Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> CNNIC is not even trustworthy among Chinese Internet users.

Oh? Then why did Firefox, Google, Microsoft, Apple, etc. trust their root certificate? I know hating on China is all the rage, but something isn't making sense here...

> Google for 3721 中文网址 if you are interested

Just did. Got nothing. Are you referring to [1]? I'm not seeing what that has to do with CNNIC.

1. https://en.wikipedia.org/wiki/Yahoo!_Assistant



> Oh? Then why did Firefox, Google, Microsoft, Apple, etc. trust their root certificate?

Mozilla no longer trust CNNIC.

https://blog.mozilla.org/security/2015/04/02/distrusting-new...


Yes, hence my using the past tense. I do not see how "CNNIC is [not trustworthy]" is compatible with "Firefox, Google, Apple, and Microsoft trusted their certificates until MCS Holding screwed up some corporate network's https-interception implementation".

In particular, was there any evidence of any mis-deeds by the CNNIC before what MCS Holding did? Anything at all aside from "they are a Chinese and that is bad" FUD? Have they ever issued a certificate used to MITM the communications of political dissidents, for example?


TFA is about the fact that Google no longer does trust CNNIC. And Mozilla no longer does, for the same reason.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: