4 ms·
I seem to not get the twist. What am I missing?
by JackGreyhat 5y ago
I seem to not get the twist. What am I missing?
- senectus1 5y agoI think its an insinuation that letsencrypt is a honeypot.
- kodah 5y agoIt's been long rumored that privacy-as-a-product companies are actually three letter agency honey pots. ProtonMail actually has some connections to NSA investment firms and some former NSA staff on their board. There could be good explanations here, and there could be bad explanations, however, we don't know the role each of these components play in the larger sum; we can only guess and speculate. In that way, an ambitious project that gives away certificates that were formerly worth a lot of money would be a pretty slick honeypot because now you could stow away private keys and have a copy of most of the encrypted webs certificates to decrypt in-flight communications.
- shkkmo 5y agoA CA can't steal your private keys, they can issues certs for your domain to themselves regardless of ownership. They could do this even without you as a customer, atleast untill they get caught and have their root certs revoked by tech companies.
- ronsor 5y agoThat's not at all how Let's Encrypt or any HTTPS CAs work (or have ever worked). You send them a certificate signing request, and they respond with a signed certificate. You never give them your private key.
- hanniabu 5y agoNever heard of a back door? There can be master private keys.
- XorNot 5y agoFunctionally irrelevant to your browser though without HSTS: being able to MITM specific targets with correctly signed certificates would be extremely useful.
- KirillPanov 5y agoIf they issued a malicious certificate they would not be able to hide it. Certificate Transparency logs are now mandatory for all TLS certificates: https://en.m.wikipedia.org/wiki/Certificate_Transparency https://en.m.wikipedia.org/wiki/Certificate_Transparency The log is like a git hash-chain: you can never erase the past without affecting the whole chain after the erasure. If you want hidden backdoors, put them in hardware, not software. Chips are the best place.
- fomine3 5y agoI believe perfect forward secrecy (now default) blocks such attacks.