Skip to content

Comment on Certificate Authority change at HN from Comodo to Entrust. No warning?

Comments

> because otherwise it is just not safe

this is just not true

https://www.eff.org/observatory

"Browsers trust a very large number of these CAs, and unfortunately, the security of HTTPS is only as strong as the practices of the least trustworthy/competent CA. Before publishing this data, we attempted to notify administrators of all sites observed vulnerable to the Debian weak key bug; please let us know if your analysis reveals other classes of vulnerabilities so that we can notify affected parties."

People from Iran would disagree. Something should also be said about problems of CAs security.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.