Hacker News new | ask | show | jobs
by glass- 3883 days ago
The CA system is unique is that one hole, breach or incompetent actor compromises the entire system.

It's also unique is that when an authority has a hole, breach or is an incompetent actor, it's very difficult to remove them from authority.

1 comments

>It's also unique is that when an authority has a hole, breach or is an incompetent actor, it's very difficult to remove them from authority.

There is no proof of this. There are lots of systems in place to deal with mistakes and trust breaches. If it gets to the extent that a Root or CA needs to be removed from trust stores, then they are removed.

Just this year we saw two CAs lose their trust.