Hacker News new | past | comments | ask | show | jobs | submit login

<hat type="tinfoil"> … or they've so thoroughly subverted the SSL certificate "industry" and the major internet backbones that they figure even people using SSL cert pinning aren't going to notice they're already MITMing every single piece of web traffic with self-issued browser-trusted certs. So it's a good PR time to pretend they need new powers.</hat>



Why would they bother MITM? They can just send a national security letter demanding the private key of the CA and a gag order forbidding them from announcing the compromise.


if they can do that ,the backdoor will be found by others sooner or later.


Where by "sooner or later", you mean "last year":

http://www.computerworld.com/s/article/print/9235260/Rogue_G...

and

http://www.computerworld.com/s/article/9219606/Hackers_stole...

Fortunately that attack is only possible if you're a despotic nation-state who controls your entire countries internet connection - or perhaps a three letter agency who'd only have to lean on half a dozen or so major internet backbone company CEOs - so you can MITM pretty much _all_ the traffic...




Consider applying for YC's Summer 2025 batch! Applications are open till May 13

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: