Skip to content

Comment on What the QWAC? An EV Certificate all over againparent

Comments

It's not that I want to trust governments more. I want to get away from the "flat list of 170+ root certificates" model because I want to trust a bunch of governments (not least that of the US) less!

Is your argument with the RFC that content exfiltration is always more costly than active network attacks? Obviously all else being equal that's true, but it's an overly simplistic model when multiple countries come into play - for a government, an active network attack against a foreign power is much more costly than any king of attack, even content exfiltration, against a company within your country.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.