| ▲ | sam_lowry_ 2 days ago | |||||||
Can't US government MITM all of us, even with certificate transparency logs? | ||||||||
| ▲ | throwaway89201 2 days ago | parent | next [-] | |||||||
They can only do that through an "SSL added and removed here ;-)"-like 'cooperation' and not through passive listening because with forward secrecy a certificate key doesn't secure the transport encryption directly. They could actively MITM outside the perimeter of the target by issuing a new certificate, but that would show up on CT logs. | ||||||||
| ||||||||
| ▲ | hiciu 2 days ago | parent | prev | next [-] | |||||||
some of us voluntarily mitm ourselves via cloudflare ;) | ||||||||
| ▲ | theginger 2 days ago | parent | prev | next [-] | |||||||
Not without leaving potential proof that it happened behind | ||||||||
| ||||||||
| ▲ | SSLy 2 days ago | parent | prev [-] | |||||||
metadata is juicier anyway. | ||||||||