Sanctions on Iran are justified. But I worry this kind of action will just lead to the eventual rise of an alternative tech ecosystem in the long term, probably led by china and Russia. It will be bad for us, bad for people living under those regimes, but good for the regimes themselves because they will have the fullest control over their technology, without having to compromise with the West.
Another example of why maximalist political hostility can be counterproductive. Leave an olive branch in sight, and you may work towards a mutually beneficial resolution, like the previous Iran nuclear deals. If push your opponent into a corner, then don't get upset when they jump over the wall into the wild where you can't catch them anymore. See also Chinese chips and AI.
show comments
lxgr
Forcing their customers to install government-affiliated alternative CAs, in turn allowing the government to spy on its citizens more easily via mis-issued certs? Great, that'll show them.
show comments
londons_explore
This seems like the kind of thing that the USA will explicitly grant an exception to.
It is clearly bad if the whole of Iran gets their own CA infrastructure which the NSA can't as easily spy on.
show comments
gonzalohm
I may speak from ignorance, but why do SSL certificates depend on centralized CA?
If I'm an entity such as a bank, I should be able to sign my own certificate and provide the public keys to my clients which then can use it to both encrypt communications and to make sure you are talking with the entity you want to talk to. Am I missing anything?
show comments
ValdikSS
The same applies to Russian banks. Russian banks have switched to internal Ministry of Digital Development CA which is not trusted in common browsers.
It is a reminder to go back to cash, ATMs and machines where you can enter you transactions instead of using the Internet.
There is no reason to give money to US middlemen for everything you do.
The whole of the EU should do this, too. I stopped using Internet banking after my bank moved from SMS Tan to hardware Tan generator (one of which didn't work) to forced mobile app. No thanks.
show comments
cestith
This seems like a bad idea.
MadrasTh0rn
Trump Vance Johnson Elon and Thiel are removing US institutions globally by force
Trump is intentionally playing into Chinese, Russian Noth Korean, Iranian hands
They must be impeached/removed regardless of intent
Nobody voted for this
badatnames
Utterly moronic. We support the freedom of the Iranian people by forcing them to install a local government root CA in every browser. I mean at this rate they won't even have to buy their monitoring tech from China any more, just an old PC and a late 90s tarball of Squid
show comments
dayyan
Good.
jMyles
It's bizarre that there isn't yet a total separation of certificate-and-state.
borschtplease
One more technical challenge. The whole ssl infrastructure is incompatible with a state current planet moves forward to.
yieldcrv
petty
cyberax
This is super-dumb. The same thing is happening with Russian banks.
Their answer? They're now asking users to install root certs from the Russian ministry of communications. So it can now MITM all the encrypted traffic in Russia.
show comments
Daishiman
So now that SSL certificates are being weaponized it now becomes a matter of national security for any country to have their own independent CA infra.
Another win for the US.
show comments
zoobab
It's not as if SSL critics warned about this ponzi pyramid, prone to censorship.
Sanctions on Iran are justified. But I worry this kind of action will just lead to the eventual rise of an alternative tech ecosystem in the long term, probably led by china and Russia. It will be bad for us, bad for people living under those regimes, but good for the regimes themselves because they will have the fullest control over their technology, without having to compromise with the West.
Another example of why maximalist political hostility can be counterproductive. Leave an olive branch in sight, and you may work towards a mutually beneficial resolution, like the previous Iran nuclear deals. If push your opponent into a corner, then don't get upset when they jump over the wall into the wild where you can't catch them anymore. See also Chinese chips and AI.
Forcing their customers to install government-affiliated alternative CAs, in turn allowing the government to spy on its citizens more easily via mis-issued certs? Great, that'll show them.
This seems like the kind of thing that the USA will explicitly grant an exception to.
It is clearly bad if the whole of Iran gets their own CA infrastructure which the NSA can't as easily spy on.
I may speak from ignorance, but why do SSL certificates depend on centralized CA?
If I'm an entity such as a bank, I should be able to sign my own certificate and provide the public keys to my clients which then can use it to both encrypt communications and to make sure you are talking with the entity you want to talk to. Am I missing anything?
The same applies to Russian banks. Russian banks have switched to internal Ministry of Digital Development CA which is not trusted in common browsers.
https://crt.sh/?id=22899279066 (Revoked: privilegeWithdrawn)
It is a reminder to go back to cash, ATMs and machines where you can enter you transactions instead of using the Internet.
There is no reason to give money to US middlemen for everything you do.
The whole of the EU should do this, too. I stopped using Internet banking after my bank moved from SMS Tan to hardware Tan generator (one of which didn't work) to forced mobile app. No thanks.
This seems like a bad idea.
Trump Vance Johnson Elon and Thiel are removing US institutions globally by force
Trump is intentionally playing into Chinese, Russian Noth Korean, Iranian hands
They must be impeached/removed regardless of intent
Nobody voted for this
Utterly moronic. We support the freedom of the Iranian people by forcing them to install a local government root CA in every browser. I mean at this rate they won't even have to buy their monitoring tech from China any more, just an old PC and a late 90s tarball of Squid
Good.
It's bizarre that there isn't yet a total separation of certificate-and-state.
One more technical challenge. The whole ssl infrastructure is incompatible with a state current planet moves forward to.
petty
This is super-dumb. The same thing is happening with Russian banks.
Their answer? They're now asking users to install root certs from the Russian ministry of communications. So it can now MITM all the encrypted traffic in Russia.
So now that SSL certificates are being weaponized it now becomes a matter of national security for any country to have their own independent CA infra.
Another win for the US.
It's not as if SSL critics warned about this ponzi pyramid, prone to censorship.