3 ms·
Governments don't outright operate CAs, but given the long list of trusted authorities and intermediates in every modern browser, and given the various successe
by corresation 13y ago
Governments don't outright operate CAs, but given the long list of trusted authorities and intermediates in every modern browser, and given the various successes of these agencies, it seems a probable certainty that if they need to generate a trusted cert for given targets, they can. In effect I am agreeing.
The Apple SSL bug seemed overblown (from a government perspective) for that reason, and unlikely to be a government effort. Exploiting a CA seems significantly easier than embedding bugs in specific platforms. I suppose they might do both, but I doubt their abilities were reduced after it was patched.