← Back to context

Comment by nazcan

5 hours ago

My guess is if you are in China they can MITM you with their own root certs.

Browsers and TLS infrastructure have been solving that for a while now, via certificate transparency. Browsers can now reject any certificate that isn't publicly logged. So, yes, they could MITM, and burn an entire CA doing it.

  • If you're dealing with an authoritarian state they don't need to burn anything or care about cert logging. They can:

      1. Make it illegal to distribute a browser that distrusts their CA
    
      2. Make it illegal to run a browser that distrusts their CA
    
      3. Block all encrypted traffic that they can't MITM and notify police that you are running illegal software

    • Sure, a state can do that, and some have tried at various times. But even authoritarian states have a number of competing aims they have to balance. And CT makes authoritarian goals harder; they can no longer do as much surreptitiously.

Russia's ROSKOMNadzor has been trying to get users to install its own Root CAs in recent years. About 10 years ago everyone in the west removed CNNIC (Chinese counterpart) roots after they were caught MITM-ing.