| ▲ | JoshTriplett 4 hours ago |
| Browsers and TLS infrastructure have been solving that for a while now, via certificate transparency. Browsers can now reject any certificate that isn't publicly logged. So, yes, they could MITM, and burn an entire CA doing it. |
|
| ▲ | ndriscoll 3 hours ago | parent [-] |
| If you're dealing with an authoritarian state they don't need to burn anything or care about cert logging. They can: 1. Make it illegal to distribute a browser that distrusts their CA
2. Make it illegal to run a browser that distrusts their CA
3. Block all encrypted traffic that they can't MITM and notify police that you are running illegal software
|
| |
| ▲ | JoshTriplett 3 hours ago | parent [-] | | Sure, a state can do that, and some have tried at various times. But even authoritarian states have a number of competing aims they have to balance. And CT makes authoritarian goals harder; they can no longer do as much surreptitiously. |
|