Hacker News new | ask | show | jobs
by sacrosanct 882 days ago
> Decrypt https traffic?

HTTPS/TLS prevents MITM attacks, but rogue certificates can be installed to sniff the plaintext, but that's exceedingly rare and hard to do. IANAC (I am not a cryptographer) and that's the best 2 cents I can manage, sorry. But things like DNS can be sniffed off the wire easily, and anything in plaintext HTTP is fair game.

1 comments

> but that's exceedingly rare and hard to do

It could be possible that the government just requests certificate keys from the relevant tech company.