Remix.run Logo
cyberax 2 days ago

This is super-dumb. The same thing is happening with Russian banks.

Their answer? They're now asking users to install root certs from the Russian ministry of communications. So it can now MITM all the encrypted traffic in Russia.

Avamander 2 days ago | parent | next [-]

China and many others run their own CAs, I'd presume Russians could use those if they wanted?

throw-the-towel 2 days ago | parent [-]

Russians didn't want to use those, until the West made it inevitable.

Avamander 2 days ago | parent [-]

And why is that?

It's not that hard to find a CA in a more aligned regime.

Rolling your own MITM CA as a replacement just looks like something that was waiting for an excuse.

cyberax 2 days ago | parent [-]

Violating the OFCOM restrictions will result in losing access to VISA/MC payments. No company wants this.

axus 2 days ago | parent | prev [-]

Dumb for the US: if US were currently MITM with certs copied by its agencies, US won't be able to do that for Iranian / Russian certs.

misano 2 days ago | parent [-]

SSL MITM also requires hijacking the network and redirecting the traffic.