Russia attempts mandating installation of root CA on clients for TLS MITM

William Herrin bill at herrin.us
Thu Mar 10 23:02:31 UTC 2022


On Thu, Mar 10, 2022 at 10:26 AM Eric Kuhnke <eric.kuhnke at gmail.com> wrote:
> https://bugzilla.mozilla.org/show_bug.cgi?id=1758773
>
> I think we'll see a lot more of this from authoritarian regimes in the future. For anyone unfamiliar with their existing distributed DPI architecture, google "Russia SORM".

Point of clarification: what's happening is that Russian web sites'
certificates are expiring and because of the sanctions, their CAs are
refusing to renew them. So, Russia has spun up their own CA which is,
of course, only present in Russian web browsers.

Regards,
Bill Herrin


--
William Herrin
bill at herrin.us
https://bill.herrin.us/


More information about the NANOG mailing list