3 ms·
Certificate transparency doesn't solve this issue fully.
by CommanderData 5y ago
Certificate transparency doesn't solve this issue fully.
- mike_d 5y agoIt sure does. Use a browser or other web client that does not trust certificates unless they appear in CT logs. A rouge CA then has to lie publicly by putting the false cert into the log, which in turn gets flagged and they don't get to be a CA anymore.
- raxxorrax 5y agoNot surely, but they should be vetted and government CAs should be made exempt in my opinion until the user explicitly allows them. Otherwise the chain of trust is compromised. It will never be perfect, but government ambitions will get more specific if a newer generation takes hold in politics.