4 ms·
Which could indicate the gov has already broken TLS's trusted model. It's known a CA was breached some years back by a state, why would it be so far fetched to
by CommanderData 5y ago
Which could indicate the gov has already broken TLS's trusted model. It's known a CA was breached some years back by a state, why would it be so far fetched to say CA's haven't been required to hand over private keys and are prevented from speaking about it?
I would not be surprised in the slightest that the government has subpoenaed a UK based CA or has a UK controlled CA of their own.
Having access to end private keys or being able to sign your own valid cert from a well known entity in the trusted list, to just operating your own all means the user is (almost) none the wiser TLS communication is opened wide to a state actor.
- deleted 5y ago[deleted]
- mike_d 5y ago> It's known a CA was breached some years back by a state Last time I bothered to check over a third of all CAs were directly owned by some arm of a government (national telecom, postal services, etc). Certificate Transparency is the solution to this problem. To be trusted by browsers the malicious CA has to publicly publish that they generated a cert for facebook.com.
- CommanderData 5y agoCertificate transparency doesn't solve this issue fully.
- mike_d 5y agoIt sure does. Use a browser or other web client that does not trust certificates unless they appear in CT logs. A rouge CA then has to lie publicly by putting the false cert into the log, which in turn gets flagged and they don't get to be a CA anymore.
- raxxorrax 5y agoNot surely, but they should be vetted and government CAs should be made exempt in my opinion until the user explicitly allows them. Otherwise the chain of trust is compromised. It will never be perfect, but government ambitions will get more specific if a newer generation takes hold in politics.