> CN = D-TRUST Root CA 3 2013 > O = D-Trust GmbH > C = DE
There is certificate transparency and pinning and so on, and they would be caught (probably, maybe) if they abused this carelessly and at scale, but in practice, for a small number of targets, it would be trivial to wait for users to connect to a less secured TLS site or even a plain-HTTP site (plenty still exist), and then use a browser exploit as the stage 1, followed by whatever escalation of privilege exploit and rootkit is needed. TLS is really good at preventing always-on dragnet surveillance of everyone's internet traffic, but not a counter measure against targeted nation state level attacks.
Or is cert pinning something different than HPKP?
- [1]: https://security.stackexchange.com/questions/213410/did-goog...
It's actually pretty scary seeing just how many CAs are in the list of trusted CAs on any given device. While no government is beyond reproach, I do wish there were a way for me as a user to say "don't trust anything signed by CAs outside of these few countries, since it's most likely a hijack, phishing, or in the rare case that I did try to visit some random site, I can approve it manually."
https://bugzilla.mozilla.org/show_bug.cgi?id=1232689
The answer is basically "no".
I don't think that they would use that certificate for MITM. They're not fools and they understand that it would lead to blacklisting it which would halt a lot of operations in the country.
Is it, though? Germany has a lot more economic leverage than Kazakhstan. Suppose they pass a law requiring any browser sold or otherwise offered on the German market to have the government certificate in the chain of trust... how many large companies would cave?
"What can you learn from an IP?" https://irtf.org/anrw/2019/slides-anrw19-final44.pdf
Looking at some of Citizen Lab’s excellent reporting on FinFisher shows that victims were redirected to regular unencrypted http downloads when the malware was installed.
One of the examples given was when a user tried to download Avast antivirus from a well-known software hosting site and the download was done over http.
There are several security sites that have downloadable packet captures of malware infections where you can see in Wireshark that redirects are commonly used.
They should maybe give bigger warnings, but lets not break all of the old web just to protect a few more people against themselves.
No-frills data means a lot nowadays.