4 ms·
CAs do not have backdoor access. The most a rogue CA can do is possibly enable a MITM against a website that has taken no protections. Google pins their public
by alextgordon 11y ago
CAs do not have backdoor access. The most a rogue CA can do is possibly enable a MITM against a website that has taken no protections.
Google pins their public key fingerprints right into Chrome, and this feature is open:
https://hstspreload.appspot.com/ https://hstspreload.appspot.com/
- enlightenedfool 11y agoI don't understand. How can you be sure that they haven't shared their keys to the government?
- xxpor 11y agoYou don't need to send your private key to a CA to get a cert. You send them a CSR with your public key. https://en.wikipedia.org/wiki/Certificate_signing_request https://en.wikipedia.org/wiki/Certificate_signing_request Edit: Ah, if you were talking about the CA's private keys, then the parent is correct.
- pimlottc 11y agoHaving a CA's private keys only allows you to generate new signed certificates for a site, not decrypt traffic encrypted using an existing signed key pair. At best, it gives you the ability to spoof a website with a man-in-the-middle attack (e.g. you run a rogue wifi hotspot with a fake amazon.com that uses a private key you generated), although certificate-pinning would warn the user that Amazon's certificate had changed unexpectedly.