Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Why?

Verisign merely signs your certificate. It does not even know your private key and hence also can't pass it to governments.



It is not necessary for the government to have your key; They can impersonate your site (using their own key) if they have the cooperation of the CA.


The trick is that if this were being done on a regular/wide basis, people would notice and have pretty incontrovertible evidence of it.

I have no doubt they can do it, but it seems to be consigned to their bag of tricks for special occasions.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: