3 ms·
A good question to be asked might be why we are still conflating the certificate store used for software signing with the certificate store for domain validatio
by uxp 9y ago
A good question to be asked might be why we are still conflating the certificate store used for software signing with the certificate store for domain validation. They're two entirely different problem domains using the same tool. Much like it doesn't make sense to use a drywall screw to join eyeglass frames together despite both attachment mechanisms requiring screws, it doesn't make sense to allow a system to validate a web domain as being trustworthy because an audio driver requires a certificate trust to validate itself as being legitimate.
Most of this separation is done on good-faith already, but it should be done in a more discrete manner.