3 ms·
Oppressors can (and I think some already do) subvert HTTPS by mandating installation of government-issued certs so they can do their MITM.
by mpartel 6y ago
Oppressors can (and I think some already do) subvert HTTPS by mandating installation of government-issued certs so they can do their MITM.
- Legogris 6y agoI know there have been attempts (was it Iran and Kazakhstan that was in the news last year?), but is anyone aware of this actually being done in practice today? My understanding is that they were forced to roll back for practical reasons (which highlights my point).
- mosselman 6y agoThat is an irrelevant detail. The comment you are responding to isn’t saying that https is foolproof. They are saying that it would help people to be more free of digital control if privacy respecting technology is so common that it isn’t suspicious when you use it.
- mpartel 6y agoI agree that it helps (though I'm probably more pessimistic about how much it helps). I wanted to counter the assertion that "There's no way it can be banned today, though" (which I should have quoted). Even a disconcertingly non-trivial number of western lawmakers make regular noises about requiring all encryption to be backdoored.
- Legogris 6y agoMy sibling response was apparently already out of touch when I wrote it. https://www.zdnet.com/article/china-is-now-blocking-all-encrypted-https-traffic-using-tls-1-3-and-esni/ https://www.zdnet.com/article/china-is-now-blocking-all-encr...