This would basically ruin online banking.
Besides, OpenSSL is not the problem. It's just a library which implements lots of cryptographic functions. SSL/TLS isn't broken because of some software problem, but because the CAs can be coopted.
It's like with secure boot. By itself, SB is a great technology to make sure customs-officer can't replace your kernel with his own without you noticing. However, SB relies on microsoft to sign bootable executables, and MS is going to sign whatever the FBI wants to be signed. Of course everyone could use his own keys, but nobody does, cuz it requires some learning. Heck, people don't even compare GPG fingerprints most of the time.
I agree with your CAs being coopted point.
I would encourage you to watch this video: https://invidio.us/watch?v=3jQoAYRKqhg
Edit: Also, it wouldn't break online banking. A I understand it, encryption can still be used, but it must be encryption protocols which are backdoored by the govt/can be bypassed in some way by the govt.
Kek, I've posted the same video 8 months ago: https://poal.co/s/Helicoptarian/113013
Online Banking
Imagine being an enemy state and having some spy in the FBI who send you a copy of the keys that enable you to access the backdoor interface for interbanking communications. You know, they have this network over which they synchronize their transactions. Now you can make up transactions, or maybe even write numbers into bank accounts.
Or, let's go back a step, and say, that they can only authenticate their own servers as being legit. You know, like fishing. Next time George Soros pays his electric bill, he connects to a spoofed server, which acts as a man in the middle to the real banking server. What would you do, if it were your server?
Ha! Didn't see that post -- very nice.
A very interesting point indeed. I'm sure the US govt would try to make it hard for such a leak to occur, but I admit I have a hard time imagining how they would prevent it.
(post is archived)