4 ms·
I bet the next thing Russian (and many other oppressive ones) will try is forcing government-issued root certs on client devices with mandatory mitm. Sure, some
by lambdadmitry 8y ago
I bet the next thing Russian (and many other oppressive ones) will try is forcing government-issued root certs on client devices with mandatory mitm. Sure, some devices might not be capable of importing new root certs, but for sufficiently dictatorial regime it's not a problem.
- ignoramous 8y agoStrict CertifcatePinning can thankfully prevent this from working [0] as intended, although on the flip-side it also introduces a significant problem for deep-packet inspection for malware/intrusion detection and privacy enthusiasts who would like to re-map certain kinds of traffic on the client-side [1]. [0] https://news.ycombinator.com/item?id=10727649 https://news.ycombinator.com/item?id=10727649 [1] https://news.ycombinator.com/item?id=19172038 https://news.ycombinator.com/item?id=19172038