site banner

Culture War Roundup for the week of August 24, 2026

This weekly roundup thread is intended for all culture war posts. 'Culture war' is vaguely defined, but it basically means controversial issues that fall along set tribal lines. Arguments over culture war issues generate a lot of heat and little light, and few deeply entrenched people ever change their minds. This thread is for voicing opinions and analyzing the state of the discussion while trying to optimize for light over heat.

Optimistically, we think that engaging with people you disagree with is worth your time, and so is being nice! Pessimistically, there are many dynamics that can lead discussions on Culture War topics to become unproductive. There's a human tendency to divide along tribal lines, praising your ingroup and vilifying your outgroup - and if you think you find it easy to criticize your ingroup, then it may be that your outgroup is not who you think it is. Extremists with opposing positions can feed off each other, highlighting each other's worst points to justify their own angry rhetoric, which becomes in turn a new example of bad behavior for the other side to highlight.

We would like to avoid these negative dynamics. Accordingly, we ask that you do not use this thread for waging the Culture War. Examples of waging the Culture War:

  • Shaming.

  • Attempting to 'build consensus' or enforce ideological conformity.

  • Making sweeping generalizations to vilify a group you dislike.

  • Recruiting for a cause.

  • Posting links that could be summarized as 'Boo outgroup!' Basically, if your content is 'Can you believe what Those People did this week?' then you should either refrain from posting, or do some very patient work to contextualize and/or steel-man the relevant viewpoint.

In general, you should argue to understand, not to win. This thread is not territory to be claimed by one group or another; indeed, the aim is to have many different viewpoints represented here. Thus, we also ask that you follow some guidelines:

  • Speak plainly. Avoid sarcasm and mockery. When disagreeing with someone, state your objections explicitly.

  • Be as precise and charitable as you can. Don't paraphrase unflatteringly.

  • Don't imply that someone said something they did not say, even if you think it follows from what they said.

  • Write like everyone is reading and you want them to be included in the discussion.

On an ad hoc basis, the mods will try to compile a list of the best posts/comments from the previous week, posted in Quality Contribution threads and archived at /r/TheThread. You may nominate a comment for this list by clicking on 'report' at the bottom of the post and typing 'Actually a quality contribution' as the report reason.

2
Jump in the discussion.

No email address required.

Is pki the next part of the global internet censorship regime?

In a previous post, we discussed the takedown of a foreign website that violated texas laws. I argued that domain takedowns are unlikely to be used for global censorship. But these days https certificates are becoming nearly obligatory, and the system around them is much more haphazard.

As a sideshow on the iran situation, the pgsa dot ir website is trying to stay up in the face of the sanctions. The website originally had a letsencrypt certificate, but obviously the US was able to get that yanked. After a week, they managed to get their hands on a chinese certificate. But surprisingly, only a few days later, the certificate was revoked, making the https site unviewable on certain browsers. I'm not certain exactly why the chinese issuer revoked it, but it could likely be due to pressure from above.

Unlike the internet, Google, Apple, and Mozilla pretty much control almost every browser in the world. And for an issuer it seems that there are no rules when it comes to having your certificates accepted on those browsers, simply beg and kiss ass to each of them until they decide to let you in the club. This means that anywhere, having an https website happens at the whim of these 3 American companies, and each one pretty much has a veto over the process. It's no wonder that they all go to lengths to put up big warnings and gimp functionality on http websites.

Of course it remains to be seen whether or not this lever of censorship will be used in the future and for what purposes. Can an SF judge order Mozilla to start rejecting certain certificates? Not sure. Right now there's also the escape hatch of simply using http, but browser makers will continue to push more and more invasive warnings about it.

On all of those you can add custom roots and chains. Now whether you would want to put Iranian government root just to visit their sites securely is up to you.

IIRC not all US government-issued certificates are recognized by the default on the listed browsers. At least, I've run into SSL warnings from them before that indicated as such in the past. The reverse you hope would be true too: important systems probably shouldn't need to trust foreign CAs for just any sites.

Also, I think Firefox on most platforms (Windows, most notably) trusts the OS's CA list: Microsoft probably has more sway than Mozilla. The one time I can think of this power was used, it was against Symantec for what seemed at the time (2018) quite reasonable reasons.

Also, I think Firefox on most platforms (Windows, most notably) trusts the OS's CA list ...

As I understand the documentation, it trusts root certs that have been added to the OS by an administrator or user but not those included by Microsoft or Apple.