Hacker News new | ask | show | jobs
by 2RTZZSro 2849 days ago
HTTPS security model is fundamentally broken to meet the needs of the junta. National Security Letters can be used to "legally" obtain root certificate keys of all Root CAs even remotely affiliated with the United States. You must be extremely naive to believe that the NSA has not already collected all Root CA keys relevant to operations within USA borders. NSL also tend to forbid disclosure of the existence of the NSL, so you will never know that the Root CA is compromised. If you as a Root CA disclose the existence of such a NSL, MS-13 might pay you a visit, and you might unfortunately show up on a obituary in a newspaper nobody reads.
1 comments

If this were something the NSA were actually doing, wouldn't we have noticed it by now via the rogue certificates showing up in certificate transparency logs?