3 ms·
In theory Firefox in the linked thread did exactly that: They said TrustCor has X number of days to reply to allegations. It sounds like you're proposing a tech
by andrejguran 4y ago
In theory Firefox in the linked thread did exactly that: They said TrustCor has X number of days to reply to allegations. It sounds like you're proposing a technical solution to a offline solution that already exist.
- jefftk 4y agoChris is explaining why the way browsers currently handle this problem is good, not proposing they act differently. He did propose that Linux act differently (https://utcc.utoronto.ca/~cks/space/blog/linux/CARootStoreTrustProblem https://utcc.utoronto.ca/~cks/space/blog/linux/CARootStoreTr...), and this post is a follow-up explaining the value browsers get out of this partial-trust situation.
- hkdjkfjhfkfjgh 4y agobut everyone disagrees. a sketchy CA should not be given the benefit of the doubt. and customers of sketchy CA should suffer for not doing their homework and should rightly scramble to secure certs from other providers to resume their business. the only sin of kernel/distro maintainers is not dropping those CAs faster. what browsers did is the ultimate sin of sacrificing users to not be blamed by something they are fixing under the guise of backward compatibility.