A government could create a new certificate for any domain without having ownership of the domain or permission of the owner. This way they can perform Man-in-the-middle attacks.
In such an attack someone intercepts the traffic of a client and presents their own certificate.
Because a government can create a universally accepted certificate, thise would be accepted as valid. The traffic can then be decrypted and forwarded to the real website. The attacker is now between the client and the real host (the Man in the middle) and can view the unencrypted traffic.
There are also the colored circles 🔴,⭕ and 🟢. The worst part for me is that while the emojis are technically one char in code, they are usually displayed with a 2-char-width.
A government could create a new certificate for any domain without having ownership of the domain or permission of the owner. This way they can perform Man-in-the-middle attacks.
In such an attack someone intercepts the traffic of a client and presents their own certificate.
Because a government can create a universally accepted certificate, thise would be accepted as valid. The traffic can then be decrypted and forwarded to the real website. The attacker is now between the client and the real host (the Man in the middle) and can view the unencrypted traffic.