Remix.run Logo
whosdat 12 hours ago

I have very little reason to believe that NSA is not doing, and had been doing that, more or less for as long as there had been CA. And on a global scale. If you don't find this plausible, it is because usually americans believe their predator state to be some kind of a "lion king" (aka superman, spiderman. etc), while it is more of a laughing hyena.

wartywhoa23 7 hours ago | parent | next [-]

Russians would often fend this off by saying "the CIA major is farther than the FSB one".

But of course there's little reason to doubt that all public-facing separation between world's secret services is but a spectacle, just like the idependence of CAs.

Not only that, but also all encryption running in OSes that run above lower level, battery-powered SoCs with full network stack like Intel ME, AMD PSP and ARM TrustZone.

whosdat 4 hours ago | parent [-]

Oh, really? That's interesting.

But as they say, the chain is as strong as its weakest link.

inigyou 10 hours ago | parent | prev [-]

You can verify this for your own domains by using certificate transparency.

whosdat 9 hours ago | parent [-]

Wouldn't that be true also for the Russian CA?

inigyou 9 hours ago | parent [-]

Yes, the banks can verify it for their own domains - unless Russia is sanctioned out of the CT logs or the government forces Yandex Browser not to check CT.

They can also just load the site from a separate internet connection and see if it has their certificate.

8 hours ago | parent [-]
[deleted]