Reply to post: Clarification needed

Tor de farce: NSA fails to decrypt anonymised network

Anonymous Coward
Anonymous Coward

Clarification needed

"while SSL private keys can easily be swiped by asking the CA root to hand it over."

How? My understanding is that root CA's never see the private keys - they just sign the public key. This should mean that whilst they can issue fake certificates enabling MITM attacks they can't actually provide the private key to enable decryption of existing traffic.

So either the above understanding is incorrect. Or They have some secret methodology to obtain private keys from something the CA's have. Or They are doing MITM on a huge amount of traffic which seems unlikely as these should be easy(er) to spot...

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon