← Back to context

Comment by JoshTriplett

5 hours ago

Browsers and TLS infrastructure have been solving that for a while now, via certificate transparency. Browsers can now reject any certificate that isn't publicly logged. So, yes, they could MITM, and burn an entire CA doing it.

If you're dealing with an authoritarian state they don't need to burn anything or care about cert logging. They can:

  1. Make it illegal to distribute a browser that distrusts their CA

  2. Make it illegal to run a browser that distrusts their CA

  3. Block all encrypted traffic that they can't MITM and notify police that you are running illegal software

  • This is unnecessary, they already have the problem controlled better. They just outright block foreign services, and the domestic ones they can request data from freely.

    Doesn’t require cracking crypto or any funny business around forcing people to install stuff.

  • Sure, a state can do that, and some have tried at various times. But even authoritarian states have a number of competing aims they have to balance. And CT makes authoritarian goals harder; they can no longer do as much surreptitiously.