←back to thread

548 points mnot | 1 comments | | HN request time: 0.195s | source
Show context
5ersi ◴[] No.38112218[source]
If you are concerned by this proposals, then you should check out current CAs trusted by your browser - all those CAs can issue rogue certificates trusted by your browser, that can be used in MITM attack.

For example, CAs present in Firefox, that might give you pause: Beijing Certificate Authority, China Financial CA, Guang Dong CA

The CA system in browsers is inherently broken and it allows state actors to MITM you and see all your traffic if they: 1. have ability to capture IP traffic (requires cooperation with ISP) 2. have ability to generate rogue certificate via cooperation with CA

replies(5): >>38112296 #>>38112304 #>>38112316 #>>38112317 #>>38112423 #
andyjohnson0 ◴[] No.38112317[source]
> For example, CAs present in Firefox, that might give you pause: Beijing Certificate Authority, China Financial CA, Guang Dong CA

For someone living in the West, what are the consequences of deleting or distrusting those CAs?

replies(2): >>38112519 #>>38112751 #
1. g-b-r ◴[] No.38112519[source]
probably none

If you run into some websites which use them the browser will tell you that the certificate is invalid; you can always reinstall them if you prefer.