2 ms·
Security requires that ALL CAs be secure, since any compromised CA can compromise all websites (barring fragile schemes like pinning or certificate transparency
by devit 9y ago
Security requires that ALL CAs be secure, since any compromised CA can compromise all websites (barring fragile schemes like pinning or certificate transparency checks), so the less CAs there are, the more secure the system is.
It's like a building that needs secure doors: it's better to invest in a single, massive, bulletproof, guarded door rather than inviting anyone who meets some standards to add a door to the building, since what matters is the weakest door.
- manigandham 9y agoThe proper solution is to actually make sure the CAs are secure, it doesn't matter if there are 1 or many. Also more CAs mean that any problems are only localized to their certificates instead of the entire internet.
- jopsen 9y agoCertificate transparency seems like it'll make a compromised CA much less of an issue. If it can be reliably proven that a CA is compromised, then it can be fixed.