Runet, as usual, is full of tragedy jokes: [lang=ru] https://tjournal.ru/p/rkn-wikipedia-block-bloggers
Runet, as usual, is full of tragedy jokes: [lang=ru] https://tjournal.ru/p/rkn-wikipedia-block-bloggers
The massive elephant in the room is the cert authorities..
And if anyone's aware of any ISP anywhere in the world, doing a MITM with a certificate that passes validation, they should really shout about this as loud as they can (or at least whisper to someone who can shout), because it concerns virtually everyone on the Internet.
The question in this case is not whether some CA is compromised or malicious, but whether the entities involved have access to such a CA and are willing to use that access.
Also, a very wide-scale HTTPS MITM is more likely every month to be detected because there are more and more people looking for it. That may not be true of small-scale MITMs for some time, but it's probably true, for example, for a large-country-wide attack against a major site -- especially a site used by lots of technically sophisticated people who've been given prior warning that something sketchy is going to happen on a particular date!
The bad thing is that some ISPs MITM (with obviously invalid self-signed certificate, not even matching CN/DN of the domain being proxied) instead of completely dropping all tcp/443 traffic.
Not that it's bad intent to try to provide access to the non-blacklisted pages, but it's an absolutely harmful practice of teaching users to click the knobs "aw, ignore those errors, I want to read the site".