4 ms·
I would actually be shocked if US agencies can't do the same here almost all the time. There has to be at least one trusted root authority that is controlled b
by edoo 7y ago
I would actually be shocked if US agencies can't do the same here almost all the time. There has to be at least one trusted root authority that is controlled by an agency. Do you remember when RSA made a $10 mil deal to give .gov a backdoor back in the day. There is no reason any major US based certificate issuer couldn't do the same, or an employee turned into an asset to sneak it to them, or they just straight hack the places and get certs they can generate anything on. You might be able to detect it by logging the issuer of the cert, the browser doesn't care who auths it as long as it is trusted. It would be odd for most places to have certs issued by multiple authorities.