Controlling the certs doesn’t control the keys. Access to the keys is necessary to inspect the traffic. Even without government control of the root certificates, if they can access the keys, they can decrypt the traffic.
Now, controlling the certs can open you up to MITM, but that’s a risk no matter who controls the root.
Controlling the certs doesn’t control the keys. Access to the keys is necessary to inspect the traffic. Even without government control of the root certificates, if they can access the keys, they can decrypt the traffic.
Now, controlling the certs can open you up to MITM, but that’s a risk no matter who controls the root.