Switch language한국어
Back to the list

Parallel Reconstruction of Lawful TLS Wiretapping | Hacker News

TL;DR AI

Key summary

2 min read
  1. A Hacker News thread discussed whether rerouted traffic for jabber.ru could let an attacker obtain a valid TLS certificate through normal issuance, without compromising a CA.

  2. Commenters debated how well Certificate Transparency can expose this kind of interception, and whether an attacker could conceal it or later blame it on a server compromise.

  3. The discussion also focused on DNSSEC, ACME, and CA policy limits as possible defenses against traffic redirection and unauthorized certificate issuance.

  4. The topic matters because state actors or attackers may use BGP leaks or similar rerouting to obtain legitimate certificates and make TLS interception harder to detect.

Read the original