Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I have very little reason to believe that NSA is not doing, and had been doing that, more or less for as long as there had been CA. And on a global scale. If you don't find this plausible, it is because usually americans believe their predator state to be some kind of a "lion king" (aka superman, spiderman. etc), while it is more of a laughing hyena.


Russians would often fend this off by saying "the CIA major is farther than the FSB one".

But of course there's little reason to doubt that all public-facing separation between world's secret services is but a spectacle, just like the idependence of CAs.

Not only that, but also all encryption running in OSes that run above lower level, battery-powered SoCs with full network stack like Intel ME, AMD PSP and ARM TrustZone.


Oh, really? That's interesting.

But as they say, the chain is as strong as its weakest link.


You can verify this for your own domains by using certificate transparency.


Wouldn't that be true also for the Russian CA?


Yes, the banks can verify it for their own domains - unless Russia is sanctioned out of the CT logs or the government forces Yandex Browser not to check CT.

They can also just load the site from a separate internet connection and see if it has their certificate.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: