Live data from Hacker News

Seven Russian banks have moved to a certificate authority run by the state

en.zona.media

31–37 of 37 posts

Re: Seven Russian banks have moved to a certificate authority run by the state

#31
post #24
post #17

Earlier quoted context omitted.

Downvotes but no counter arguments? DO people think I am wrong but cannot be bothered to explain why, or are people shooting the messenger, or have poor reading skills and interpret prediction as advocacy? Genuinely curious.

People on HN are resistant to government power, but fail to realize the US government having power over Russia (via CAs) is worse than the Russian government having power over Russia.

Even that goes beyond what I was saying, and its a matter of PoV - Americans would presumably prefer their government to have more power over other countries in at least some cases, and very likely with regard to Russia.

I am not saying its a good thing and I strongly implied that it is a bad thing (I referred to it as a "flaw"). Surely the anti-government power people on HN should agree with me? I am warning of an expansion of government power. They might not like it, but no one likes warnings.

Re: Seven Russian banks have moved to a certificate authority run by the state

#32
post #18

Earlier quoted context omitted.

I have very little reason to believe that NSA is not doing, and had been doing that, more or less for as long as there had been CA. And on a global scale. If you don't find this plausible, it is because usually americans believe their predator state to be some kind of a "lion king" (aka superman, spiderman. etc), while it is more of a laughing hyena.

Russians would often fend this off by saying "the CIA major is farther than the FSB one". But of course there's little reason to doubt that all public-facing separation between world's secret services is but a spectacle, just like the idependence of CAs. Not only that, but also all encryption running in OSes that run above lower level, battery-powered SoCs with full network stack like Intel ME, AMD PSP and ARM TrustZ…

Oh, really? That's interesting.

But as they say, the chain is as strong as its weakest link.

Re: Seven Russian banks have moved to a certificate authority run by the state

#33
post #22
post #16

Earlier quoted context omitted.

>Nope, they do it primarily out of necessity, because of the mounting pressure on the previously used CAs. The MitM capability is just a nice side bonus. So the West essentially helps Kremlin to control Russian citizens. Why is that? Incompetence or something else?

Allowing Russia to have a TLD is also helping the Kremlin control Russian citizens. Do you recommend that IANA should delete the .ru domain?

How so?

Re: Seven Russian banks have moved to a certificate authority run by the state

#34
post #33
post #22

Earlier quoted context omitted.

Allowing Russia to have a TLD is also helping the Kremlin control Russian citizens. Do you recommend that IANA should delete the .ru domain?

How so?

it lets them have websites, where they can impose controls via the internet, obviously. Should we delete .ru?

Re: Seven Russian banks have moved to a certificate authority run by the state

#35
post #23
post #13

> The banks came back in disguise, repackaging their apps as coupon trackers That’s a wild move by a bank. How is the place not overrun with scams?

If you scam Russian citizens, you are defenestrated. If you scam foreign citizens, they don't care.

I remember reading here about the viruses that would uninstall themselves if they detected a Cyrillic language configured on the OS.

Re: Seven Russian banks have moved to a certificate authority run by the state

#36
post #34
post #33

Earlier quoted context omitted.

How so?

it lets them have websites, where they can impose controls via the internet, obviously. Should we delete .ru?

You are not making sense. What controls? They can only ban your domain name and if they do that, you already have a bigger problem.

It's not a surprise for you, you used you passport when registering the domain name and if you planned to do something Kremlin wouldn't like you could've registered it via a foreign registrar and used foreign hosting.

Contrarily, when you have to install Kremlin's root certificate to access your bank, you are unwittingly allowing Kremlin to quietly MitM any connection you make (without them specifically targeting you) and to avoid that you need:

- to be aware of the problem,

- to install those certs in a separate browser or on a separate device which you'd use only to visit your bank and state services

Re: Seven Russian banks have moved to a certificate authority run by the state

#37
post #3

Earlier quoted context omitted.

Nope, MitMing will be done by the SORM system [0] using certificates signed by the Ministry of Digital "Development" which will be trusted the Yandex Browser, which will be widely installed out of necessity by ordinary Russians to access banks and subsequently other Web resources. Surely this will improve user security and trust in the existing Web PKI system in non-Western countries. /s [0]: https://en.wikipedia.org…

> Surely this will improve user security and trust in the existing Web PKI system in non-Western countries. /s I recognize that Russia is making this change for MitM spying, but this particular sarcasm seems incorrect. Given Verisign's willingness to bend the knee to Texas courts, one could reasonably lose faith in US PKI issuers such as Digicert. I certainly hope the EU is studying the problem US-controlled EU-trust…

> I certainly hope the EU is studying the problem US-controlled EU-trusted issuers

cough DE-CIX cough CIA cough

Post reply on HN