A question that just popped to my mind, reasonable input/debate welcome around it: "Let"s encrypt is a US based non profit organization, submitted to the "US Cloud Act", how could the EU laws (GDPR) be respected by EU or swiss companies (Proton, others) using "Let's encrypt" to secure the communication privacy, given it can lead way to massive TLS communication hijacks via emissions of website certs for CDN appearing to be the website that client (apps, web browser) communicates with using anonymous TLS.? Even more in this kind of context: https://noyb.eu/en/us-cloud-soon-illegal-trump-punches-first-hole-eu-us-data-deal Any idea anyone? Where am I wrong in this line of thoughts? Why don't they use the EU approved eIDAS qualified certificate authorities (https://eidas.ec.europa.eu/efda/trust-services/browse/eidas/tls) that ensure that the EU laws and GDPR are respected by the CAs? At least EU govs would have a little more control on what could happen to limit interferences? Why are browsers like mozilla not talking about this? I start to wonder if some blocks that did cut the ties with current Internet PKI & DNS infrastructrue to ensure that their people laws are respected by the technical infrastructure are not completely wrong to do so, given the US not going to a free people country direction anymore.
PS: Features like MS recall or CSAM are even more frightening from a personal freedom and corporate security perspective, since they use neural nets to sort the screenshots on laptop and label them for easier retrieval...
.
.
.#nyob #cloudact #TLS #PKI #gdpr