Skip to content

Comment on Mozilla wants CAs to revoke 30 random certificates per yearparent

Comments

CA trust should be handled at the OS vendor level.

Who's the "vendor" for Linux? IBM?

The outcome of this idea is Google & Microsoft can MITM all internet traffic.

Who's the "vendor" for Linux? IBM?

There are countless companies and groups (but only a handful that serve the vast majority of users) releasing a version of Linux bundled with a GNU userland and other open source niceties, all designed to work together as a system. These are colloquially called "Linux distributions".

Linux distros universally use the Mozilla root store. So if a CA told Mozilla "to go pound sand" as suggested by likeabatterycar, the CA would end up distrusted not only by the "2.5%" of browser users, but by every Linux server.

The outcome of this idea is Google & Microsoft can MITM all internet traffic.

Google, MS, and Apple already handle their own CA trust. So this conspiracy theory would already be true.

Wait, is it a "conspiracy theory" or is it true? Are you claiming both? I'm aware that Google, Apple, Microsoft etc. could already MITM traffic to Chrome/Safari/Edge browsers if they were so determined.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.