Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

About the MITM attack: TurkTrust, the only ssl certificate authority in Turkey, was recently involved in a huge scandal: http://nakedsecurity.sophos.com/2013/01/08/the-turktrust-ssl...

Do you think that it's possible for the government to force TurkTrust to generate fake certificates for Google & Twitter and intercept the SSL traffic using TTNET?

They did that, apparently by mistake, on the EGO(government company in Ankara) network by generating fake Google certificates.

Is there something to stop them from doing this on national level? I don't think the ISP's would reject cooperation.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: