logoalt Hacker News

repelsteeltjetoday at 9:38 AM1 replyview on HN

Yeah but isn't the point of these certificates to express trust?

The point isn't (or: shouldn't be) to forcefully find your way through some back alley to make it look legit. It's to certify that the software is legit.

Trust goes both ways: we ought to trust Microsoft to act as a responsible CA. Obfuscating why they revoked trust (as is apparently the case) and leaving the phone ringing is hurting trust in MS as a CA and as an organization.


Replies

sidewndr46today at 10:36 AM

who on planet earth trusts a piece of software because Microsoft signed it?

show 3 replies