Remix.run Logo
▲ nazcan 5 hours ago

My guess is if you are in China they can MITM you with their own root certs.

▲JoshTriplett 4 hours ago | parent | next [-]

Browsers and TLS infrastructure have been solving that for a while now, via certificate transparency. Browsers can now reject any certificate that isn't publicly logged. So, yes, they could MITM, and burn an entire CA doing it.

▲ndriscoll 4 hours ago | parent [-]

If you're dealing with an authoritarian state they don't need to burn anything or care about cert logging. They can:

  1. Make it illegal to distribute a browser that distrusts their CA

  2. Make it illegal to run a browser that distrusts their CA

  3. Block all encrypted traffic that they can't MITM and notify police that you are running illegal software
▲JoshTriplett 4 hours ago | parent [-]

Sure, a state can do that, and some have tried at various times. But even authoritarian states have a number of competing aims they have to balance. And CT makes authoritarian goals harder; they can no longer do as much surreptitiously.

▲hnav 5 hours ago | parent | prev [-]

Russia's ROSKOMNadzor has been trying to get users to install its own Root CAs in recent years. About 10 years ago everyone in the west removed CNNIC (Chinese counterpart) roots after they were caught MITM-ing.