Skip to content

Comment on Entrust Certificate Distrustparent

Comments

How dysfunctional does a company have to be to let this happen?

Surprised no one pointed to the nature of the business as a source of this behavior.

In a non-innovative, compliance-based industry, you make money by cutting costs.

This affects the entire business, as you find managers who are effective at cutting costs and architects/engineers who will work for lower salary.

Multiply that over enough years, and we know where it leads...

Thought this reply from 3 months ago was prescient, re: options in response to a previous Entrust failure to revoke issue. https://bugzilla.mozilla.org/show_bug.cgi?id=1890898#c21

> I see three possible outcomes:
> 1. The root programs continue to be lenient with Entrust indefinitely. Nothing changes.
> 2. The root programs continue to be lenient with Entrust for a while, but eventually the mistakes pile up enough that one of the root programs pushes for distrust.
> 3. The root programs immediately stop being lenient with Entrust. Entrust is forced to make internal changes to remain a CA.

It raises an interesting point about what constitutes a historical pattern of behavior, sufficient for infering future deficiencies reliably enough to take present action.

Here, the motivation seemed to be that (a) enough history had accumulated to estimate Entrust's rate of process improvement & (b) that rate was deemed insufficient. Which seems a decent metric: if perfection is not presently achieved, then remediation progress needs to be seen.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.