Hacker News new | past | comments | ask | show | jobs | submit login

If u have a state-owned, state-run DNS service with a root zone and cooperation (forced or not) from ISPs, you really would not have to care about https, and if CT services are not reachable nobody would know.



How would that work ?

Aren't there private and public keys involved ? Public keys are pre-packaged with clients (Firefox/Chrome/etc), so the state can't just change or fake the private keys.

Maybe they would force all clients to prepackage a government key and then change all infrastructure to pretend all websites use this public key for their https traffic?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: