5 ms·
TLS encryption means absolutely nothing. The very system of using certificate authorities is flawed by design. NSA has no trouble performing MITM. Go search 'NS
by davisr 2y ago
TLS encryption means absolutely nothing. The very system of using certificate authorities is flawed by design. NSA has no trouble performing MITM. Go search 'NSA FLYING PIG'.
https://www.cnet.com/tech/tech-industry/nsa-disguised-itself-as-google-to-spy-say-reports/ https://www.cnet.com/tech/tech-industry/nsa-disguised-itself...
- blablabla123 2y agoYeah but I imagine the ice is getting thin. Sure, use of key pinning on the web failed - but for instance banking apps commonly use it. Once monitoring Certificate transparency logs gets more traction, things like that could get noticed.
- davisr 2y agoHow does the use of certificate pinning mean anything when a FISA court can demand the keys and issue a gag order to prevent public disclosure?
- gruez 2y ago1. AFAIK no government, even authoritarian ones, coerced a CA to misissue a certificate. There have, however, been plenty of other ways governments are able to get certificates, like seizing the domains/servers. 2. Even if they did, chrome has enforced certificate transparency, so a gag order on the CA/CT provider would simply result in the certificate being rejected.
- hulitu 2y ago> 1. AFAIK no government, even authoritarian ones, coerced a CA to misissue a certificate. As far as you and i know. Those things are not public. Helps with espionage (see Crypto AG).
- blablabla123 2y agoSure, but then it isn't related to the CA system anymore and any action from them wouldn't be under the radar anymore. Also this problem would apply to any key like gpg. Well, as long as it's not in a Hardware security module. Of course they could also seize that but at some point it becomes logistically impractical, at least for mass surveillance.
- amanda99 2y agoThat's just not even remotely true. After the PRISM stuff, folks got a lot more savvy with encryption. TLS has been tightened up a lot since then across many fronts (perfect forward secrecy, removing crap roots, certificate transparency, etc). There's just no way the NSA can be MITMing any reasonable proportion of traffic. Possibly extremely targeted stuff, and sure, there's technically the possibility that Google is handing over keys, but if it was happening at any massive scale, people would now know. That's why the fight has moved over to metadata now, which is what the three letter agencies are vacuuming up these days.
- halJordan 2y agoPeople choose to believe that nothing happened after snowden and because this is a religion to them you can't even tell them they're wrong