This is super-dumb. The same thing is happening with Russian banks.
Their answer? They're now asking users to install root certs from the Russian ministry of communications. So it can now MITM all the encrypted traffic in Russia.
Their answer? They're now asking users to install root certs from the Russian ministry of communications. So it can now MITM all the encrypted traffic in Russia.
It's not that hard to find a CA in a more aligned regime.
Rolling your own MITM CA as a replacement just looks like something that was waiting for an excuse.