3 ms·
So they're done, right? Why should we not immediately un-trust their root?
by captncraig 10y ago
So they're done, right? Why should we not immediately un-trust their root?
- pfg 10y ago"Too big to fail" would be the usual argument. They're currently the third-largest CA in the industry. Pulling the root completely would desensitize a lot of users to the error interstitials, causing more harm than good. However, a number of browsers now have experience with distrusting CAs only after a certain cut-off date while still accepting old ones (and some even make an attempt to prevent the CAs from bypassing that check by backdating certificates), so Symantec is certainly treading on thin ice.