On Mon, Jul 22, 2019 at 9:20 PM Corey Bonnell via dev-security-policy <
dev-security-policy@lists.mozilla.org> wrote:

>
> I think the optimal solution in terms of user security is to create a
> blacklist of known MITM CA public keys and simply prevent the installation
> of certificates containing these public keys in the trust store. If several
> browsers could coordinate on such an effort, then perhaps that would
> pressure the government to back down on their demand to intercept TLS
> communications because their root is would be incompatible with major
> browsers.
>

It is an interesting question.  It essentially becomes a gamble on whether
they'll back down or just fork their own KazakhFox.  But if they do push
this all the way with a national browser, then their people are even
further worse off.
_______________________________________________
dev-security-policy mailing list
dev-security-policy@lists.mozilla.org
https://lists.mozilla.org/listinfo/dev-security-policy
  • Re: Nation State MITM CA'... starosekpd--- via dev-security-policy
    • Re: Nation State MIT... Wayne Thayer via dev-security-policy
      • Re: Nation State... Wayne Thayer via dev-security-policy
        • Re: Nation S... Matthew Hardeman via dev-security-policy
          • Re: Nati... Andrew via dev-security-policy
            • Re:... Matthew Hardeman via dev-security-policy
              • ... gewalopdrbat--- via dev-security-policy
              • ... healthyelijah--- via dev-security-policy
              • ... Corey Bonnell via dev-security-policy
                • ... Matthew Hardeman via dev-security-policy
                • ... jfb1776--- via dev-security-policy
                • ... whateverusernameforme--- via dev-security-policy
            • Re:... wolfgang.richter--- via dev-security-policy
              • ... mucius--- via dev-security-policy
                • ... peridiane--- via dev-security-policy
              • ... Troy Cauble via dev-security-policy
                • ... Matthew Hardeman via dev-security-policy
                • ... bayden--- via dev-security-policy
                • ... Jakob Bohm via dev-security-policy
                • ... My1 via dev-security-policy

Reply via email to