3 ms·
No need to decrypt SSL, there are easier ways: https://xkcd.com/538/ https://xkcd.com/538/
by anyzen 8y ago
No need to decrypt SSL, there are easier ways: https://xkcd.com/538/ https://xkcd.com/538/
- walrus01 8y agoOr do like Uzbekistan has done, force all local computer stores to install a trusted root CA in the operating system before it gets to the hand of the end user. You can transparently MITM TLS1.2 if the system trusts the mitm operator CA. Maybe 0.01% of people even know where to look to examine their windows 10 machine's trusted CA list.
- yayana 8y agoHaving looked through the government CAs in preinstalled CA lists, I'm a little surprised Uzbekistan doesn't qualify.
- vegardx 8y agoNaturally! Well - except for the diplomatic disaster this would turn into if you did it on foreigners. I think most people exaggerate the technical capabilities of the Chinese government and how interesting they are for them. Sure, we shouldn't be naive, but a drop of realism is always good.
- lbriner 8y agoThe difference is in the degree! I don't think the Chinese could or would decrypt all foreigners traffic (and I did mean TLS but use the more well-known SSL name) but if the question is "As someone with a trip to Beijing on the horizon, aside from using a VPN, are there any other best practices to keep data secure while traveling there?", the answer is very clearly don't connect to the internet. I don't know the person who asked the question, whether he is a realistic government target or just some normal person but there are enough reports of cache poisoning, VPN control/blocking and Chinese hijinks to know that if you are worried about them, don't connect. Mind you, the same fear applies to the US and UK as well.