Re: Nation State MITM CA's ?

2019-07-20 Thread Jakob Bohm via dev-security-policy
On 21/07/2019 03:21, My1 wrote: Hello everyone, I am new here but also want to share my opinion about some posts here, I know it's a lot of text but I hope it's not too bad. Am Freitag, 19. Juli 2019 23:42:47 UTC+2 schrieb dav...@gmail.com: Wouldn't it be easier to just decree that HTTPS is

Re: Nation State MITM CA's ?

2019-07-20 Thread Jakob Bohm via dev-security-policy
On 20/07/2019 09:31, simc...@gmail.com wrote: I think it must be quickly blacklisted by Google, Mozilla and Microsoft all together, because it is known as a state scale MITM affecting citizen "real" life. The purpose of https is being defeated and such companies who tried to improve network

Re: Nation State MITM CA's ?

2019-07-20 Thread My1 via dev-security-policy
Am Sonntag, 21. Juli 2019 03:31:03 UTC+2 schrieb sim...@gmail.com: > I think it must be quickly blacklisted by Google, Mozilla and Microsoft all > together, because it is known as a state scale MITM affecting citizen "real" > life. > > The purpose of https is being defeated and such companies

Re: Nation State MITM CA's ?

2019-07-20 Thread simchat--- via dev-security-policy
I think it must be quickly blacklisted by Google, Mozilla and Microsoft all together, because it is known as a state scale MITM affecting citizen "real" life. The purpose of https is being defeated and such companies who tried to improve network security for past decade have to react (yes,

Re: Nation State MITM CA's ?

2019-07-20 Thread peridiane--- via dev-security-policy
It would allow people who are using VPNs and other alternative access strategies to realize that they forgot to turn it on/etc On Friday, July 19, 2019 at 11:26:43 AM UTC-4, muc...@wirade.ru wrote: > Well, then users will just get accustomed to seeing this indication on > corporate sites and

Re: Nation State MITM CA's ?

2019-07-20 Thread My1 via dev-security-policy
Hello everyone, I am new here but also want to share my opinion about some posts here, I know it's a lot of text but I hope it's not too bad. Am Freitag, 19. Juli 2019 23:42:47 UTC+2 schrieb dav...@gmail.com: > Wouldn't it be easier to just decree that HTTPS is illegal and block all > outbound