3 ms·
I think your worry is a bit out of scope. There is a thing called "Verhaeltnismaessigkeit" in Germany, and in most other countries where "The Rule Of Law" appli
by alcoholic_byte 6y ago
I think your worry is a bit out of scope.
There is a thing called "Verhaeltnismaessigkeit" in Germany, and in most other countries where "The Rule Of Law" applies, to paraphrase Trudeau.
Meaning: You are not allowed to burn down the house just because the neighbor was playing the music too loudly.
So others are not to caught in the cross-fire of this operation.
So it will be a very technical challenge to overcome these obstacles.
And since an ISP is not providing updates, coercing OS vendors to alter the CA's for a specific user is a bit far-fetched.
The more likely approach is the acquisition of cryptographic keys to create one's own SSL-Certificiate.
Now: This is the domain of the intelligence-community.
Their bread and butter. Compared to the rest of the world, this community is heavily regulated; you just have to think of the CIA's Black Budget or other agencies from less pleasent countries to get a comparison.
It is best they get the legal framework in place (s.o. heralded it as the OS for society once). The alternative would be clandestine operations outside the law, and that is never good.
Only requirement I would demand for s.th. like this: The solution mustn't be scalable, as to ensure to avoid a subjecting large swats of a population to this, which is challenging with technologies these days.
The good thing is that ISPs will not keel over just because the police are requesting it.
After all they have a reputation and their customers to protect and, let's face it, this is not China, Russia, Iran or some other country were you vanish for far less than demanding more paperwork and speaking out against executive orders.
As long as the mechanisms of a society are functioning and everyone watches everyone and there is due process it works.
It will be a problem if these mechanisms fail though. I for one will be watching with keen interest.
As for the new root certificate to a domain for the agencies:
I already pointed out, s.w. in this discussion, that there is a mechanism called Certificate Pinning. Works wonders if the server configured it.
So yes, they are working on the legal framework, but thanks to the foresight of engineers and people concerned with safety for the general non-technical and technical internet-population, it is a hard challenge officials are facing.
- saati 6y agoThere is no certificate pinning anymore, it's deprecated. Your whole argument is based on the state actually playing nicely and assume a meaningful oversight of intelligence, both are hopelessly naive.