3 ms·
It’s not merely about setting up a CA. The CA certificates would have to be added to the trust stores of every operating system, browser, framework, and applica
by misano 19d ago
It’s not merely about setting up a CA. The CA certificates would have to be added to the trust stores of every operating system, browser, framework, and application, creating a sea of security risks for the public. It’s an isolated, privacy-invasive process.
- toomuchtodo 19d agoDo you not believe the rest of the world will not move in this direction to decouple from the US? If not, you should consider it is more likely than before. Countries will mandate it if they want it done badly enough, and there is enough open source to own the entire stack (OS, browser, CLIs, etc). It is simply a matter of will, resources, and time, in that order. "You eat an elephant one bite at a time" as the saying goes. Can it be done? Yes. Will it be done? We can only watch to find out. https://news.ycombinator.com/item?id=49225112 https://news.ycombinator.com/item?id=49225112 (citations) (sysadmin/network admin/devops/infra engineer a lifetime ago, mostly familiar with what bootstrapping this looks like)
- AlecSchueler 19d ago> Do you not believe the rest of the world will not move in this direction to decouple from the US? Sure, but that will require more than 20 people, 5 million USD and the sole will of the Iranian government.
- toomuchtodo 18d agoDifferent contexts. It is cheap to build your own Let's Encrypt, it takes more time and effort for the world to decouple. Both can be true.
- hulitu 19d ago> The CA certificates would have to be added to the trust stores of every operating system, browser, framework, and application, creating a sea of security risks for the public Finaly one that acknowledges...