logoalt Hacker News

nlytoday at 7:26 AM1 replyview on HN

It is of course inconceivable that the NSA do not have the private keys for dozens of browser trusted certificate authorities

That nonetheless doesn't help them unless they are doing active MITM. In order to do that they'd have to have at least some physical presence at Cloudflare or on the path to Cloudflare.


Replies

RealityVoidtoday at 8:00 AM

My understanding is that they tapped communication nodes before. I would be surprised if they can't tap the pipes to cloudflare.

show 1 reply