Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

In general none of the disclosures of what GFW is doing g should be seen as evidence that western governments do not do the same thing. Hope nobody is drawing that conclusion.


Western governments do not routinely block VPNs.


Western governments effectively control 99% of consumer technology, and hack whatever else they can't have. VPNs are a false sense of security going up against a nation-sized adversary like the US.


They also can correlate packet streams in and out of the tor network.


Different phylosophy: why block VPNs when you can monitor them. Most Root CAs are in US.


Certificate transparency is mandatory in browsers; interception certificates appear in certificate logs to be accepted. Have you found one?

Edit: OCSP has been ended.


He might be referring to OCSP. Browsers ping CAs by default, revealing to them the sites that are visited.


OCSP is very much on the way out, this is hardly true anymore; although some things still check OCSP, many things do not.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: