3 ms·
> How would it destroy the company? If you're in business of selling X.503 certs trusted by browsers, then not being trusted by browsers kinda limits the marke
by throw_a_grenade 1y ago
> How would it destroy the company?
If you're in business of selling X.503 certs trusted by browsers, then not being trusted by browsers kinda limits the marketability of your product.
I don't believe the browsers could be coerced to not distrust such a CA. In every root program I know there's a clause that membership to the program is at browser's pleasure. (Those that have public terms, i.e. not msft, but I'd assume those have similar language.)
Re: they can just do it, well, I think they'd be distrusted the same.
In Symantecgate one of the reasons for distrust was that they signed FPKI bridge, so I think no CA in the future will sign a subca that will sign FPKI certs.
> Also for example the USA is famous for installing malware on other countries head of state.
Yeah, exactly. I think they have more targeted ways that risk less detection and less collateral damage.
- 1718627440 1y agoWell what destroys the company is not the generation of a certificate, but the publication. I think the state would compel the company not disclose it, so they would coerce the company into not destroying itself. Do you thing Google or Apple are going to care? They bowed down to China, I think the state they have their headquarters in has even more leverage. As for Mozilla Firefox on Linux, maybe, but I wouldn't trust this too much either. > I think they have more targeted ways that risk less detection and less collateral damage. I think they don't really need to care about this, it was quite clear that no other state is publicly doing anything against this.