3 ms·
Quick reminder, from several years ago now, the root certificate authorities are fully compromised by the police state/intelligence apparatus.
by frankfrankfrank 3y ago
Quick reminder, from several years ago now, the root certificate authorities are fully compromised by the police state/intelligence apparatus.
- pieter_mj 3y agoPlease elaborate.
- agwa 3y agoChrome and Safari only accept certificates which are publicly logged in Certificate Transparency logs, so if a government actor uses a CA to issue malicious certificates, they run a high risk of being detected and having that CA distrusted. When evidence came to light last year that Trustcor might be compromised by government actors, it was distrusted by browsers, as was Dark Matter before them. If you have any evidence that current CAs have been compromised, please provide it so they too can be distrusted.
- woodruffw 3y agoCompromising a CA doesn’t “get” you anything in the web PKI scheme: holding the CA’s private key doesn’t get you access to individual end entity keys, and issuing a new certificate with it loudly announces your presence due to CT. Intelligence agencies are, in all likelihood, far more interested in obtaining individual end entity keys than they are in CAs.
- tialaramex 3y agoEven the end entity keys are rarely interesting. Increasingly they are signature keys, and so the only thing you can use those keys for is impersonation, which is cumbersome. What you want more often are session keys so that you can either listen in live (if you obtain in time) or decrypt a transcript later if you don't. Because this is passive it's harder to detect and easier to deny.
- cpach 3y agoThat’s an extraordinary claim, so some references would be prudent.