Earlier quoted context omitted.
I have a question about this -- maybe I'm ignorant. But using https without self-signed keys actually allows the government to peer into your communications, doesn't it? We are worried about third parties stealing your data between you and your bank for example. A bank might be a bad example as they probably already have access to their databases for compliance reasons. Can't the US government ask for the keys of the…
They don't even need to ask for the keys. Pretty much every OS/browser comes with root CAs belonging to the U.S. government (on OS X I see "DoD Root CA 2" and "DoD CLASS 3 Root CA", see also http://support.apple.com/kb/HT4415 ). As I understand it, if they wanted to, they could MITM any HTTPS connection by forging a certificate using their root CAs. This is why people were upset when a root CA for some Chinese govern…
This might not be a laymen solution, but it's a very simple procedure in most browsers.