Live data from Hacker News

Seven Russian banks have moved to a certificate authority run by the state

en.zona.media

21–30 of 37 posts

Re: Seven Russian banks have moved to a certificate authority run by the state

#21
post #10

Earlier quoted context omitted.

>I recognize that Russia is making this change for MitM spying Nope, they do it primarily out of necessity, because of the mounting pressure on the previously used CAs. The MitM capability is just a nice side bonus. >So I empathize with the sarcasm, but best not to offer MitM proponents (whether in Russia or the U.S. or elsewhere!) an argument that could be used against your viewpoint. If browsers truly cared about u…

I’d be totally onboard with TLD-locking them to legal jurisdictions they’re comfortable being bound to, except that this would underserve a great deal of the Internet. Don’t really have a great solution yet, either. Perhaps as each TLD operates DNSSEC they could sign authorized issuers by publishing TLD CAA records, which would create some legal zone accountability that’s lacking today (and give the EU a lever by whi…

We should let each country specify trusted CAs the way they specify their DNS signing keys. Or we should just implement DANE already and then the same key serves both purposes and we can delete WebPKI from the world.

Re: Seven Russian banks have moved to a certificate authority run by the state

#22
post #16
post #10

Earlier quoted context omitted.

>I recognize that Russia is making this change for MitM spying Nope, they do it primarily out of necessity, because of the mounting pressure on the previously used CAs. The MitM capability is just a nice side bonus. >So I empathize with the sarcasm, but best not to offer MitM proponents (whether in Russia or the U.S. or elsewhere!) an argument that could be used against your viewpoint. If browsers truly cared about u…

>Nope, they do it primarily out of necessity, because of the mounting pressure on the previously used CAs. The MitM capability is just a nice side bonus. So the West essentially helps Kremlin to control Russian citizens. Why is that? Incompetence or something else?

Allowing Russia to have a TLD is also helping the Kremlin control Russian citizens. Do you recommend that IANA should delete the .ru domain?

Re: Seven Russian banks have moved to a certificate authority run by the state

#23
post #13

> The banks came back in disguise, repackaging their apps as coupon trackers That’s a wild move by a bank. How is the place not overrun with scams?

If you scam Russian citizens, you are defenestrated. If you scam foreign citizens, they don't care.

Re: Seven Russian banks have moved to a certificate authority run by the state

#24
post #17
post #4

This is probably the future. Who is better able to verify an identity than a state? State run registrars regulate companies. States issue individuals ID documents. If you have trusted central parries issue encryption certificates it will gravitate to fewer and more centralised issuers. Decentralised systems such as ssh are different, but I find it hard to imagine trusted central authorities ending up as anything othe…

Downvotes but no counter arguments? DO people think I am wrong but cannot be bothered to explain why, or are people shooting the messenger, or have poor reading skills and interpret prediction as advocacy? Genuinely curious.

People on HN are resistant to government power, but fail to realize the US government having power over Russia (via CAs) is worse than the Russian government having power over Russia.

Re: Seven Russian banks have moved to a certificate authority run by the state

#25
post #20
post #18

Earlier quoted context omitted.

I have very little reason to believe that NSA is not doing, and had been doing that, more or less for as long as there had been CA. And on a global scale. If you don't find this plausible, it is because usually americans believe their predator state to be some kind of a "lion king" (aka superman, spiderman. etc), while it is more of a laughing hyena.

You can verify this for your own domains by using certificate transparency.

Wouldn't that be true also for the Russian CA?

Re: Seven Russian banks have moved to a certificate authority run by the state

#26
post #25
post #20

Earlier quoted context omitted.

You can verify this for your own domains by using certificate transparency.

Wouldn't that be true also for the Russian CA?

Yes, the banks can verify it for their own domains - unless Russia is sanctioned out of the CT logs or the government forces Yandex Browser not to check CT.

They can also just load the site from a separate internet connection and see if it has their certificate.

Re: Seven Russian banks have moved to a certificate authority run by the state

#27
post #26
post #25

Earlier quoted context omitted.

Wouldn't that be true also for the Russian CA?

Yes, the banks can verify it for their own domains - unless Russia is sanctioned out of the CT logs or the government forces Yandex Browser not to check CT. They can also just load the site from a separate internet connection and see if it has their certificate.

[deleted]

Re: Seven Russian banks have moved to a certificate authority run by the state

#28

Earlier quoted context omitted.

Don't think the cartel would go against a state

Browsers have to kowtow too ...

Browsers are the cartel. CAs have zero power against browsers, but browsers can poof CAs out of existence. And it's not really a cartel - it's a monopoly, it's Google and everyone else had better copy Google.

Re: Seven Russian banks have moved to a certificate authority run by the state

#29
post #18

Might as well merge them all and call FSBank, for they will be sure as hell MITMing all the communication between clients and backends.

I have very little reason to believe that NSA is not doing, and had been doing that, more or less for as long as there had been CA. And on a global scale. If you don't find this plausible, it is because usually americans believe their predator state to be some kind of a "lion king" (aka superman, spiderman. etc), while it is more of a laughing hyena.

Russians would often fend this off by saying "the CIA major is farther than the FSB one".

But of course there's little reason to doubt that all public-facing separation between world's secret services is but a spectacle, just like the idependence of CAs.

Not only that, but also all encryption running in OSes that run above lower level, battery-powered SoCs with full network stack like Intel ME, AMD PSP and ARM TrustZone.

Re: Seven Russian banks have moved to a certificate authority run by the state

#30
post #16
post #10

Earlier quoted context omitted.

>I recognize that Russia is making this change for MitM spying Nope, they do it primarily out of necessity, because of the mounting pressure on the previously used CAs. The MitM capability is just a nice side bonus. >So I empathize with the sarcasm, but best not to offer MitM proponents (whether in Russia or the U.S. or elsewhere!) an argument that could be used against your viewpoint. If browsers truly cared about u…

>Nope, they do it primarily out of necessity, because of the mounting pressure on the previously used CAs. The MitM capability is just a nice side bonus. So the West essentially helps Kremlin to control Russian citizens. Why is that? Incompetence or something else?

Just some Nanay Boys wrestling.

https://www.youtube.com/watch?v=ztstTo3dVp4

Post reply on HN