For what it's worth, mostly private CAs are garbage. Bad at the crypto parts, bad at the identity problem, bad at their own security. Just pretty bad.
It doesn't really matter, because mostly bad guys don't see the CA as the weak point, if anything what is remarkable about the Web PKI is that we did a good enough job elsewhere that actual bad guys sometimes try to attack the Web PKI. Not often, but it happens at all.
It's like finding out you did a good enough job securing your home that an actual burglar picked your front door lock! Yes, the burglar still got in because of course no door look is effective against somebody who knows what they're doing and has plenty of time to try - but still, apparently you actually did a good enough job that they weren't able to just climb in through a side window or force open a patio door. Go you.
If STIR/SHAKEN turns out to have the CA function as its weak point then everybody involved should clap themselves on the back for an extraordinarily good job.
Comments
For what it's worth, mostly private CAs are garbage. Bad at the crypto parts, bad at the identity problem, bad at their own security. Just pretty bad.
It doesn't really matter, because mostly bad guys don't see the CA as the weak point, if anything what is remarkable about the Web PKI is that we did a good enough job elsewhere that actual bad guys sometimes try to attack the Web PKI. Not often, but it happens at all.
It's like finding out you did a good enough job securing your home that an actual burglar picked your front door lock! Yes, the burglar still got in because of course no door look is effective against somebody who knows what they're doing and has plenty of time to try - but still, apparently you actually did a good enough job that they weren't able to just climb in through a side window or force open a patio door. Go you.
If STIR/SHAKEN turns out to have the CA function as its weak point then everybody involved should clap themselves on the back for an extraordinarily good job.