I know that I can simply make my own private certificate authority that only I and my family trust. But is there some public provider like letsencrypt that is in a free-er part of the world than the US?

  • 3abas@lemmy.world
    link
    fedilink
    English
    arrow-up
    12
    ·
    18 days ago

    Fortunately, that’s not how it works.

    The private key is created on your server, not by Let’s encrypt, and it’s never transferred to them. Nobody can decrypt your data.

    Certbot (the official ACME client) is open source, but you’re also welcome to use any other client of your choosing, or make your own. The secrets never leave your server.

    Unless the NSA has working powerful quantum computers that can break public key encryption, that they are successfully hiding from the public, they wouldn’t be able to break let’s encrypt certificates backed public key encryption, the math just doesn’t math. It would still take the most powerful super computers millions of years to break RSA 2048.

    There’s a reason they want to make encryption illegal, instead of just letting us trust it like sheep. Thankfully, we don’t have to trust anyone, it’s all verifiable math.

    • RabbitBBQ@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      13 hours ago

      You’re not understanding Certificate Authorities or what certificate pinning does to stop man in the middle impersonation of firewall traffic. You have no understanding of what the Government is able to do to your devices and internet connection. You don’t have to take my word for it, I don’t care what you think. You just haven’t been a target to understand.