How to nab a HTTPS cert for a stranger's website: Step one, shatter those DNS queries...

Re: Fundamental design

"...has to be cryptographically secure."

But worse comes to worse, the TLAs can dirty the communications channels to be sure the process can NEVER be cryptographically secure: turning it into a DoS attack. IOW, if they can't sniff the channels, they can block them instead, which amounts to the least-bad scenario for them.

