Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"Why should anyone's choice of CA determine trust" is not equivalent to "why should any site's choice of top level domain determine trust". Users control CAs. They do not control TLDs.

If you dislike the CA model that HTTPS/SSL has, you should have your spear pointed at DNSSEC.

Like I said upthread, we probably agree regarding the current HTTPS/SSL PKI.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: