I wonder if China, Sudan, or Iran are included on the list of governments that they're allowed or willing to sell to. If so, the problems that arise from trusting too many Certificate Authorities would also apply to trusting too many governments.
I wonder if China, Sudan, or Iran are included on the list of governments that they're allowed or willing to sell to. If so, the problems that arise from trusting too many Certificate Authorities would also apply to trusting too many governments.
Worse yet, the company that makes these boxes advertised them at "the world's largest gathering of North American, Caribbean and Latin American Law Enforcement, Intelligence and Homeland Security Analysts and Telecom Operators responsible for lawful interception, electronic investigations and network Intelligence gathering." Any Mexican drug lord worth his cocaine money (or, of course, FARC) will now start bribing or scaring some suitable official into handing over a box or two.
Hopefully we'll discover an alternative approach to ensure online security. Just having fewer, more reliable CAs would be enough -- although, as I pointed out elsewhere, the measure of security is ultimately boots on the ground, not code in the aether.
Update: You're right, there's a trusted Chinese CA. From the Wired article: "[w]hen Mozilla added a Chinese company, China Internet Network Information Center, as a trusted Certificate Authority in Firefox this year, it set off a firestorm of debate, sparked by concerns that the Chinese government could convince the company to issue fake certificates to aid government surveillance."
Another problem is the sheer conceptual complexity of the system. It wouldn't take much to convince your boss to let you purchase an "SSL proxy" to fight viruses and commercial espionage, when all you really want is to steal all his passwords.
Sudan and Iran are "axis of evil" states anyway.
China has close trade relations with both.
No government can be blindly trusted no matter which one it is!