Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I’m disappointed that a competitor doesn’t exist that uses longevity of IP routing as a reputation validator. I would think maintaining routing of DNS to a static IP is a better metric for reputation. Having unstable infrastructure to me is a flag for fly by night operations.


The German NSA intercepted the jabber.im server with a physical interposer device, issued themselves an LE certificate and MITMed this service for months


Well, be prepared for certificates that change every 7 to 47 days, as the Internet formally moves to security being built entirely on sand.


I wonder if this is a potential "off switch" for the internet. Just hit the root ca so they can't hand out the renewed certificates, you only have to push them over for a week or so.


People will learn to press all the buttons with scarry messages to ignore the wrong certificates. It may be a problem for credit cards and online shopping.


HSTS was specifically designed to block you from having any ignore buttons. (And Firefox refuses to implement a way to bypass it.)

But this is also why the current PKI mindset is insane. The warnings are never truly about a security problem, and users have correctly learned the warnings are useless. The CA/B is accomplishing absolutely nothing for security and absolutely everything for centralized control and platform instability.


> The CA/B is accomplishing absolutely nothing for security and absolutely everything for centralized control and platform instability.

is it their fault?

with the structure of the browser market today: you do what Google or Apple tell you to, or you're finished as a CA

the "forum" seems to be more of a puppet government


The CA/B is basically some Apple and Google people plus a bunch of people who rubber stamp the Apple and Google positions. Everyone is culpable and it creates a self-fulfilling process. Everyone is the expert for their company's certificate policy so nobody can tell them it's dumb and everyone else can say they have no choice because the CA/B decided it.

Even Google and Apple from a corporate level likely have no idea what their CA/B reps are doing and would trust their expertise if asked, regardless of how many billions of dollars it is burning.

The CA/B has basically made itself accountable to nobody including itself, it has no incentives to balance practicality or measure effectiveness. It's basically a runaway train of ineffective policy and procedure.


Any user agent worthy of the name will ignore that user-hostile part of the spec.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: