4 ms·
I've lived in China and I used Skype. I didn't think they did this. I don't think I should have expected this either since I knew Skype encrypts all communicat
by DigitalTurk 14y ago
I've lived in China and I used Skype. I didn't think they did this.
I don't think I should have expected this either since I knew Skype encrypts all communication. I wasn't expecting them to actively cooperate with the Chinese government.
Mind you, I never assumed I was completely safe since I have my doubts about the security of SSL certificates (I believe some CAs are corrupt). I'm also used to international companies bending over for a piece of the Chinese market. I'm still surprised!
- 11001 14y ago>I have my doubts about the security of SSL certificates (I believe some CAs are corrupt Care to elaborate?
- ef4 14y agoIt's pretty much consensus at this point that the current CA model is highly broken. Among other problems, there are trusted CAs providing interception capabilities to local governments, and there are CAs that have been compromised and used by criminals. For more, see the EFF's SSL Observatory. Further proof that people take this problem seriously are some features Google has added to Chrome: they keep a list of important websites (particularly Google's own) and refuse to accept perfectly valid certificates for those sites if the certificates are signed by an unexpected CA.
- schoen 14y agoI work with the people developing the SSL Observatory. So far, the Observatory has never been used to discover intentional malfeasance on the part of a certificate authority (though it's found certs that shouldn't have been issued). The Observatory exists, though, because of many data points showing pressures on and uncertainty about the certificate authority industry: successful compromises of CAs, rumors of governments coercing CAs to misissue, some trusted CAs unclear on the concept of what they were supposed to be doing, and other risks. Google's pinning responds to the same set of concerns. One nice change from just a few years ago is that the system is starting to get a lot of scrutiny.
- DigitalTurk 14y agoThat's really nice to hear! I had actually never heard of the SSL Observatory before.