3 ms·
A "trusted MITM" is just that, a trusted MITM...You kind of accept the compromises that come with such a setup. A CA that can issue a certificate to a third-pa
by Edmond 6y ago
A "trusted MITM" is just that, a trusted MITM...You kind of accept the compromises that come with such a setup.
A CA that can issue a certificate to a third-party without the consent of the domain owner is not a trusted CA by definition.
In other words the issue in Kazakhstan should probably not be viewed as a technical issue...authoritarian governments will always get their way if the only recourse against them is a technical solution. In the case of Kazakhstan, they are forcing their citizens to accept the compromised CA, that is not a technical problem to solve.