Earlier quoted context omitted.
Oh yeah if encryption is broken only for browsers no big deal right
Governments still can't see your requests to servers under normal circumstances with this law. The weakness is only if someone controls your internet connection and can use a compromised certification process to trick you into thinking you are at "e2e.com" when you are on another site, and in those cases the only difference from now is that your browser will display "secure" instead of "invalid cert". There is no oth…
Oh that's SUCH as an insignificant difference!!!
> So to orchestrate an attack they would need to build an webbapp that is sufficient similar for you not to notice, take over your internet connection and break the certification process.
You can simply relay the requests to the original site/"webapp", no need to build one similar