3 ms·
The government would be able to obtain a certificate identical to the one of the a website owner (the real one), enabling the mitm attack (for example with the
by Dumble 3y ago
The government would be able to obtain a certificate identical to the one of the a website owner (the real one), enabling the mitm attack (for example with the help of ISPs etc).
- landgenoot 3y agoYes, but you will see that the certificate authority suddenly switches to the Hungarian government, while reading an article.
- Urd- 3y agoHow would they get the private key? Or would this CA only allow using certs with private keys they generated instead of using CSRs?
- ulrikrasmussen 3y agoWouldn't Certificate Transparency make it very visible and obvious if they did that?
- Avamander 3y agoCT would not be allowed if ETSI does not allow it. Neither would distrusting that mis-issuing CA be allowed.