top | item 43403398

(no title)

steego | 11 months ago

Seeing how we’re only a few months in, I think you’re wrong.

I can see their desire to circumvent the firewalls and monitoring infrastructure because it’s too complicated and/or they don’t know who they can trust yet.

discuss

order

Nextgrid|11 months ago

But on a purely technical level, doesn't TLS make all these concerns obsolete anyway?

steego|11 months ago

It doesn’t.

Many governments block TLS connections directly between a client and an external website. Instead, they’ll install a custom root certificate and all connections and intercept traffic, using the government root certificate for each TLS connection instead of the external website’s.

https://en.m.wikipedia.org/wiki/Deep_packet_inspection