Let's Encrypt’s subscriber agreement changes on Sept 21
letsencrypt.org
letsencrypt.org
The companies for which you want that are probably the companies who don't want you to figure out what changed though, so little luck of that happening
https://support.microsoft.com/en-us/office/compare-and-merge...
(It shows how to also "merge" but you don't have to merge, it will highlight the differences.)
https://docs.google.com/viewer?url=https%3A%2F%2Fletsencrypt...
Agree, now I remember that at least Google is doing it.
TOS: https://policies.google.com/terms/archive/20200331-20220105
Privacy Policy: https://policies.google.com/privacy/archive/20210701-2022021...
The main updates are: we now link to instructions on choosing a revocation reason if you revoke a certificate. This is a requirement for Subscriber Agreements from all Certificate Authorities as of this year. Also, we've removed unneeded capitalization, removed a section that is redundant with our Certificate Policy (CP), and tweaked the wording of the requirement to "assure" control of your private key so it matches the Baseline Requirements (BRs).
Yes and that is really stupid, especially from a group of people who are otherwise very clever.
It’s really quite annoying that companies have taken this “you can’t unsubscribe from service emails” approach and I wish this act would get a refresh 20 years later.
Technically, this is not true. You can "unsubscribe" (read "remove") your email via the Certbot client.
Nevertheless, I agree that this is far too complicated, and I do not understand why there is no form on their website. I wonder if this behavior is compliant with the GDPR.
The problem is that this is junk messaging that no one reads nor needs.
A justification could be that email notifications are a security feature and to disable them you need strong authentication (an unsubscribe link in the email could used by anyone you forward the email)
Speaking from personal experience: I received 7 emails from them, for various "tag" parts of my email (username+tag@server.example). Two of them - for when I was playing with Caddy server many years ago (well before COVID) - and its "auto-https" feature. There's no chance I still have these keys - I likely `rm -rf`'d whole caddy directory.
You probably would need to reauthenticate via DNS, create a new private key and then do what you wanted to do.
EDIT: this is just a guess.
In my view there’s only one thing to do when emails don’t contain an unsubscribe link: report spam — because it is, as described by CAN-SPAM.
Consider an outage email containing a diagnostic report. You might be the relevant person on call for that email and based on the diagnostic you forward it to who should be most competent to fix the issue. This person/team has now read access to the email, but they should not be able to unsubscribe you from these notifications.
In general unsubscribing should not be unduly harder than it needs to be.
For marketing email the effort required should be zero; for critical security issues (like certificates) it should be more.
So, here's the problem, I don't care. I left the company. I cannot access the account anymore. The project is dead. There are a million reasons why I just don't want your emails so there's no excuse to not add an unsubscribe link.
The only messages that don't have to include such link are those that if missed/ignored lead to fees, fines, death, imprisonment and other real-life consequences.
An update to your privacy policy does not fall into that category.
My point was not that you should keep receiving those emails, it was an example of the necessity of having sometimes other mechanisms.
An unsubscribe email address could work better (assuming that if you can send arbitrary emails from an address then you control it).
At any rate, it seems good practice to send such notifications. I don't believe you can usually opt out of "business communications" like this.
Now, letsencrypt is a free service, and they may not be as good as they should about identifying who is a current user? If you don't have have certs that haven't expired, and they're still including you in business communications, then perhaps something isn't as targeted as it could be.