GlobalSign and Let's Encrypt have started denying and revoking TLS certificates for websites of "Russian government-controlled entities", citing sanctions rules, and this is very bad because it means the Russian government will have more incentive to promote its government-controlled root CA, and citizens will have more incentive to install these. In turn, this means the Russian government would be able to MITM a lot of TLS traffic.
If these CAs become popular at any point, they can start banning any TLS traffic that doesn't use them, as Kazakhstan tried in the past.
https://en.wikipedia.org/wiki/Kazakhstan_man-in-the-middle_attack
Post #51
215