3 ms·
They're mandating who your privately-owned computer must trust. That is a severe overstepping of boundaries, and the concern shown is, if anything, too small.
by pannSun 4y ago
They're mandating who your privately-owned computer must trust. That is a severe overstepping of boundaries, and the concern shown is, if anything, too small.
- ratg13 4y agoYou misunderstand. They are merely adding themselves to the defaults set by current manufacturers. End users are free to remove them. Microsoft, Mozilla and others already provide you with a list of who you’re going to trust by default. It would be more outrageous if the current CAs were some sort of gold standard, but the whole system is flawed.
- pmontra 4y ago> End users are free to remove them. And browsers could create a "more secure" list of CAs, with governments CAs outside the list and a scary Accept the Risk page for everything outside the more secure list. Anyway, what happens when every government website use the new CAs and people will have to accept that because it's the only way to deal with government services? Every other site using those CAs will soon enjoy a free pass because of the Accept/Next/Next fatigue demonstrated by the last 30+ years of human computer interaction.
- pannSun 4y ago> End users are free to remove them. Let's not pretend we don't know the power of defaults, or that we expect users to learn about and modify the obscure and technical innards of their browsers. Even expert users can be fooled, such as when the NSA bribed a company to default to a weak cipher [1]. > Microsoft, Mozilla and others already provide you with a list of who you’re going to trust by default. If I use Firefox, I choose to trust Mozilla. But now, whichever browser I choose, I am forced to trust its maker and the government and intelligence agencies of every EU member state. I can spend my limited time learning how to fix this, but is it legal to share my solution in a convenient form (such as a browser that by-default trusts CAs based on merit, not government order), or would that make me a browser vendor, and compel me to backdoor my software? This is, in effect, prohibiting cooperation to fight surveillance. > It would be more outrageous if the current CAs were some sort of gold standard, but the whole system is flawed. I don't see how the current system being flawed makes a government mandate to default-trust hypothetical known-untrustworthy CAs less bad. It is a red herring - is a system being "flawed" justification for government intrusion? And does this intrusion even attempt to fix those flaws?? [1] https://www.theverge.com/2013/12/20/5231006/nsa-paid-10-million-for-a-back-door-into-rsa-encryption-according-to https://www.theverge.com/2013/12/20/5231006/nsa-paid-10-mill...