Russia recently moved to its own SSL certificates due to sanctions. Now you cannot use a bank without allowing the government to MITM you.
Russia recently moved to its own SSL certificates due to sanctions. Now you cannot use a bank without allowing the government to MITM you.
Can't US government MITM all of us, even with certificate transparency logs?
They can only do that through an "SSL added and removed here ;-)"-like 'cooperation' and not through passive listening because with forward secrecy a certificate key doesn't secure the transport encryption directly. They could actively MITM outside the perimeter of the target by issuing a new certificate, but that would show up on CT logs.
tls1.3 you can fully mitm with nice green padlock, its much easier if you have access to CAs where most big 'trusted' are US based. that being said a lot of govt for their services use their own ones and what is trusted and not trusted in CA land is highly dubious at best. try looking at all those weird nooneheardofthem names in the CA bundles on modern systems.
besides that its quite likely they will have intercepted most key exchanges since thats still a problem and pretty easy to see happening if you say, tap the backbone -_-.
US and few other have really futuristic capabilities here. its hard to imagine snowden was 14 years of secret innovation ago... it has only gotten much worse friend.
some of us voluntarily mitm ourselves via cloudflare ;)
Not without leaving potential proof that it happened behind
Dream on.
metadata is juicier anyway.
Hence why E2EE is so important, and where feasible, only accessible by you and not the other party
The biggest issue at scale is to confirm the identity of legitimate contacts without a single point of trust.