Hacker News new | ask | show | jobs
by Strom 3742 days ago
You would soon be left without any CAs. [1] People are pretty stupid when it comes to security, and this includes people working for CAs. There have been cases where the CA private key is publicly accessible to the internet without any password. [2]

--

[1] Yes, plenty of smart people have been advocating moving away from the current CA system. It's fundamentally broken.

[2] A great talk by moxie, filled with horror examples of CAs. The private key example is at 19:20. https://www.youtube.com/watch?v=Z7Wl2FW2TcA

1 comments

Certificate Transparency with mandatory SCT delivery (as with EV certificates) will largely solve¹ the issue of fraudulent or compromised CAs.

¹ As long as you're monitoring CT log servers for anything involving domains you own.

Obligatory reference to my CT monitoring service:

https://ctadvisor.lolware.net/