I am a fan of pushing people to use services that respect their privacy (aka not google), but that only helps if the underlying infrastructure is secure. If we have malware vendors operating root CAs, that is a significant problem that deserves to be discussed without devolving into generic google bashing.
Edit: There is no proof that a malware vendor was operating TrustCor CA, but there sure was a lot of smoke...
Sorry I missed the window for a timely reply. Yes, these are valid
serious concerns. You're right that unfocused, random denouncements
add very little. It's hard to know what to focus on these days as so
much of tech has gone to the dogs. Outrage, even at most egregious
acts has lost its edge. Naked criminality is being normalised. This
cannot be good. Thus I find I've more sympathy for (or rather, less
will to criticise) those who pour nebulous scorn and mistrust around.
They have "a point" even if they are unable to make one.
Comments
From stuff like this: https://groups.google.com/a/mozilla.org/g/dev-security-polic...
I am a fan of pushing people to use services that respect their privacy (aka not google), but that only helps if the underlying infrastructure is secure. If we have malware vendors operating root CAs, that is a significant problem that deserves to be discussed without devolving into generic google bashing.
Edit: There is no proof that a malware vendor was operating TrustCor CA, but there sure was a lot of smoke...
Sorry I missed the window for a timely reply. Yes, these are valid serious concerns. You're right that unfocused, random denouncements add very little. It's hard to know what to focus on these days as so much of tech has gone to the dogs. Outrage, even at most egregious acts has lost its edge. Naked criminality is being normalised. This cannot be good. Thus I find I've more sympathy for (or rather, less will to criticise) those who pour nebulous scorn and mistrust around. They have "a point" even if they are unable to make one.