They'd grab some MITM hardware and force everyone (in their jurisdiction) to 'trust' their root cert.
For the rest of the world, where we try to be less blatant you're certainly correct. I for one would like to see something like tcpcrypt become standard.
Oh and the world looks like it's moving this way, see SPDY, which requires TLS (partially because that's the only way to get around the legions of broken proxies out there).
Posted Feb 16, 2012 15:18 UTC (Thu) by intgr (subscriber, #39733)
[Link]
> I for one would like to see something like tcpcrypt become standard.
Agreed. Sadly, it seems the tcpcrypt project is dead. The last commits in their github were in July 2011 and there has been only 1 post on their mailing list since May 2011. The last RFC draft was posted in August, but it's not clear when the last changes were made.