← Back to context

Comment by lazide

1 day ago

Not if they have a root cert.

That's not a property of QUIC. Yes, if you trust both sides, then you trust both sides. That's not what people normally understand as MitM.

  • Pre-cert usage/issuance lists, it would take a keen eye to spot auto-mitm using root certs.

If China uses a root cert to issue bogus certs, that'll get caught by certificate transparency. Assuming people use browsers that enforce certificate transparency.