4 ms·
This is something I was thinking about last night, prompted by the recent resurgence in awareness of government wiretapping and some of the responses of "use SS
by erydo 14y ago
This is something I was thinking about last night, prompted by the recent resurgence in awareness of government wiretapping and some of the responses of "use SSL everywhere so it's not a problem."
Does anything prevent a government from privately coercing a CA into issuing certificates that enable a MITM attack?
It may be that the difficulty of getting a gag order for a CA could be greater than the difficulty of obtaining a warrant on the destination, unless the destination is foreign--but it still sounds feasible for a government to do.
Am I off base about that?
- tptacek 14y agoThat's becoming a high-risk proposition now that Chrome (and apparently Firefox) are pinning certs. A government could indeed coerce a CA into issuing certificates, but they can't easily coerce Google into transparently overriding their pinned certificates, and when the two disagree, the world can see which CA root chain was used to forge the certs. As you can see, it doesn't even take pervasive deployment of a technology like TACK to significantly mitigate the threat of rogue CAs.