

Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- Move related with wildberries attacks probablyby pvaldes
- > The banks came back in disguise, repackaging their apps as coupon trackers
That’s a wild move by a bank. How is the place not overrun with scams?
by Havoc - If you scam Russian citizens, you are defenestrated. If you scam foreign citizens, they don't care.by inigyou
- Might as well merge them all and call FSBank, for they will be sure as hell MITMing all the communication between clients and backends.by wartywhoa23
- Nope, MitMing will be done by the SORM system [0] using certificates signed by the Ministry of Digital "Development" which will be trusted the Yandex Browser, which will be widely installed out of necessity by ordinary Russians to access banks and subsequently other Web resources.
Surely this will improve user security and trust in the existing Web PKI system in non-Western countries. /s
by fuoqi - They don't need to. These are politically connected entities.by inigyou
- I have very little reason to believe that NSA is not doing, and had been doing that, more or less for as long as there had been CA. And on a global scale. If you don't find this plausible, it is because usually americans believe their predator state to be some kind of a "lion king" (aka superman, spiderman. etc), while it is more of a laughing hyena.by whosdat
- Based on the timing, I assume this is a direct response to the US state directed revocation of certificates of Iran's Fars News Agency.by jackb4040
- This is probably the future. Who is better able to verify an identity than a state? State run registrars regulate companies. States issue individuals ID documents. If you have trusted central parries issue encryption certificates it will gravitate to fewer and more centralised issuers.
Decentralised systems such as ssh are different, but I find it hard to imagine trusted central authorities ending up as anything other than states, or so heavily regulated as to be effectively state be controlled. This wax always the big flaw in SSL/TLS. In DNS too.
by graemep - Downvotes but no counter arguments? DO people think I am wrong but cannot be bothered to explain why, or are people shooting the messenger, or have poor reading skills and interpret prediction as advocacy? Genuinely curious.by graemep
- Of course. Who else would be their CA? Some USA state-run CA? That's far too much political risk.
I hope we see a different CA for each ccTLD in the future.
by inigyou - >I hope we see a different CA for each ccTLD in the future.
Completely agree with this and IMO it's how the system should've operated from the very start. Unfortunately, I highly doubt that the CA cartel will let go of the power (and associated cash flow) voluntarily.
by fuoqi