3 ms·
Security is not obtained by optimistically assuming actors are using their capabilities for good. Sure, there are legit ways they could use this, but the entire
by devishard 10y ago
Security is not obtained by optimistically assuming actors are using their capabilities for good. Sure, there are legit ways they could use this, but the entire point of CAs is that they be trusted actors, and there are very strong reasons not to trust Blue Coat.
Your comment is like discovering the fox has been given the keys to the henhouse and saying "Maybe the fox just wants to hang out with the hens".
- mhkool 10y agoIt is now simply a matter of time. How long will it take to find out that this certificate was used for a MITM attack? I suspect it will be less than 18 months. And 99% of the people will be 'shocked' :-)