3 ms·
CAs that you choose to trust are more trustworthy than those you are compelled to trust. See RobotToaster's comment: https://news.ycombinator.com/item?id=33967
by pannSun 4y ago
CAs that you choose to trust are more trustworthy than those you are compelled to trust. See RobotToaster's comment:
https://news.ycombinator.com/item?id=33967192 https://news.ycombinator.com/item?id=33967192
- thefounder 4y agoIn practice users don't really choose which CA to trust. That choice is made by app and/or OS developers but I understand your point. That EU directive seems to force developers to accept EU's CA which is wrong of course. Nevertheless this CA store distribution put us in this censorship situation. I think it should be moved further towards the service provider in a similar way webauthn works. The 3rd party CA makes the whole process vulnerable to rough CA providers or mandatory CA stores. Let's stop trusting 3rd parties with our security.