4 ms·
I think you’re interpreting my comment about trust too literally. If you’re talking about “Web PKI root of trust” trust then yes, having two CAs just means you’
by mmalone 7y ago
I think you’re interpreting my comment about trust too literally. If you’re talking about “Web PKI root of trust” trust then yes, having two CAs just means you’re trusting two third parties without reducing trust in either. I was using the term more broadly and more narrowly... like, trusting them to be good stewards, trusting them with PII, and trusting them to not configure their DNS resolvers to use NSA-controlled DNS. They have more power and more control and become a more attractive target and more susceptible to corruption because the stakes are higher. Maybe I should have said “concentration of control”. If one CA owns 90% of issuances they’ll be able to push their agenda, for sure.
To be clear, all of the evidence shows that LE uses this power only for good. But that’s the threat. 30% market share is probably fine. 90% or 100% would be scary.