Posted Mar 25, 2010 20:48 UTC (Thu) by blitzkrieg3
In reply to: Multiple authorities
Parent article: Blaze: The Spy in the Middle
It's worth pointing out that, from the perspective of a law enforcement or intelligence agency, this sort of surveillance is far from ideal. Although current browsers don't ordinarily detect unusual or suspiciously changed certificates, there's no fundamental reason they couldn't (and the Soghoian/Stamm paper proposes a Firefox plugin to do just that).
I would absolutely LOVE to see this. I had no idea that the CA's were willing to sign certs for governmental agencies, but that information is actually not that surprising.
to post comments)