3 ms·
Well sort of, it allows government to create a falsified certificate for other sites like Google sites (man in the middle attack). When the browser forum/certif
by theonlybutlet 3y ago
Well sort of, it allows government to create a falsified certificate for other sites like Google sites (man in the middle attack). When the browser forum/certificate authority wise up to it's use, they've then got to prove it's causing harm and get approval from authorities to remove it (authorities can take their sweet time responding to the request).
- foota 3y agoSorry, I mean, browsers today ship with a list of sites that specify a cert that must be in the chain for it to be considered valid, e.g., only trust a facebook.com cert if it's from XYZ CA. Depending on the wording of the law, it seems like it could require browsers to ignore this requirement for government issued certificates, hence bypassing the cert pinning and allowing them to intercept traffic to e.g., Facebook. I'm not sure how many sites do this, I think Google's own do, and maybe some of the other big names use it as well, but I'm not certain.
- theonlybutlet 3y agoSorry I see what you're saying, I think you're right. Perhaps a browser fork for non-EU folk? Far from ideal.