4 ms·
They maybe don't even need to force them. There are plenty of certificate authorities. Just look at your browsers list of trusted CAs or even worse the big num
by danishguy 6y ago
They maybe don't even need to force them. There are plenty of certificate authorities. Just look at your browsers list of trusted CAs or even worse the big number included in Android.
You can assume that some of those are at least in bed with TLAs or can't withstand an attack for stealing the keys.
There are hundreds of those.
If only one is compromised an attacker could issue valid certificates for whatever website you visit. They maybe not going to risk a root CA but there are plenty of intermediate ones. Some are directly controlled by states, so no reason to compromise anyone.
https://ccadb-public.secure.force.com/mozilla/IncludedCACertificateReport https://ccadb-public.secure.force.com/mozilla/IncludedCACert...
https://ccadb-public.secure.force.com/mozilla/PublicAllIntermediateCerts https://ccadb-public.secure.force.com/mozilla/PublicAllInter...
https://security.stackexchange.com/questions/2268/how-feasible-is-it-for-a-ca-to-be-hacked-which-default-trusted-root-certificate https://security.stackexchange.com/questions/2268/how-feasib...