Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is so obvious and so "acceptable" even in security circles that I have thought for a while that it is a tacit acknowledgement that state actor attacks are "OK".

Trusted CAs should be one of the most scrutinized and controversial aspects of system configuration, and OSes should support a variety of trust models.

I've run this by a few security "experts" and the response has always been that it's a UX issue and the goal is to have websites load correctly without the user seeing and complaining about opaque security errors.

It's quite absurd. The rewards for compromising a single CA are so great that surely most state actors have succeeded in doing it at least once.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: