3 ms·
For me, this issue again shows the devastating state in which the whole SSL system is in. My browser (and therefore myself) has to trust unknown agencies with t
by larelli 15y ago
For me, this issue again shows the devastating state in which the whole SSL system is in. My browser (and therefore myself) has to trust unknown agencies with totally intransparent policies. The current state of google and mozilla releasing patches and fixes to the already broken system makes it only look worse to me.
- kahawe 15y ago> My browser (and therefore myself) has to trust unknown agencies with totally intransparent policies. I completely agree with your message but I think this part is actually even worse! Theoretically you could manage all the root certs yourself and revoke and delete whichever you want but... as the average user you get a system shoved down your throat that has clearly reached critical mass (no Iran puns intended) and you basically willing-fully trust it because you have learned Firefox is awesome and safe and that little golden padlock tells you "hey, it's ok, relax buddy!" and even just a few years back most but the very versed encryption geeks could probably care less about WHAT exactly was going on in the mess that are root CAs and were happy enough there was something SSL-y going on.
- pasbesoin 15y agoOpera just updated (to 11.51). I opened up the cert management dialog in it and was impressed at the, by comparison, relatively limited number of root certificates and the apparent -- based on associated names -- nature of these. (And no, DigiNotar is not currently in their set.)