Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is just an alarming sign that the entire SSL business is broken. It was exploited so many times by western agencies and also by criminals that it should be clear to everybody that this workflow is broken. This action from Google is an example of double standards. There are CAs from three letter friends in some of the tools we are using today so they can silently mitm attack your SSL traffic. I don't see Google rushing to fix the underlying problem and just trying to mess with China.


Re: 3 letter friends CAs, I believe it. Sort of have to do that, given their operating goal of being able to read everything at will. Its low-hanging fruit, and the only real reason to continue with such a centralized authority-based scheme is to support that type of thing.


Well, I would agree with you if this opportunity could not be exploited by malicious organizations.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: