为提升您的使用体验,本站正在维护,部分功能暂时无法使用。如果本站文章无法解决您的问题,您想要向社区提问的话,请到 Twitter 上的 @FirefoxSupport 或 Reddit 上的 /r/firefox 提问,我们的支持社区将会很快回复您的疑问。

搜索 | 用户支持

防范以用户支持为名的诈骗。我们绝对不会要求您拨打电话或发送短信,及提供任何个人信息。请使用“举报滥用”选项报告涉及违规的行为。

详细了解

Serious New Privacy Issue

more options

I recently got seriously worried when I became aware about the new AI firewalls these days, which monitors or inspect SSL encrypted packets, before the packets reach to the main website. These new AI firewall systems are installed in some countries by their governments to suppress free speech, or just spy on its people. These firewalls, as you may already know, uses DPI-SSL system, which decrypts packets traveling from user to the main website. To decrypt the HTTPS packets, these firewalls uses its own self signed CA certificates. So I am asking the firefox developers, that why you guys allow this privacy issue? Does the packets sent from a firefoxe browser to other websites are also decrypted, by these firewalls? If yes, then why you guys allow this? Firefox must ONLY allow a specific CA certificate made for firefox browser only. Firefox browser must never let other third party softwares, or any software, to decrypt its encrypted packets. This is a serious privacy issue. With these firewalls, they can see what users write in chats, or posts, they can see witch content we are watching on a website, they can see who we follow on social media platforms, they can see which content or posts we like and etc. Even passwords are not safe anymore, which e use for any website of platform. When passwords are not safe, so does our accounts of various websites. This is a serious privacy breach.

These firewalls is a weapon for those countries which want to suppress free speech or suppress opposition sides in a government or spy on its own people.

Please let me know if I am mistaken or my concerns are genuine.

I recently got seriously worried when I became aware about the new AI firewalls these days, which monitors or inspect SSL encrypted packets, before the packets reach to the main website. These new AI firewall systems are installed in some countries by their governments to suppress free speech, or just spy on its people. These firewalls, as you may already know, uses DPI-SSL system, which decrypts packets traveling from user to the main website. To decrypt the HTTPS packets, these firewalls uses its own self signed CA certificates. So I am asking the firefox developers, that why you guys allow this privacy issue? Does the packets sent from a firefoxe browser to other websites are also decrypted, by these firewalls? If yes, then why you guys allow this? Firefox must ONLY allow a specific CA certificate made for firefox browser only. Firefox browser must never let other third party softwares, or any software, to decrypt its encrypted packets. This is a serious privacy issue. With these firewalls, they can see what users write in chats, or posts, they can see witch content we are watching on a website, they can see who we follow on social media platforms, they can see which content or posts we like and etc. Even passwords are not safe anymore, which e use for any website of platform. When passwords are not safe, so does our accounts of various websites. This is a serious privacy breach. These firewalls is a weapon for those countries which want to suppress free speech or suppress opposition sides in a government or spy on its own people. Please let me know if I am mistaken or my concerns are genuine.

所有回复 (3)

more options

What makes you think that we allow it? Please read "Certificate cannot be trusted" warning in Kazakhstan.

有帮助吗?

more options

TyDraniu said

What makes you think that we allow it? Please read "Certificate cannot be trusted" warning in Kazakhstan.


You are talking about certificate installation on user device, but I am talking about self signed certificate installed on ISP server, for those new AI firewalls, which can decrypt packets, coming from user device and going to main website.

有帮助吗?

more options

TyDraniu said

What makes you think that we allow it? Please read "Certificate cannot be trusted" warning in Kazakhstan.

OK, I now I understand what you said. The certificate must be installed on user devices too, to work properly. Thanks for clearing this issue. I was so much concerned about this issue.

有帮助吗?

我要提问

您需要登录才能回复。如果您还没账号,可以提出新问题