3 ms·
If I had to guess the people who wrote this are just assuming tls on top.
by anonacct37 8y ago
If I had to guess the people who wrote this are just assuming tls on top.
- zimbatm 8y agoThat's an interesting implication. If they distribute the same cert so widely geographically, any host country could technically request it for "lawful intercepts".
- dsl 8y agoYou don't have to keep keys on boxes in random countries if you use a TLS oracle [1]. Another option is deploying the keys onto an HSM and pointing your frontends at that. 1. Here is CloudFlare's implementation (and pats themselves on the back for "inventing" it): https://blog.cloudflare.com/keyless-ssl-the-nitty-gritty-technical-details/ https://blog.cloudflare.com/keyless-ssl-the-nitty-gritty-tec...
- romed 8y agoA host country can request a lawful intercept regardless of whatever technical conditions exist on your network.
- deleted 8y ago[deleted]