Theme 1 – Countries are building (or planning) their own certificate authorities to escape US control
- “They could stand up their own version of Let's Encrypt with less than 20 people and $5M/year. It is inevitable.” – toomuchtodo
- “So now that SSL certificates are being weaponized it now becomes a matter of national security for any country to have their own independent CA infra.” – Daishiman
- “Sure they can, but very importantly, so far the US has not forced them to for extremely good reasons.” – lxgr
Theme 2 – State‑run CAs enable government surveillance and increase MITM risks
- “It’s not merely about setting up a CA. The CA certificates would have to be added to the trust stores of every operating system, browser, framework, and application, creating a sea of security risks for the public.” – misano
- “Much worse, this will greatly improve their position with regards to wiretapping their own citizens.” – lxgr
- “CAs is the problem. Not who runs them… For 99% of all sites today security would be handled better without CAs.” – AtNightWeCode
Theme 3 – US sanctions are seen as either justified or counter‑productive, pushing nations toward alternative tech ecosystems
- “I worry this kind of action will just lead to the eventual rise of an alternative tech ecosystem in the long term, probably led by china and Russia. It will be bad for us, bad for people living under those regimes, but good for the regimes themselves because they will have the fullest control over their technology, without having to compromise with the West.” – pibaker
- “If Iran, China, North Korea, and Russia want to get together and create their own crappy Intranet that nobody uses, well, more power to them.” – ericmay
- “I think United States should be sanctioned.” – swat535