| ▲ | ceejayoz 3 days ago | |||||||
Your many, many default-trusted CAs can mint new certs for the sites you visit. | ||||||||
| ▲ | parineum 2 days ago | parent [-] | |||||||
Which would be easily detectable if the cert I'm using on my server didn't match the one that was being served publicly. There's really no way this conspiracy theory works if "they" have a copy of every single private cert generated. Which would be impressive because I can generate one myself and get it trusted without ever sending it and would be easily able to detect a MITM attack. Not to mention most sites are going to use pinned certs so any repeat visitors to a site will notice a cert change associated with a MITM. This whole idea relies on the assumption that everyone is trusting third parties with their private certs. That is not at all required. | ||||||||
| ||||||||