|
|
|
|
|
by heavyset_go
1687 days ago
|
|
> If the saudis are breaking TLS1.3 in an up to date browser in a client workstation that doesn't have some kind of APT/rootkit on it (also a high risk), we have other problems. They wouldn't need to break TLS 1.3 if they have access to root certificates, they could use them to perform MitM attacks. |
|
It's trivially easy and almost undetectable for any nation-state to perform targeted MitM against HTTPS. It wouldn't be legally possible in most of jurisdictions, but Saudi Arabia isn't exactly "rule of law" country.
Uzbekistan tried, because they wanted zero-risk mass surveillance.