3 ms·
Do they sell the private keys to the NSA? Maybe not. It is an effort by many companies and groups to make the web more secure.
by abcleb 6y ago
Do they sell the private keys to the NSA? Maybe not.
It is an effort by many companies and groups to make the web more secure.
- hu3 6y agoLet's imagine they do sell private keys to state actors (which I highly doubt). Would that allow transparent sniffing of traffic encrypted with these certs?
- AgentME 6y agoMost HTTPS connections today negotiate ephemeral keys at the start of the connection, so even if an attacker has the server's private key (which the CA never sees and couldn't sell!), the attacker can't do passive listening attacks on connections using it. The attacker would have to do an active man-in-the-middle attack that rewrites the connection and swaps out the ephemeral keys with keys known to the attacker, which risks detection. If an attacker has the CA's private key, then the attacker can mint new HTTPS certificates. They wouldn't be able to do passive listening attacks on connections, but they could use an active man-in-the-middle attack to swap out the server's certificate in the connection. However, this attack could be detected through Certificate Transparency, and the CA's leaked keys would become untrusted by browsers.
- blibble 6y agothey couldn't sell your private keys to the NSA as they don't have them as they're generated locally on your machine and never leave it they could sell their keys, but impersonations would likely be spotted thanks to certificate transparency
- huhtenberg 6y agoThey don't see the private keys.
- cocoa19 6y agoThey can't sell the keys since they don't have them. NSA could still mount an attack by asking the CA to register NSA's certs as valid, and tamper the victim's network connection. What makes certs secure is our trust in certificate authorities.