logoalt Hacker News

account42last Tuesday at 3:39 PM1 replyview on HN

Pretty much any big government has a CA they can exert direct control over whenever needed.


Replies

theamklast Tuesday at 3:58 PM

Maybe, but then can only do it once. Then they get caught, and their CA is distrusted. See Diginotar [0] for example.

And things only gotten better since - we now have CT logs, and browsers require them, so any mis-issuance can be detected automatically, by any interested third party.

If we go to DANE, we lose this all. "Oops, our CT uploader process failed, we will fix Real Soon(tm) we promise" - and what are browsers going to do? Distrust the entire country?

[0] https://blog.mozilla.org/security/2011/09/02/diginotar-remov...

show 3 replies