10 karma · joined February 26, 2020
It is right there in the first section of the article.
"In this discussion, we assume that we already know some basic properties of arithmetic operations such as the distributive property of multiplication over subtraction, existence of the additive inverse of real numbers, etc."
Not sure how that is relevant. DigiNotar was a trusted root CA in all major browsers. So if an attacker managed to get a fake certificate issued by DigiNotar, they could attack 100% of the users visiting the website for which the fake certificate was issued.
In fact, they did issue fake certificates by accident due to a security breach. As soon as the error was caught, their CA certificates were removed from all browsers. They went bankrupt! That's how serious this business of issuing certificates is.
How exactly would Google MITM half the SSL on the internet by virtue of issuing certificates via ACME?
The private key never leaves the subject's system (the system hosting a website for example). Google would never have access to the private key for which it would issue the public key certificate.
Further, if Google abuses its power by issuing a fake certificate for another website and uses that to MITM all traffic to that website, all browsers and systems would remove the offending CA certificates from their trust store immediately. Look what happened to DigiNotar.
It really shows how much the UX has deteroriated over these years. In early 2000s, Google was the hallmark for simplicity, speed and usability. Now it is ugly, bloated and clumsy!