The Spy in the Middle
crypto.com
crypto.com
I wonder if China, Sudan, or Iran are included on the list of governments that they're allowed or willing to sell to. If so, the problems that arise from trusting too many Certificate Authorities would also apply to trusting too many governments.
Worse yet, the company that makes these boxes advertised them at "the world's largest gathering of North American, Caribbean and Latin American Law Enforcement, Intelligence and Homeland Security Analysts and Telecom Operators responsible for lawful interception, electronic investigations and network Intelligence gathering." Any Mexican drug lord worth his cocaine money (or, of course, FARC) will now start bribing or scaring some suitable official into handing over a box or two.
Hopefully we'll discover an alternative approach to ensure online security. Just having fewer, more reliable CAs would be enough -- although, as I pointed out elsewhere, the measure of security is ultimately boots on the ground, not code in the aether.
Update: You're right, there's a trusted Chinese CA. From the Wired article: "[w]hen Mozilla added a Chinese company, China Internet Network Information Center, as a trusted Certificate Authority in Firefox this year, it set off a firestorm of debate, sparked by concerns that the Chinese government could convince the company to issue fake certificates to aid government surveillance."
Another problem is the sheer conceptual complexity of the system. It wouldn't take much to convince your boss to let you purchase an "SSL proxy" to fight viruses and commercial espionage, when all you really want is to steal all his passwords.
Sudan and Iran are "axis of evil" states anyway.
China has close trade relations with both.
No government can be blindly trusted no matter which one it is!
How much money and what kind of resources would it take some to really create their own valid CA just for generating forged yet valid certs that browsers would not flag as invalid when used in a MITM such as those used by the device in the wired article?
If you're willing to handle all of the key management yourself and you are only accepting certificates that you know you control... and you know for a fact that nobody snooped your private key from the signing station... and you never stored the signing key on any persistent storage in the clear... and you implicitly trust all connecting clients to not be spoofing authentication to users, and, and... Then you can say truthfully that you think you can trust certificates signed by that key maybe.
i think with time, patience, and an apparent genuine interest in doing things the right way, anyone could get mozilla to accept their root certificate. (and then generate certs for the black market for unauthorized people with loads of cash)