logoalt Hacker News

JoshTriplett • yesterday at 6:51 PM • 1 reply • view on HN

Browsers and TLS infrastructure have been solving that for a while now, via certificate transparency. Browsers can now reject any certificate that isn't publicly logged. So, yes, they could MITM, and burn an entire CA doing it.


Replies

ndriscoll • yesterday at 7:14 PM

If you're dealing with an authoritarian state they don't need to burn anything or care about cert logging. They can:

  1. Make it illegal to distribute a browser that distrusts their CA

  2. Make it illegal to run a browser that distrusts their CA

  3. Block all encrypted traffic that they can't MITM and notify police that you are running illegal software
➕ show 3 replies