This seems like the kind of thing that the USA will explicitly grant an exception to.

It is clearly bad if the whole of Iran gets their own CA infrastructure which the NSA can't as easily spy on.

They could stand up their own version of Let's Encrypt with less than 20 people and $5M/year. It is inevitable. Let's Encrypt had a budget of $3.6M and 13 employees as of 2019 [1], but I don't have recent funding and staff figures as of this comment (replies with context welcome!). Probably spread the cost across the BRICS to make it US sanction resistant.

[1] https://news.ycombinator.com/item?id=24085559 (citations)

It’s not merely about setting up a CA. The CA certificates would have to be added to the trust stores of every operating system, browser, framework, and application, creating a sea of security risks for the public. It’s an isolated, privacy-invasive process.

Do you not believe the rest of the world will not move in this direction to decouple from the US? If not, you should consider it is more likely than before. Countries will mandate it if they want it done badly enough, and there is enough open source to own the entire stack (OS, browser, CLIs, etc). It is simply a matter of will, resources, and time, in that order. "You eat an elephant one bite at a time" as the saying goes. Can it be done? Yes. Will it be done? We can only watch to find out.

https://news.ycombinator.com/item?id=49225112 (citations)

(sysadmin/network admin/devops/infra engineer a lifetime ago, mostly familiar with what bootstrapping this looks like)

> Do you not believe the rest of the world will not move in this direction to decouple from the US?

Sure, but that will require more than 20 people, 5 million USD and the sole will of the Iranian government.

Different contexts. It is cheap to build your own Let's Encrypt, it takes more time and effort for the world to decouple. Both can be true.

> The CA certificates would have to be added to the trust stores of every operating system, browser, framework, and application, creating a sea of security risks for the public

Finaly one that acknowledges...

Sure they can, but very importantly, so far the US has not forced them to for extremely good reasons.

As just one example, you can take a guess as to whether such a CA will support certificate transparency...

Yeah now the NSA only contains the code of the browsers Iranians use, right down to the os and even firmware. Clearly a big loss ...

I guess you could say a loss is a loss ...