
Some time next year we definitely plan to show how the EFF failed women, failed bloggers, and basically prioritised GAFAM
Daniel Pocock on a "metre-long ballot paper"
The Debian "cult" (as he calls them collectively) is simply jealous of him
Links 06/08/2026: Disney and Fentanylware (TikTok) Deal, "Hearing Aids Shenanigans"
Links for the day
IBM Mass Layoffs Began Yesterday, They're Sold as "Voluntary", the "Offer" Runs for Two Weeks (Last Day August 19th 2026)
IBM will self-detonate while using contractual agreements to force people to smile
Start of September 2026 'Voluntary' Mass Layoffs at IBM, Start of October Red Hat Employees Forced Into the 'Bloodbath' (After Collapse of IBM's Shares)
Red Hat is in trouble
Many GNU/Linux PCs Are Not Connected to the Net or Don't Use the Web
Saying GNU/Linux user-agents are just "bots" (Microsoft Lunduke and other Microsofters say this) is like asserting that the Twin Towers fell not because of two giant planes but because of explosives
They Call Occupations "Professions" Because the "Pro" Means Something
If you want to find tech news online
New Conference Paper (Science of Cyber Security) Credits RMS With Delaying Passwords
When it comes to passwords, RMS was "right"
Removing Gender Barriers in Computer Science
It is not that "women aren't good at maths"
In Brunei, GNU/Linux Approaches International Average of 8.5%
a sharp rise from 0% to about 7.5% happened in a few years
15% of IBM Staff Marked for Layoffs ("RAs"), the Workers' Objective is to Find Another Employer and Leave
"That's not a workforce, that's a waiting room."
Maintenance to be Completed Tonight (IPv6)
Notice how, after 25+ years, we're still not fully adopting IPv6, we're only about 50% there
A Data Centres Hub Puts Everyone at Risk, Especially People Who Live Near Them at Times of War/s
Spoiler: Datacentres are military targets, they attract missiles, some with nuclear warheads
GAFAM Mass Layoffs and Mountains (Trillions of Dollars in 'Secret' or 'Off-the-Ledger') Debt
GAFAM is having layoffs this month
August 2026 Microsoft Layoffs Confirmed by Staff This Week
It's hard to assess how many are impacted but signed an NDA, preventing them from speaking about what really happened
analytics.usa.gov Says 7% of Sessions Come From GNU/Linux and ChromeOS. If ~40% (Mobile) Get Omitted, It's More Like 11%.
In desktops and in laptops GNU/Linux has become a big player
IBM Cannot Survive for Much Longer, There Are Limits to RAs and Offshoring, IBM Now Asks Workers to Quit
IBM is in very serious trouble
SLAPP Censorship - Part 141 Out of 200: Brett Wilson LLP Failed to Learn From the Mistakes of the European Patent Office (EPO)
my solicitor, David Allen Green, put them in their place
Texts of the Claims From Balabhadra (Alex) Graveley and Matthew J. Garrett Almost Identical, I am Suing for Abuse of Process
Half a decade ago Balabhadra (Alex) Graveley from Microsoft and GNOME was arrested for strangulation in Texas
Gemini Links 06/08/2026: "Eat That Frog", Mutt Terminal Email Guide, and BASICODE
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, August 05, 2026
IRC logs for Wednesday, August 05, 2026
Big Announcement Tomorrow
Stay tuned...
GNU/Linux Seen Exceeding 10% in Antigua and Barbuda
In Antigua And Barbuda, what's seen this month is not far from the average
Gemini Links 05/08/2026: Family Room, Smoke, and Alarm clocks
Links for the day
The Establishment, Oxford, Google & Debian artificial intelligence conspiracies
Reprinted with permission from Daniel Pocock
SLAPP Censorship - Part 140 Out of 200: You Become What You Eat, Your Clients Become You
In 2024 Brett Wilson LLP failed to heed a decade-old warning
Debian losses in Switzerland hidden until after DPL election debate
Reprinted with permission from Daniel Pocock
Links 05/08/2026: Microsoft's (XBox's) "Devastating July" and "Never Write With" Slop, Says New York Times
Links for the day
Gemini Links 05/08/2026: No to Slop, Dangers of Clown Computing, and Reducing Internet Usage
Links for the day
The Register MS Takes Money From NVIDIA and HP to Promote Their Ponzi Scheme, "AI", in a Fake 'Article' That Says "AI" 42 Times
"The media"... selling us scams for profit
Fertility app privacy, Britain's teenage pregnancies & faith based schooling
Reprinted with permission from Daniel Pocock
In Chile, GNU/Linux Approaches 4%
Let's see if it can exceed 5% by year's end
No Room for Misogyny and Incels in Free Software
How can we ever trust men whose own family and their own partners cannot trust?
How to Dehumanise a Triple National
Don't be easily incited against those who sacrifice a lot to inform the public of suppressed topics
In El Salvador, ChromeOS and GNU/Linux Now Measured at Around 12%
signs of gradual and steady adoption of GNU/Linux
Software in the Public Interest (SPI) Starts Spending Big Money in an Effort to Resist Lawsuit From Daniel Pocock
They've lost over half a million dollars in the latest 3 years
The Establishment, Cambridge, Steve McIntyre & Debian suicide cluster
Reprinted with permission from Daniel Pocock
Links 05/08/2026: Internet Archive Harmed by Slop Bot, "EBay And Former Execs Agree to Pay $56 Million For Trying to ‘Crush’ a Journalist"
Links for the day
Luxembourg and Software Freedom
Luxembourg's adoption of GNU/Linux has quite consistently been higher than the European average
The Free Software Foundation (FSF) Web Site is Online, GNU's Site Having Issues (Ongoing Issues)
We hope they can rectify the issues with the GNU Web site
Freedom Includes the Liberty to Disagree (and be Listened to, Not Censored)
Freedom is our collective strength
Tanzania: GNU/Linux Now Seen on 8% on Desktops/Laptops (User Clients)
numbers have more than doubled
IBM CEO Says IBM Won't be Bankrupt by 2028 or 2029 (When He Reaches Retirement Age)
IBM has no path to survival
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, August 04, 2026
IRC logs for Tuesday, August 04, 2026
Gemini Links 05/08/2026: Being Good, Tildeverse and Tilde.pink, Games
Links for the day