This is super-dumb. The same thing is happening with Russian banks.
Their answer? They're now asking users to install root certs from the Russian ministry of communications. So it can now MITM all the encrypted traffic in Russia.
This is super-dumb. The same thing is happening with Russian banks.
Their answer? They're now asking users to install root certs from the Russian ministry of communications. So it can now MITM all the encrypted traffic in Russia.
China and many others run their own CAs, I'd presume Russians could use those if they wanted?
Russians didn't want to use those, until the West made it inevitable.
And why is that?
It's not that hard to find a CA in a more aligned regime.
Rolling your own MITM CA as a replacement just looks like something that was waiting for an excuse.
Violating the OFCOM restrictions will result in losing access to VISA/MC payments. No company wants this.
Dumb for the US: if US were currently MITM with certs copied by its agencies, US won't be able to do that for Iranian / Russian certs.
SSL MITM also requires hijacking the network and redirecting the traffic.