3 ms·
The SSL infrastructure is protected only by the shaky assumption that "all CAs are responsible and would never create a certificate for anyone but the true owne
by ProblemFactory 13y ago
The SSL infrastructure is protected only by the shaky assumption that "all CAs are responsible and would never create a certificate for anyone but the true owner of the domain."
Here is a list of root CAs in Firefox: https://docs.google.com/spreadsheet/pub?key=0Ah-tHXMAwqU3dGx0cGFObG9QM192NFM4UWNBMlBaekE&single=true&gid=1&output=html https://docs.google.com/spreadsheet/pub?key=0Ah-tHXMAwqU3dGx...
Not just NSA, but all of those organisations can create a valid SSL certificate for mail.google.com, and your browser would accept it silently.