3 ms·
Which CAs have never been subject to a National Security letter? Can't say cuz you can't know? Lets talk about that false sense of security indeed.
by JackRabbitSlim 7y ago
Which CAs have never been subject to a National Security letter? Can't say cuz you can't know? Lets talk about that false sense of security indeed.
- arminiusreturns 7y agoYep, for years when everyone was talking about NSL's and other corporate strong-arming by the gov, I started saying I suspect most major CA's are compromised. At least you know your threat model though, because only the nation states are going to have that. CA's and DNS are two parts of the internet that have become way too centralized in my opinion.
- daxelrod 7y agoThis is one of the threats addressed by https://www.certificate-transparency.org/ https://www.certificate-transparency.org/ . If a CA issues a rogue cert and _does_ add it to the CT log, it's discoverable, at least in retrospect. If a CA issues a rogue cert and _doesn't_ add it to the log, some browsers will refuse the connection when presented with that cert. https://www.agwa.name/blog/post/how_will_certificate_transparency_logs_be_audited_in_practice https://www.agwa.name/blog/post/how_will_certificate_transpa... has more details about Chrome's implementation.