logoalt Hacker News

mariusor • yesterday at 2:39 PM • 1 reply • view on HN

I think we have pretty decent examples where browsers remove malicious root certificates if they have been so proven. Do you think the matters will be different if those belong to a country level root?


Replies

Yizahi • yesterday at 8:14 PM

And I think we have pretty decent examples of all kinds of initiatives where governments (or corporations) promise not abuse something which clearly can be abused, and then proceed to do just that. In the age of "cheques and bank balances" and continuous degradation of parliamentarism and judicial systems in multiple developed countries, I don't have much hope for "if the abuse will happen, we will fix it afterwards" promises. Rather, I expect it to be immediately normalized and then made worse. Yesterday we (IT) were talking how government can abuse information requests. Today we have government just sifting through almost everything unencrypted in real-time with zero shame. Tomorrow we will lose E2EE in most big countries and no one would "fix that" or roll back (it's already slowly happening in UK for example).