3 ms·
On the "CAs is controlled by state" side, some privacy enthusiasts in China already removed those CAs from their system long ago. Go give them some hug and supp
by rqs 8y ago
On the "CAs is controlled by state" side, some privacy enthusiasts in China already removed those CAs from their system long ago. Go give them some hug and support: https://github.com/chengr28/RevokeChinaCerts https://github.com/chengr28/RevokeChinaCerts
And of course, in the context of CA, what's truly important is transparency in the audit process and continuous monitoring. Catch them red handed will end their business[0] once and for all. And so far, most of them are rule-abiding.
[0] https://blog.mozilla.org/security/2016/10/24/distrusting-new-wosign-and-startcom-certificates/ https://blog.mozilla.org/security/2016/10/24/distrusting-new...
- gsnedders 8y agoAnd it's a question of when, and not if, we require CT logs for every certificate the browser sees.