Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yes, but after the damage was done and only because the damage happened to be uncovered.


Well, obviously yes.

The CA/B mailing list can't do much about shady behaviour they don't know anything about.

I do trust in Mozilla to ensure that the game rules for CAs are strict enough that my trust in the green lock isn't 0. It's not 100% either but it's above 50%. When I connect to a website and it has SSL, I'm fairly certain it's the right place.

Most likely there will never be a replacement for it, any PKI requires some third party to vouch for an endpoint otherwise you get easy MitM (I believe there is a proof floating around somewhere from the area of Signal Theory).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: