5 ms·
How does the use of certificate pinning mean anything when a FISA court can demand the keys and issue a gag order to prevent public disclosure?
by davisr 2y ago
How does the use of certificate pinning mean anything when a FISA court can demand the keys and issue a gag order to prevent public disclosure?
- gruez 2y ago1. AFAIK no government, even authoritarian ones, coerced a CA to misissue a certificate. There have, however, been plenty of other ways governments are able to get certificates, like seizing the domains/servers. 2. Even if they did, chrome has enforced certificate transparency, so a gag order on the CA/CT provider would simply result in the certificate being rejected.
- hulitu 2y ago> 1. AFAIK no government, even authoritarian ones, coerced a CA to misissue a certificate. As far as you and i know. Those things are not public. Helps with espionage (see Crypto AG).
- blablabla123 2y agoSure, but then it isn't related to the CA system anymore and any action from them wouldn't be under the radar anymore. Also this problem would apply to any key like gpg. Well, as long as it's not in a Hardware security module. Of course they could also seize that but at some point it becomes logistically impractical, at least for mass surveillance.