3 ms·
> the CA would be immediately distrusted by browsers, not as punishment but to deter state actors This is not practically possible for browsers to do, as it wo
by cyphar 1y ago
> the CA would be immediately distrusted by browsers, not as punishment but to deter state actors
This is not practically possible for browsers to do, as it would also cause all of the legitimate certificates signed by that CA to become distrusted and break large swathes of the internet. This was one of the main complaints Moxie Marlinspike had in his 2011 talk on TLS (the contents of which are sadly just as true today as they were then)[1].
In fact, there is fairly credible evidence that the NSA did actually do this already back in 2011 with the DigiNotar hack to steal the contents of Iranian emails[2]. This case was so egregious that DigiNotar did get distrusted by browsers, but other hacks like that of Comodo did not result in their CA certificates being distrusted.
The CAB does apparently block CAs more aggressively than they did a decade ago, but I wonder if they would actually block a big CA like LetsEncrypt if it came out they did something shady or got hacked. It just seems incredibly unlikely they would flip the "turn off >60% of the internet" switch regardless of what LetsEncrypt hypothetically did (for reference, in 2011 Comodo signed only 20-25% of website certificates).
[1]: https://www.youtube.com/watch?v=UawS3_iuHoA https://www.youtube.com/watch?v=UawS3_iuHoA
[2]: https://en.wikipedia.org/wiki/DigiNotar https://en.wikipedia.org/wiki/DigiNotar