Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

And all examples of CAs essentially no longer in business (or bought up by DigiCert).


Yes, but after the damage was done and only because the damage happened to be uncovered.


Well, obviously yes.

The CA/B mailing list can't do much about shady behaviour they don't know anything about.

I do trust in Mozilla to ensure that the game rules for CAs are strict enough that my trust in the green lock isn't 0. It's not 100% either but it's above 50%. When I connect to a website and it has SSL, I'm fairly certain it's the right place.

Most likely there will never be a replacement for it, any PKI requires some third party to vouch for an endpoint otherwise you get easy MitM (I believe there is a proof floating around somewhere from the area of Signal Theory).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: