Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"Maybe someone working at a browser vendor can reply to this comment and explain to us why any one company is trusted to make a decision like that for the entire Internet?"

I don't work on security (although I do work at Mozilla), but I'm sure it's basically this: SSL/TLS PKI is the system we have, and if Firefox stops working with people's banks because a widely-used CA was distrusted, users will switch browsers. Once they switch browsers, the security benefits of distrusting the CA are lost.

Instead, Mozilla has to work with the CAs. As you say, we're between a rock and a hard place. The best we can do is a message like this:

http://groups.google.com/group/mozilla.dev.security.policy/b...

Which not only requires action on the part of all CAs to prove that this cannot happen again, but also clearly explains that abuses in the future can and will result in distrusting of the CA.



Issue a moratorium on subCAs. Nothing will break. Today would be great. Then we (or, more appropriately, your organization and the stakeholders) can work out a better policy than we have now.

(Is what I'd say if you were the right person at Moz to talk to).




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: