|
|
|
|
|
by yk
4742 days ago
|
|
Perfect forward secrecy would prevent some attacks against Google, as does certificate pinning in Chrome. But if the NSA got somehow Google's secret key, they can still MITM a SSL connection. It just means, that they actually need Google's secret key, instead of using a CA under their control. ( And they need this key before they can MITM any connection.) And the entire secure connection stuff is broken, if the NSA just obtains a FISA warrant for your GMail account. ( Or compromises the Google servers directly.) |
|
Note that Google runs their own CA (signed by Equifax's Root CA) and, thus, issues their own certificates.
The way things are going, I see no reason why the NSA could not, with a FISA warrant, simply order Google to:
1. provide them with a copy of Google's CA's private key; or, 2. issue the NSA a certificate valid for *.{every-google-domain}.com.
Maybe they can.
Maybe they have.