4 ms·
I don't understand. How can you be sure that they haven't shared their keys to the government?
by enlightenedfool 11y ago
I don't understand. How can you be sure that they haven't shared their keys to the government?
- xxpor 11y agoYou don't need to send your private key to a CA to get a cert. You send them a CSR with your public key. https://en.wikipedia.org/wiki/Certificate_signing_request https://en.wikipedia.org/wiki/Certificate_signing_request Edit: Ah, if you were talking about the CA's private keys, then the parent is correct.
- pimlottc 11y agoHaving a CA's private keys only allows you to generate new signed certificates for a site, not decrypt traffic encrypted using an existing signed key pair. At best, it gives you the ability to spoof a website with a man-in-the-middle attack (e.g. you run a rogue wifi hotspot with a fake amazon.com that uses a private key you generated), although certificate-pinning would warn the user that Amazon's certificate had changed unexpectedly.