Comment by JoshTriplett
5 hours ago
Browsers and TLS infrastructure have been solving that for a while now, via certificate transparency. Browsers can now reject any certificate that isn't publicly logged. So, yes, they could MITM, and burn an entire CA doing it.
If you're dealing with an authoritarian state they don't need to burn anything or care about cert logging. They can:
This is unnecessary, they already have the problem controlled better. They just outright block foreign services, and the domestic ones they can request data from freely.
Doesn’t require cracking crypto or any funny business around forcing people to install stuff.
Sure, a state can do that, and some have tried at various times. But even authoritarian states have a number of competing aims they have to balance. And CT makes authoritarian goals harder; they can no longer do as much surreptitiously.