4 ms·
The TL;DR of this whole thing * Root CA practice allows delegating validation to 3rd parties * However, the Root CA must accept all responsibility for any mis
by hackcasual 10y ago
The TL;DR of this whole thing
* Root CA practice allows delegating validation to 3rd parties
* However, the Root CA must accept all responsibility for any mis-validation the 3rd parties do. No throwing them under the bus
* Symantec delegates validation to 4 different companies to serve local markets
* Said companies fail to adequately validate domain ownership
* Symantec attempts to throw them under the bus
Further compounding the issue is that there is no way to separate the certificates that had more rigorous validation than the ones validated by these 4 companies