@GossiTheDog yeah this was one that got me blocked for an opinion on country controlled rootCAs…: @mattblaze Clipper chip was certainly not bulk collection either, and rouge CAs are always around, ie. Wosign, Qaznet. Since no normal user keeps track of what root CAs are signing certs and devices trust all kinds of state owned or influenced CAs, PKI is much more of a risk than the Clipper ever was, and I can’t think of one commercial site using SSL or TLS mutual authentication, so it is inherently being used for encyption only. User trust comes from a green padlock.