3 ms·
> IMO warrants revoking everything to do with DigiCert on the spot This is pretty heavy handed and I don't think you've thought through what the consequences o
by terminalbraid 2y ago
> IMO warrants revoking everything to do with DigiCert on the spot
This is pretty heavy handed and I don't think you've thought through what the consequences of that may look like. The historic way to deal with a problematic CA is to prevent them from issuing new certificates or renewing certificates (after taking care of immediate damage, of course). There are lots of legitimate companies that use Digicert and they should have an expectation of being able to continue business in the short term while they find a different certificate provider.
- DeepPPP 2y agoAre you saying it was okay to distrust EnTrust but DigiCert is too big to fail?
- terminalbraid 2y agoNo, and I'm deeply confused how you drew this conclusion from what was written. I specifically say the historical way to deprecate a certificate authority is to prevent them from issuing new certificates. Since certificates have a finite lifetime, the certificate authority would as well and would have immediately no further revenue from certificates. I am saying "pulling the plug" without notice is going to take down tens of thousands of bystanders and anyone using those certificates for business would be unable to conduct business securely online, which would be disastrous. For example amazon.com has a DigiCert-issued certificate.
- DeepPPP 2y agoAgreed. That was my bad.
- infogulch 2y agoI agree. "Revoking everything digicert" is a bit imprecise, "preventing digicert from issuing new certificates" is a more reasonable measure that actually only damages the parties that deserve it (digicert) and spares innocent bystanders (their customers).