Seven Russian banks have moved to a certificate authority run by the state
Posted by mtty 1 hour ago
Comments
Comment by inigyou 2 minutes ago
Of course. Who else would be their CA? Some USA state-run CA? That's far too much political risk.
I hope we see a different CA for each ccTLD in the future.
Comment by graemep 34 minutes ago
This is probably the future. Who is better able to verify an identity than a state? State run registrars regulate companies. States issue individuals ID documents. If you have trusted central parries issue encryption certificates it will gravitate to fewer and more centralised issuers.
Decentralised systems such as ssh are different, but I find it hard to imagine trusted central authorities ending up as anything other than states, or so heavily regulated as to be effectively state be controlled. This wax always the big flaw in SSL/TLS. In DNS too.
Comment by wartywhoa23 1 hour ago
Might as well merge them all and call FSBank, for they will be sure as hell MITMing all the communication between clients and backends.
Comment by inigyou 1 minute ago
They don't need to. These are politically connected entities.
Comment by fuoqi 59 minutes ago
Nope, MitMing will be done by the SORM system [0] using certificates signed by the Ministry of Digital "Development" which will be trusted the Yandex Browser, which will be widely installed out of necessity by ordinary Russians to access banks and subsequently other Web resources.
Surely this will improve user security and trust in the existing Web PKI system in non-Western countries. /s